Agent skill

Threat Modeling

by Hack23 in Hack23/cia

Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform

Apache-2.0Auto-check passedSecurity

Install Threat Modeling

skills CLI
$ npx skills add Hack23/cia --skill threat-modeling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia threat-modeling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/threat-modeling .claude/skills/threat-modeling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
threat-modeling
GitHub stars
239
Token cost
~6.8k tokens
SKILL.md length
835 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform

  • Tasks that involve Threat modeling
  • SKILL.md covers Purpose, When to Use This Skill, STRIDE Threat Model Framework and Attack Tree Analysis, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Threat Modeling is an agent skill from Hack23/cia. Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform

Its SKILL.md is about 6.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Threat modeling

Example prompts

  • “/threat-modeling”

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • owasp.org
    • learn.microsoft.com
    • versprite.com
    • attack.mitre.org
    • iso.org
    • csrc.nist.gov
    • microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Modeling loads about 6.8k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 835 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 835 words, ~6,775 tokens.

Download SKILL.mdSave it as .claude/skills/threat-modeling/SKILL.md (or your agent's skills folder).
name
threat-modeling
description
Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform
license
Apache-2.0

Threat Modeling Skill

Purpose

This skill provides structured methodology for identifying, analyzing, and mitigating security threats in the CIA platform using industry-standard frameworks including STRIDE, PASTA, and attack tree analysis. It ensures proactive security design aligned with Hack23 ISMS requirements.

When to Use This Skill

Apply this skill when:

  • ✅ Designing new features that handle sensitive political data
  • ✅ Integrating external APIs (Riksdagen, World Bank, Election Authority)
  • ✅ Implementing authentication or authorization mechanisms
  • ✅ Modifying security architecture or trust boundaries
  • ✅ Before major releases to identify residual risks
  • ✅ After security incidents to prevent recurrence
  • ✅ Conducting annual security architecture reviews

Do NOT use for:

  • ❌ Routine bug fixes without security implications
  • ❌ UI/UX changes that don't affect security
  • ❌ Performance optimizations (unless affecting security)

STRIDE Threat Model Framework

S - Spoofing Identity

Threats to Consider:

  • Attackers impersonating legitimate users
  • Session hijacking or fixation
  • Credential theft or replay attacks
  • API key theft and misuse

CIA Platform Attack Scenarios:

Threat: Attacker impersonates politician to modify profile data
├─ Entry Point: User authentication endpoint (/login)
├─ Attack Vector: Credential stuffing with breached password databases
├─ Impact: Reputational damage, data integrity loss
└─ Mitigation:
    ├─ Implement rate limiting (5 attempts per 15 minutes)
    ├─ Enable 2FA for sensitive accounts
    ├─ Monitor for suspicious login patterns
    └─ Enforce strong password policy (12+ chars, complexity)

Mitigation Checklist:

  • ✅ Multi-factor authentication for privileged accounts
  • ✅ Certificate-based authentication for API clients
  • ✅ Strong password policies (bcrypt with cost factor 12)
  • ✅ Session tokens with HMAC integrity protection
  • ✅ JWT signature verification for API tokens

Code Pattern:

java
@Service
public class AuthenticationService {
    
    private static final int MAX_LOGIN_ATTEMPTS = 5;
    private static final Duration LOCKOUT_PERIOD = Duration.ofMinutes(15);
    
    @Autowired
    private LoginAttemptService loginAttemptService;
    
    @Autowired
    private UserDetailsService userDetailsService;
    
    public AuthenticationToken authenticate(LoginRequest request) {
        String username = request.getUsername();
        
        // Check if account is locked due to failed attempts
        if (loginAttemptService.isLocked(username)) {
            throw new AccountLockedException(
                "Account temporarily locked. Try again in " + 
                loginAttemptService.getTimeUntilUnlock(username) + " minutes"
            );
        }
        
        try {
            // Authenticate user
            UserDetails user = userDetailsService.loadUserByUsername(username);
            
            if (!passwordEncoder.matches(request.getPassword(), user.getPassword())) {
                loginAttemptService.recordFailedAttempt(username);
                throw new BadCredentialsException("Invalid credentials");
            }
            
            // Success - reset attempt counter
            loginAttemptService.resetAttempts(username);
            
            // Generate secure token
            return tokenService.generateToken(user);
            
        } catch (UsernameNotFoundException e) {
            // Don't reveal if username exists
            throw new BadCredentialsException("Invalid credentials");
        }
    }
}
T - Tampering with Data

Threats to Consider:

  • Modification of politician voting records
  • Alteration of financial data or reports
  • Database injection attacks
  • Parameter tampering in HTTP requests

CIA Platform Attack Scenarios:

Threat: Attacker modifies politician absence rate to damage reputation
├─ Entry Point: REST API endpoint /api/politicians/{id}/data
├─ Attack Vector: SQL injection via unvalidated input parameters
├─ Impact: Data integrity compromise, false political analysis
└─ Mitigation:
    ├─ Use JPA parameterized queries exclusively
    ├─ Implement data integrity checks (checksums, timestamps)
    ├─ Enable database audit logging
    └─ Apply digital signatures to critical data

Mitigation Checklist:

  • ✅ All database queries use parameterized statements
  • ✅ Input validation on all user-provided data
  • ✅ Data integrity checks (checksums, digital signatures)
  • ✅ Database audit logging enabled
  • ✅ CSRF protection on all state-changing operations
  • ✅ Immutable data structures for sensitive information

Code Pattern:

java
@Entity
@Table(name = "politician_voting_record")
@Audited // Hibernate Envers for audit trail
public class VotingRecord {
    
    @Id
    @GeneratedValue
    private Long id;
    
    @Column(nullable = false)
    private String politicianId;
    
    @Column(nullable = false)
    private String voteType;
    
    @Column(nullable = false)
    private LocalDateTime voteDate;
    
    // Integrity protection - computed hash of critical fields
    @Column(name = "data_hash")
    private String dataHash;
    
    @PrePersist
    @PreUpdate
    private void calculateHash() {
        this.dataHash = DigestUtils.sha256Hex(
            politicianId + voteType + voteDate.toString()
        );
    }
    
    public boolean verifyIntegrity() {
        String expectedHash = DigestUtils.sha256Hex(
            politicianId + voteType + voteDate.toString()
        );
        return expectedHash.equals(this.dataHash);
    }
}

@Repository
public interface VotingRecordRepository extends JpaRepository<VotingRecord, Long> {
    // Safe: JPA query with named parameters
    @Query("SELECT v FROM VotingRecord v WHERE v.politicianId = :politicianId " +
           "AND v.voteDate BETWEEN :startDate AND :endDate")
    List<VotingRecord> findByPoliticianAndDateRange(
        @Param("politicianId") String politicianId,
        @Param("startDate") LocalDateTime startDate,
        @Param("endDate") LocalDateTime endDate
    );
}
R - Repudiation

Threats to Consider:

  • Users denying actions they performed
  • Lack of audit trails for sensitive operations
  • Missing transaction logs
  • Insufficient evidence for security investigations

CIA Platform Attack Scenarios:

Threat: Administrator denies modifying user permissions
├─ Entry Point: Admin panel /admin/users/{id}/permissions
├─ Attack Vector: No audit logging of administrative actions
├─ Impact: Accountability loss, inability to investigate incidents
└─ Mitigation:
    ├─ Implement comprehensive audit logging
    ├─ Log all authentication and authorization events
    ├─ Include timestamps, user identity, IP address, action details
    └─ Store logs in tamper-proof storage (write-once)

Mitigation Checklist:

  • ✅ Comprehensive audit logging for all sensitive operations
  • ✅ Logs include: timestamp, user, IP, action, outcome
  • ✅ Logs stored in tamper-resistant storage
  • ✅ Log retention policy enforced (minimum 1 year)
  • ✅ Regular log review and analysis
  • ✅ Digital signatures on critical transactions

Code Pattern:

java
@Component
@Aspect
public class AuditLoggingAspect {
    
    private static final Logger auditLog = LoggerFactory.getLogger("AUDIT");
    
    @Autowired
    private AuditLogRepository auditLogRepository;
    
    @Around("@annotation(Audited)")
    public Object logAuditEvent(ProceedingJoinPoint joinPoint) throws Throwable {
        MethodSignature signature = (MethodSignature) joinPoint.getSignature();
        String methodName = signature.getName();
        String className = signature.getDeclaringTypeName();
        
        // Capture context
        String username = SecurityContextHolder.getContext()
            .getAuthentication().getName();
        String ipAddress = RequestContextHolder.currentRequestAttributes()
            .getSessionId();
        
        AuditLogEntry entry = new AuditLogEntry();
        entry.setTimestamp(Instant.now());
        entry.setUsername(username);
        entry.setIpAddress(ipAddress);
        entry.setAction(className + "." + methodName);
        entry.setParameters(Arrays.toString(joinPoint.getArgs()));
        
        try {
            // Execute the method
            Object result = joinPoint.proceed();
            
            entry.setOutcome("SUCCESS");
            entry.setResult(result != null ? result.toString() : "void");
            
            return result;
            
        } catch (Exception e) {
            entry.setOutcome("FAILURE");
            entry.setErrorMessage(e.getMessage());
            throw e;
            
        } finally {
            // Always log, even on failure
            auditLogRepository.save(entry);
            auditLog.info("Audit: {}", entry.toJson());
        }
    }
}

@Entity
@Table(name = "audit_log")
public class AuditLogEntry {
    @Id
    @GeneratedValue
    private Long id;
    
    @Column(nullable = false, updatable = false)
    private Instant timestamp;
    
    @Column(nullable = false, updatable = false)
    private String username;
    
    @Column(updatable = false)
    private String ipAddress;
    
    @Column(nullable = false, updatable = false)
    private String action;
    
    @Column(updatable = false, columnDefinition = "TEXT")
    private String parameters;
    
    @Column(nullable = false, updatable = false)
    private String outcome;
    
    // Immutable - prevent tampering
    @PreUpdate
    private void preventUpdate() {
        throw new IllegalStateException("Audit log entries cannot be modified");
    }
}
I - Information Disclosure

Threats to Consider:

  • Exposure of personal identifiable information (PII)
  • Leakage of API keys or credentials
  • Verbose error messages revealing system details
  • Insufficient access controls on sensitive data

CIA Platform Attack Scenarios:

Threat: Attacker accesses politician personal contact information
├─ Entry Point: Public API endpoint /api/politicians/{id}
├─ Attack Vector: Insufficient access control, over-fetching data
├─ Impact: GDPR violation, privacy breach
└─ Mitigation:
    ├─ Implement field-level access control
    ├─ Return only public data in API responses
    ├─ Redact or mask sensitive fields (phone, email)
    └─ Log all access to PII for audit purposes

Mitigation Checklist:

  • ✅ Sensitive data encrypted at rest (database encryption)
  • ✅ TLS 1.2+ for all data in transit
  • ✅ Error messages sanitized (no stack traces in production)
  • ✅ Access control on all data endpoints
  • ✅ Data classification and handling procedures
  • ✅ PII minimization and purpose limitation

Code Pattern:

java
@RestController
@RequestMapping("/api/politicians")
public class PoliticianController {
    
    @GetMapping("/{id}")
    public ResponseEntity<PoliticianDTO> getPolitician(
            @PathVariable String id,
            @AuthenticationPrincipal UserDetails currentUser) {
        
        Politician politician = politicianService.findById(id)
            .orElseThrow(() -> new ResourceNotFoundException("Politician not found"));
        
        // Apply field-level filtering based on user role
        PoliticianDTO dto = mapToDTO(politician, currentUser);
        
        // Log PII access for audit
        auditLogger.logPIIAccess(currentUser.getUsername(), "Politician", id);
        
        return ResponseEntity.ok(dto);
    }
    
    private PoliticianDTO mapToDTO(Politician politician, UserDetails user) {
        PoliticianDTO dto = new PoliticianDTO();
        
        // Always include public information
        dto.setFirstName(politician.getFirstName());
        dto.setLastName(politician.getLastName());
        dto.setParty(politician.getParty());
        dto.setDistrict(politician.getDistrict());
        
        // Only include sensitive data for authorized users
        if (hasRole(user, "ADMIN") || hasRole(user, "RESEARCHER")) {
            // Redact instead of exposing full data
            dto.setEmail(redactEmail(politician.getEmail()));
            dto.setPhone(redactPhone(politician.getPhone()));
        }
        
        return dto;
    }
    
    private String redactEmail(String email) {
        if (email == null) return null;
        int atIndex = email.indexOf('@');
        if (atIndex > 2) {
            return email.substring(0, 2) + "***" + email.substring(atIndex);
        }
        return "***" + email.substring(atIndex);
    }
}

@Configuration
public class SecurityHeadersConfig {
    
    @Bean
    public SecurityFilterChain securityHeaders(HttpSecurity http) throws Exception {
        http.headers(headers -> headers
            .contentSecurityPolicy("default-src 'self'; script-src 'self'; style-src 'self'")
            .xssProtection()
            .frameOptions().deny()
            .httpStrictTransportSecurity()
                .maxAgeInSeconds(31536000)
                .includeSubDomains(true)
        );
        return http.build();
    }
}
D - Denial of Service

Threats to Consider:

  • Resource exhaustion attacks (CPU, memory, disk)
  • Application-level DoS (expensive queries)
  • Distributed denial of service (DDoS)
  • API abuse and rate limit bypass

CIA Platform Attack Scenarios:

Threat: Attacker overwhelms system with expensive political data queries
├─ Entry Point: Public search API /api/search?query=*
├─ Attack Vector: Recursive queries, unbounded result sets
├─ Impact: Service unavailability, degraded performance for legitimate users
└─ Mitigation:
    ├─ Implement rate limiting (100 requests/minute per IP)
    ├─ Query result pagination (max 100 results per page)
    ├─ Timeout for long-running queries (30 seconds)
    └─ Resource quotas per user tier

Mitigation Checklist:

  • ✅ Rate limiting on all public APIs
  • ✅ Request size limits enforced
  • ✅ Query timeouts configured
  • ✅ Pagination on all list endpoints
  • ✅ Resource monitoring and alerting
  • ✅ Circuit breakers for external dependencies

Code Pattern:

java
@Configuration
public class RateLimitingConfig {
    
    @Bean
    public RateLimiter apiRateLimiter() {
        return RateLimiter.create(100.0); // 100 requests per second
    }
}

@Component
public class RateLimitingInterceptor implements HandlerInterceptor {
    
    @Autowired
    private RateLimiter rateLimiter;
    
    private final LoadingCache<String, AtomicInteger> requestCounts = CacheBuilder.newBuilder()
        .expireAfterWrite(1, TimeUnit.MINUTES)
        .build(new CacheLoader<String, AtomicInteger>() {
            public AtomicInteger load(String key) {
                return new AtomicInteger(0);
            }
        });
    
    @Override
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response, 
                            Object handler) throws Exception {
        
        String clientIp = getClientIP(request);
        
        // Apply rate limit
        if (!rateLimiter.tryAcquire(1, TimeUnit.SECONDS)) {
            response.setStatus(HttpStatus.TOO_MANY_REQUESTS.value());
            response.getWriter().write("Rate limit exceeded. Try again later.");
            return false;
        }
        
        // Check per-IP limit
        int requestCount = requestCounts.get(clientIp).incrementAndGet();
        if (requestCount > 1000) {
            response.setStatus(HttpStatus.TOO_MANY_REQUESTS.value());
            response.getWriter().write("IP-based rate limit exceeded.");
            return false;
        }
        
        return true;
    }
}

@Repository
public interface PoliticianSearchRepository extends JpaRepository<Politician, Long> {
    
    // Pageable prevents unbounded result sets
    @Query("SELECT p FROM Politician p WHERE " +
           "LOWER(p.firstName) LIKE LOWER(CONCAT('%', :searchTerm, '%')) OR " +
           "LOWER(p.lastName) LIKE LOWER(CONCAT('%', :searchTerm, '%'))")
    @QueryHints(@QueryHint(name = "org.hibernate.timeout", value = "30")) // 30 second timeout
    Page<Politician> search(@Param("searchTerm") String searchTerm, Pageable pageable);
}

@RestController
public class SearchController {
    
    private static final int MAX_PAGE_SIZE = 100;
    
    @GetMapping("/api/search")
    public Page<PoliticianDTO> search(
            @RequestParam String query,
            @RequestParam(defaultValue = "0") int page,
            @RequestParam(defaultValue = "20") int size) {
        
        // Enforce maximum page size
        if (size > MAX_PAGE_SIZE) {
            size = MAX_PAGE_SIZE;
        }
        
        Pageable pageable = PageRequest.of(page, size);
        return searchService.search(query, pageable);
    }
}
E - Elevation of Privilege

Threats to Consider:

  • Horizontal privilege escalation (access other users' data)
  • Vertical privilege escalation (gain admin rights)
  • Bypassing authorization checks
  • Exploiting misconfigured access controls

CIA Platform Attack Scenarios:

Threat: Regular user gains administrative access to modify site configuration
├─ Entry Point: Admin API endpoint /api/admin/settings
├─ Attack Vector: Missing @PreAuthorize annotation on controller method
├─ Impact: Unauthorized configuration changes, system compromise
└─ Mitigation:
    ├─ Enforce role-based access control on all endpoints
    ├─ Use Spring Security annotations (@PreAuthorize, @Secured)
    ├─ Implement defense in depth (controller + service layer checks)
    └─ Regular access control audits

Mitigation Checklist:

  • ✅ Role-based access control (RBAC) implemented
  • ✅ Principle of least privilege enforced
  • ✅ Authorization checks at multiple layers
  • ✅ Regular access control reviews
  • ✅ Privilege escalation attempts logged and alerted
  • ✅ No default or backdoor admin accounts

Code Pattern:

java
@RestController
@RequestMapping("/api/admin")
@PreAuthorize("hasRole('ADMIN')") // Controller-level authorization
public class AdminController {
    
    @PostMapping("/settings")
    @PreAuthorize("hasAuthority('MODIFY_SETTINGS')") // Method-level check
    public ResponseEntity<SystemSettings> updateSettings(
            @RequestBody @Valid SystemSettingsRequest request,
            @AuthenticationPrincipal UserDetails currentUser) {
        
        // Log privileged action
        auditLogger.logPrivilegedAction(
            currentUser.getUsername(),
            "UPDATE_SYSTEM_SETTINGS",
            request.toString()
        );
        
        // Service layer also enforces authorization
        SystemSettings updated = adminService.updateSettings(request);
        
        return ResponseEntity.ok(updated);
    }
}

@Service
public class AdminService {
    
    @PreAuthorize("hasRole('ADMIN')")
    public SystemSettings updateSettings(SystemSettingsRequest request) {
        // Verify authorization again at service layer (defense in depth)
        Authentication auth = SecurityContextHolder.getContext().getAuthentication();
        if (!auth.getAuthorities().stream()
                .anyMatch(a -> a.getAuthority().equals("ROLE_ADMIN"))) {
            throw new AccessDeniedException("Admin role required");
        }
        
        // Perform update
        SystemSettings settings = settingsRepository.findCurrent();
        settings.updateFrom(request);
        return settingsRepository.save(settings);
    }
}

// Global method security enabled
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true, securedEnabled = true)
public class MethodSecurityConfig extends GlobalMethodSecurityConfiguration {
    
    @Override
    protected MethodSecurityExpressionHandler createExpressionHandler() {
        DefaultMethodSecurityExpressionHandler handler = 
            new DefaultMethodSecurityExpressionHandler();
        handler.setPermissionEvaluator(new CustomPermissionEvaluator());
        return handler;
    }
}
Show full SKILL.md (312 more words)Show less

Attack Tree Analysis

Example: Compromise Politician Data Integrity
ROOT: Compromise Politician Voting Record Data
├─ AND: Gain Write Access
│  ├─ OR: Exploit Authentication
│  │  ├─ Brute force credentials [Mitigated: Rate limiting]
│  │  ├─ Credential stuffing [Mitigated: 2FA]
│  │  └─ Session hijacking [Mitigated: Secure cookies]
│  └─ OR: Exploit Authorization
│     ├─ Privilege escalation [Mitigated: RBAC]
│     └─ IDOR vulnerability [Mitigated: Ownership checks]
└─ AND: Modify Data
   ├─ OR: Direct Database Access
   │  ├─ SQL injection [Mitigated: Parameterized queries]
   │  └─ Database credential theft [Mitigated: Secrets management]
   └─ OR: API Manipulation
      ├─ Parameter tampering [Mitigated: Input validation]
      └─ CSRF attack [Mitigated: CSRF tokens]
Attack Tree Legend:
  • AND: All child nodes must succeed
  • OR: Any child node success achieves goal
  • [Mitigated]: Control in place, residual risk accepted

Security Architecture Review

Trust Boundaries
Internet Users (Untrusted)
    │
    ├─→ Application Firewall / Rate Limiter
    │       │
    │       ├─→ Spring Boot Application (DMZ)
    │       │       │
    │       │       ├─→ Authentication Filter
    │       │       ├─→ Authorization Filter
    │       │       └─→ CSRF Protection
    │       │
    │       └─→ Internal Network (Trusted)
    │               │
    │               ├─→ PostgreSQL Database (Encrypted)
    │               └─→ Redis Session Store (Encrypted)
    │
    └─→ External APIs (Semi-Trusted)
            ├─→ Riksdagen API (HTTPS only)
            ├─→ World Bank API (HTTPS only)
            └─→ Election Authority API (HTTPS only)
Data Flow Diagram (DFD) Security Analysis

Level 0 DFD - Context Diagram:

[Public Users] → (CIA Web App) → [Database]
[Admin Users] → (CIA Web App) → [External APIs]

Security Analysis:

  • Public Users: Untrusted, require authentication for sensitive operations
  • Admin Users: Trusted but verify, require strong authentication (2FA)
  • External APIs: Semi-trusted, validate all responses
  • Database: Trusted, encrypted at rest and in transit

Threat Model Documentation Template

markdown
# Threat Model: [Feature Name]

## Overview
- **Component**: [Component being analyzed]
- **Last Updated**: [Date]
- **Reviewer**: [Name]
- **Risk Rating**: [Critical/High/Medium/Low]

## Assets
1. Politician personal information (GDPR protected)
2. Voting records (integrity critical)
3. User credentials (confidentiality critical)
4. API keys for external services

## Trust Boundaries
- Internet → Application Server
- Application Server → Database
- Application Server → External APIs

## STRIDE Analysis

### Spoofing
- **Threat**: [Description]
- **Likelihood**: [High/Medium/Low]
- **Impact**: [High/Medium/Low]
- **Risk**: [Critical/High/Medium/Low]
- **Mitigation**: [Controls in place]
- **Residual Risk**: [Accepted/Needs treatment]

[Repeat for T, R, I, D, E]

## Attack Trees
[Attach attack tree diagrams]

## Security Requirements
1. [Requirement 1]
2. [Requirement 2]

## Security Test Cases
1. Test authentication bypass attempts
2. Test authorization escalation
3. Test input validation

## ISMS Compliance
- ISO 27001:2022 A.5.15 (Access Control)
- NIST CSF PR.AC-4 (Access Permissions)
- CIS Control 6.1 (Access Control Management)

## Sign-off
- **Security Team**: [Approved/Rejected]
- **Development Team**: [Approved/Rejected]
- **Date**: [Date]

ISMS Compliance Mapping

ISO 27001:2022 Controls
  • A.5.15 - Access Control: STRIDE analysis ensures proper access controls
  • A.8.8 - Management of Technical Vulnerabilities: Threat modeling identifies vulnerabilities proactively
  • A.14.2.1 - Secure Development Policy: Threat modeling is mandatory step in SDLC
  • A.16.1 - Management of Information Security Incidents: Attack trees inform incident response
NIST Cybersecurity Framework
  • ID.RA-1: Vulnerabilities identified through threat modeling
  • ID.RA-3: Threats identified internally and externally
  • PR.IP-1: Baseline security configurations from threat analysis
  • DE.CM-4: System monitored for malicious activity based on threat model
CIS Controls v8
  • Control 18.3: Establish and maintain architecture documentation
  • Control 18.4: Establish secure application design
  • Control 18.5: Document application design flaws

Hack23 ISMS Policy References

Threat Management Framework:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

CIA Platform Architecture References

References

Threat Modeling Standards
Tools & Frameworks

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/threat-modeling of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Threat Modeling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Modeling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Modeling this skillHack23/cia239—~6.8kAutomated safety check: PassApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~5.6kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Create Rulecartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0
Commit Security Scancodexstar69/bug-hunter519—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills156—~3.2kAutomated safety check: PassMIT

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~5.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    519 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    156 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit Browser Security Boundaries

    nordstjernen-web/northstar-browser

    Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

    112 GitHub stars~920 tokensUpdated yesterday
    SecurityAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Threat Modeling

What does Threat Modeling do?

Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform. Threat Modeling is an agent skill from Hack23/cia.

When should I use Threat Modeling?

Threat Modeling fits situations like: tasks that involve Threat modeling.

How do I install Threat Modeling in Claude Code?

Run `npx skills add Hack23/cia --skill threat-modeling -a claude-code`. Or copy the skill folder (.github/skills/threat-modeling in Hack23/cia) into .claude/skills/threat-modeling in your project. Claude Code loads it when a task matches its description.

How do I install Threat Modeling in Codex?

Run `npx skills add Hack23/cia --skill threat-modeling -a codex`. Or copy the skill folder (.github/skills/threat-modeling in Hack23/cia) into .agents/skills/threat-modeling in your project. Codex loads it when a task matches its description.

Can I use Threat Modeling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill threat-modeling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-modeling, .gemini/skills/threat-modeling, .github/skills/threat-modeling and .opencode/skills/threat-modeling in your project.

What does Threat Modeling need to run?

SKILL.md names no scripts, command-line tools or credentials: Threat Modeling is instructions for the agent only.

Does Threat Modeling access the network?

SKILL.md names 8 domains. As links in the text: github.com, owasp.org, learn.microsoft.com, versprite.com, attack.mitre.org, iso.org, csrc.nist.gov and microsoft.com. This is read from the text; nothing was executed.

Is Threat Modeling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Threat Modeling use?

Threat Modeling is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Modeling use?

About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Threat Modeling?

Skills that share tags, products or a category with Threat Modeling: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 187 stars), Create Rule (cartography-cncf/cartography, 4.1k stars) and Commit Security Scan (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Modeling?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.