Ramp Security Basics
jeremylongshore/tons-of-skills-marketplace
Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration.
安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。
$ npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install devcodex-labs/devcodex security-threat-modeling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/content/skills/security-threat-modeling .claude/skills/security-threat-modeling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-threat-modeling" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modeling into .claude/skills/security-threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-threat-modeling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modelingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install devcodex-labs/devcodex security-threat-modeling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .agents/skills && cp -r skills-src/content/skills/security-threat-modeling .agents/skills/security-threat-modeling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-threat-modeling" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modeling into .agents/skills/security-threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-threat-modeling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install devcodex-labs/devcodex security-threat-modeling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/content/skills/security-threat-modeling .cursor/skills/security-threat-modeling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-threat-modeling" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modeling into .cursor/skills/security-threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-threat-modeling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/devcodex-labs/devcodex.git --path content/skills/security-threat-modeling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install devcodex-labs/devcodex security-threat-modeling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/content/skills/security-threat-modeling .gemini/skills/security-threat-modeling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-threat-modeling" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modeling into .gemini/skills/security-threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-threat-modeling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install devcodex-labs/devcodex security-threat-modelingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .github/skills && cp -r skills-src/content/skills/security-threat-modeling .github/skills/security-threat-modeling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-threat-modeling" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modeling into .github/skills/security-threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-threat-modeling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install devcodex-labs/devcodex security-threat-modeling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/devcodex-labs/devcodex.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/content/skills/security-threat-modeling .opencode/skills/security-threat-modeling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-threat-modeling" agent skill from https://github.com/devcodex-labs/devcodex/tree/main/content/skills/security-threat-modeling into .opencode/skills/security-threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-threat-modeling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-threat-modeling安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。
Security Threat Modeling is an agent skill from devcodex-labs/devcodex. 安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。
Its SKILL.md is about 770 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `intent.json`).
It sits in Security, covering Threat modeling, Webhooks and OAuth and OpenID Connect. The repository describes itself as: Intent-driven AI coding workflow runtime for consistent context, skills, approvals, validation, and handoffs across six AI coding hosts. The licence is AGPL-3.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 1dd4525. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Threat Modeling loads about 771 tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 124 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from devcodex-labs/devcodex at commit 1dd4525, republished under its AGPL-3.0 licence (© devcodex-labs). 124 words, ~771 tokens.
.claude/skills/security-threat-modeling/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.本 Skill 负责安全威胁建模 Owner 视角。它不默认改变 S02 用户策略,而是把信任边界、滥用路径、权限、审计和缓解验证说清楚。
| 场景 | 是否触发 |
|---|---|
| 认证、授权、权限、敏感操作、输入输出信任边界、审计、密钥策略 | 必须 |
| OAuth、Webhook、外部集成、admin、脚本执行、文件系统、数据库写入、发布凭据 | 必须 |
| 复审发现权限绕过、越权、注入、重放、审计缺失或风险误判 | 必须 |
| 纯文案或无安全边界变化 | N/A + skipReason |
| Gate | 要求 | 证据 |
|---|---|---|
SecurityThreatModelingGate | 信任边界、威胁场景、权限滥用、密钥策略、审计和缓解验证必须成矩阵 | trustBoundary、threatScenario |
TrustBoundaryGate | 输入、输出、调用方、外部系统和持久化边界必须明确 | trustBoundary |
PermissionAbuseCaseGate | 权限滥用、越权、绕过和敏感操作必须有负向样例 | permissionAbuseCase |
SecretPolicyRespectGate | 必须遵循 S02 用户 / 项目策略,不得自行加严 | secretPolicy |
AuditMitigationGate | 缓解措施必须有日志、审计或测试证据 | auditLogging、mitigationVerification |
AuthorizedLocalSecurityAuditPresentationGate | 用户自有/明确授权的本地安全审查也要分离“真实本地探针”与“用户可见呈现”;明确防御目标、最小必要证据和中断恢复,不得宣称绕过宿主安全控制 | authorizationContext、visibleEvidenceBudget、safetyInterruptionCard |
当安全审查目标是用户自有仓库、本地环境或已明确授权系统时,先记录 authorizationContext(所有权/授权、目标范围、允许动作、排除动作)与 defensiveObjective(识别、预防、修复、验证或恢复)。授权不能替代平台安全控制,也不能扩大用户未授权的外部目标。
SafetyInterruptionCard:exact message、surface/model、date/time/timezone、requestId(若有)、redacted task summary、workspace/org、last accepted checkpoint、resume evidence。## SecurityThreatModelingGate
| 字段 | 内容 |
|------|------|
| trustBoundary | 用户/系统/外部/数据/密钥边界 |
| threatScenario | 威胁场景、攻击面、失败路径 |
| permissionAbuseCase | 越权、绕过、滥用、敏感操作 |
| secretPolicy | S02 用户/项目策略、明文/硬编码/env 边界 |
| auditLogging | 审计、日志、追踪、证据保留 |
| mitigationVerification | 缓解措施和负向验证 |
| authorizationContext | 本地所有权/授权、允许与排除范围;N/A 时写 skipReason |
| defensiveObjective | 防御目标 |
| visibleEvidenceBudget | 用户可见证据边界与隔离探针位置 |
| safetyInterruptionCard | 提示上下文、最近检查点与恢复/反馈路线;未触发时写 N/A |
| evidenceMatrix | 判断 -> 代码 / policy / tests / logs / docs || 反模式 | 修正 |
|---|---|
| 一看到密钥就默认改 env | 先执行 S02 策略判断 |
| 权限只测 happy path | 补 permissionAbuseCase 负向样例 |
| 安全建议无验证 | 补 mitigationVerification |
| 把框架已有鉴权重复写进业务层 | 先查框架/项目原生能力 |
| 为避免内容提示而改写/拆分攻击载荷 | 聚焦防御结果和最小证据;不得绕过平台控制 |
| 把“无法显示”直接判为违规或直接丢弃进度 | 保留 SafetyInterruptionCard,从文件真相和审查状态恢复 |
external-integration-architecture:OAuth/Webhook/签名需要联合审查。backend-domain-architecture:权限模型和领域不变量需要一致。audit-project:安全 finding 进入工程审查和测试路线。© devcodex-labs, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in content/skills/security-threat-modeling of devcodex-labs/devcodex.
Open the folder on GitHubat commit 1dd4525
Security Threat Modeling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Threat Modeling this skilldevcodex-labs/devcodex | 439 | — | ~771 | Automated safety check: Pass | AGPL-3.0 | |
| Ramp Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Clickup Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1k | Automated safety check: Pass | MIT | |
| Bamboohr Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Canva Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| Linear Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT |
jeremylongshore/tons-of-skills-marketplace
Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration.
jeremylongshore/tons-of-skills-marketplace
Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls.
jeremylongshore/tons-of-skills-marketplace
Threat-model and harden a BambooHR integration that handles employee PII, OAuth tokens, API keys, files, and webhooks.
jeremylongshore/tons-of-skills-marketplace
Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification.
jeremylongshore/tons-of-skills-marketplace
Harden Linear credentials, OAuth, team access, webhook verification, logging, and rotation.
jeremylongshore/tons-of-skills-marketplace
Threat-model a Procore integration across OAuth credentials, company routing, DMSA permissions, webhooks, files, logs, and revocation.
devcodex-labs/devcodex
无障碍与国际化专家 Owner — 当任务涉及可访问性、键盘操作、焦点、屏幕阅读器、ARIA、语言地区、本地化、RTL、翻译资源、用户可见文案或多语言文档时使用;要求把包容性体验和本地化验证绑定到真实用户路径。
devcodex-labs/devcodex
AI Agent 系统架构专家 Owner — 当任务涉及 Agent 路由、工具调用、上下文管理、记忆、状态机、权限、人机协作、可观测性、回放验证或模型辅助治理时使用;要求把 Agent 行为设计成可解释、可恢复、可审计。
devcodex-labs/devcodex
API 契约架构专家 Owner — 当任务涉及 public API、HTTP/SDK/CLI 契约、版本兼容、错误模型、分页过滤、幂等、Schema、类型、迁移或消费者影响时使用;要求先冻结消费者契约,再设计实现与验证。
devcodex-labs/devcodex
架构设计文档编排 Owner — 当用户要求架构设计、系统设计、技术架构或可指导开发、Review 与任务拆分的完整方案时使用;要求从业务流程反推节点、状态、数据、一致性、异常补偿、ADR 与实施任务。
devcodex-labs/devcodex
审查公共维度 G0~G5 + Profile Freshness Check — 所有 audit 子类型必先执行的基础维度层
devcodex-labs/devcodex
审计工作流的跨会话状态机 — 在 <audit-root/.audit-state/<session-id.json 持久化轮次/发现项/收敛状态,支持 Token 中断后精准恢复
Categories
安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。. Security Threat Modeling is an agent skill from devcodex-labs/devcodex.
Security Threat Modeling fits situations like: tasks that involve Threat modeling; tasks that involve Webhooks; tasks that involve OAuth and OpenID Connect.
Run `npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a claude-code`. Or copy the skill folder (content/skills/security-threat-modeling in devcodex-labs/devcodex) into .claude/skills/security-threat-modeling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a codex`. Or copy the skill folder (content/skills/security-threat-modeling in devcodex-labs/devcodex) into .agents/skills/security-threat-modeling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcodex-labs/devcodex --skill security-threat-modeling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-threat-modeling, .gemini/skills/security-threat-modeling, .github/skills/security-threat-modeling and .opencode/skills/security-threat-modeling in your project.
SKILL.md names no scripts, command-line tools or credentials: Security Threat Modeling is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Threat Modeling is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 771 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Threat Modeling: Ramp Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Clickup Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Bamboohr Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Canva Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
devcodex-labs (a GitHub organization) maintains it in devcodex-labs/devcodex, which has 439 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on September 17, 2026.
Source: devcodex-labs/devcodex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.