Fla Ascend Performance
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform
$ npx skills add Hack23/cia --skill threat-modeling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia threat-modeling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/threat-modeling .claude/skills/threat-modeling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "threat-modeling" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/threat-modeling into .claude/skills/threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-modeling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/threat-modelingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill threat-modeling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia threat-modeling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/threat-modeling .agents/skills/threat-modeling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "threat-modeling" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/threat-modeling into .agents/skills/threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-modeling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill threat-modeling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia threat-modeling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/threat-modeling .cursor/skills/threat-modeling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "threat-modeling" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/threat-modeling into .cursor/skills/threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-modeling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/threat-modeling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill threat-modeling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia threat-modeling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/threat-modeling .gemini/skills/threat-modeling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "threat-modeling" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/threat-modeling into .gemini/skills/threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-modeling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia threat-modelingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill threat-modeling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/threat-modeling .github/skills/threat-modeling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "threat-modeling" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/threat-modeling into .github/skills/threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-modeling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill threat-modeling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia threat-modeling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/threat-modeling .opencode/skills/threat-modeling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "threat-modeling" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/threat-modeling into .opencode/skills/threat-modeling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-modeling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
threat-modelingConduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform
Threat Modeling is an agent skill from Hack23/cia. Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform
Its SKILL.md is about 6.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Threat modeling. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are java and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comowasp.orglearn.microsoft.comversprite.comattack.mitre.orgiso.orgcsrc.nist.govmicrosoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Threat Modeling loads about 6.8k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 835 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 835 words, ~6,775 tokens.
.claude/skills/threat-modeling/SKILL.md (or your agent's skills folder).This skill provides structured methodology for identifying, analyzing, and mitigating security threats in the CIA platform using industry-standard frameworks including STRIDE, PASTA, and attack tree analysis. It ensures proactive security design aligned with Hack23 ISMS requirements.
Apply this skill when:
Do NOT use for:
Threats to Consider:
CIA Platform Attack Scenarios:
Threat: Attacker impersonates politician to modify profile data
├─ Entry Point: User authentication endpoint (/login)
├─ Attack Vector: Credential stuffing with breached password databases
├─ Impact: Reputational damage, data integrity loss
└─ Mitigation:
├─ Implement rate limiting (5 attempts per 15 minutes)
├─ Enable 2FA for sensitive accounts
├─ Monitor for suspicious login patterns
└─ Enforce strong password policy (12+ chars, complexity)Mitigation Checklist:
Code Pattern:
@Service
public class AuthenticationService {
private static final int MAX_LOGIN_ATTEMPTS = 5;
private static final Duration LOCKOUT_PERIOD = Duration.ofMinutes(15);
@Autowired
private LoginAttemptService loginAttemptService;
@Autowired
private UserDetailsService userDetailsService;
public AuthenticationToken authenticate(LoginRequest request) {
String username = request.getUsername();
// Check if account is locked due to failed attempts
if (loginAttemptService.isLocked(username)) {
throw new AccountLockedException(
"Account temporarily locked. Try again in " +
loginAttemptService.getTimeUntilUnlock(username) + " minutes"
);
}
try {
// Authenticate user
UserDetails user = userDetailsService.loadUserByUsername(username);
if (!passwordEncoder.matches(request.getPassword(), user.getPassword())) {
loginAttemptService.recordFailedAttempt(username);
throw new BadCredentialsException("Invalid credentials");
}
// Success - reset attempt counter
loginAttemptService.resetAttempts(username);
// Generate secure token
return tokenService.generateToken(user);
} catch (UsernameNotFoundException e) {
// Don't reveal if username exists
throw new BadCredentialsException("Invalid credentials");
}
}
}Threats to Consider:
CIA Platform Attack Scenarios:
Threat: Attacker modifies politician absence rate to damage reputation
├─ Entry Point: REST API endpoint /api/politicians/{id}/data
├─ Attack Vector: SQL injection via unvalidated input parameters
├─ Impact: Data integrity compromise, false political analysis
└─ Mitigation:
├─ Use JPA parameterized queries exclusively
├─ Implement data integrity checks (checksums, timestamps)
├─ Enable database audit logging
└─ Apply digital signatures to critical dataMitigation Checklist:
Code Pattern:
@Entity
@Table(name = "politician_voting_record")
@Audited // Hibernate Envers for audit trail
public class VotingRecord {
@Id
@GeneratedValue
private Long id;
@Column(nullable = false)
private String politicianId;
@Column(nullable = false)
private String voteType;
@Column(nullable = false)
private LocalDateTime voteDate;
// Integrity protection - computed hash of critical fields
@Column(name = "data_hash")
private String dataHash;
@PrePersist
@PreUpdate
private void calculateHash() {
this.dataHash = DigestUtils.sha256Hex(
politicianId + voteType + voteDate.toString()
);
}
public boolean verifyIntegrity() {
String expectedHash = DigestUtils.sha256Hex(
politicianId + voteType + voteDate.toString()
);
return expectedHash.equals(this.dataHash);
}
}
@Repository
public interface VotingRecordRepository extends JpaRepository<VotingRecord, Long> {
// Safe: JPA query with named parameters
@Query("SELECT v FROM VotingRecord v WHERE v.politicianId = :politicianId " +
"AND v.voteDate BETWEEN :startDate AND :endDate")
List<VotingRecord> findByPoliticianAndDateRange(
@Param("politicianId") String politicianId,
@Param("startDate") LocalDateTime startDate,
@Param("endDate") LocalDateTime endDate
);
}Threats to Consider:
CIA Platform Attack Scenarios:
Threat: Administrator denies modifying user permissions
├─ Entry Point: Admin panel /admin/users/{id}/permissions
├─ Attack Vector: No audit logging of administrative actions
├─ Impact: Accountability loss, inability to investigate incidents
└─ Mitigation:
├─ Implement comprehensive audit logging
├─ Log all authentication and authorization events
├─ Include timestamps, user identity, IP address, action details
└─ Store logs in tamper-proof storage (write-once)Mitigation Checklist:
Code Pattern:
@Component
@Aspect
public class AuditLoggingAspect {
private static final Logger auditLog = LoggerFactory.getLogger("AUDIT");
@Autowired
private AuditLogRepository auditLogRepository;
@Around("@annotation(Audited)")
public Object logAuditEvent(ProceedingJoinPoint joinPoint) throws Throwable {
MethodSignature signature = (MethodSignature) joinPoint.getSignature();
String methodName = signature.getName();
String className = signature.getDeclaringTypeName();
// Capture context
String username = SecurityContextHolder.getContext()
.getAuthentication().getName();
String ipAddress = RequestContextHolder.currentRequestAttributes()
.getSessionId();
AuditLogEntry entry = new AuditLogEntry();
entry.setTimestamp(Instant.now());
entry.setUsername(username);
entry.setIpAddress(ipAddress);
entry.setAction(className + "." + methodName);
entry.setParameters(Arrays.toString(joinPoint.getArgs()));
try {
// Execute the method
Object result = joinPoint.proceed();
entry.setOutcome("SUCCESS");
entry.setResult(result != null ? result.toString() : "void");
return result;
} catch (Exception e) {
entry.setOutcome("FAILURE");
entry.setErrorMessage(e.getMessage());
throw e;
} finally {
// Always log, even on failure
auditLogRepository.save(entry);
auditLog.info("Audit: {}", entry.toJson());
}
}
}
@Entity
@Table(name = "audit_log")
public class AuditLogEntry {
@Id
@GeneratedValue
private Long id;
@Column(nullable = false, updatable = false)
private Instant timestamp;
@Column(nullable = false, updatable = false)
private String username;
@Column(updatable = false)
private String ipAddress;
@Column(nullable = false, updatable = false)
private String action;
@Column(updatable = false, columnDefinition = "TEXT")
private String parameters;
@Column(nullable = false, updatable = false)
private String outcome;
// Immutable - prevent tampering
@PreUpdate
private void preventUpdate() {
throw new IllegalStateException("Audit log entries cannot be modified");
}
}Threats to Consider:
CIA Platform Attack Scenarios:
Threat: Attacker accesses politician personal contact information
├─ Entry Point: Public API endpoint /api/politicians/{id}
├─ Attack Vector: Insufficient access control, over-fetching data
├─ Impact: GDPR violation, privacy breach
└─ Mitigation:
├─ Implement field-level access control
├─ Return only public data in API responses
├─ Redact or mask sensitive fields (phone, email)
└─ Log all access to PII for audit purposesMitigation Checklist:
Code Pattern:
@RestController
@RequestMapping("/api/politicians")
public class PoliticianController {
@GetMapping("/{id}")
public ResponseEntity<PoliticianDTO> getPolitician(
@PathVariable String id,
@AuthenticationPrincipal UserDetails currentUser) {
Politician politician = politicianService.findById(id)
.orElseThrow(() -> new ResourceNotFoundException("Politician not found"));
// Apply field-level filtering based on user role
PoliticianDTO dto = mapToDTO(politician, currentUser);
// Log PII access for audit
auditLogger.logPIIAccess(currentUser.getUsername(), "Politician", id);
return ResponseEntity.ok(dto);
}
private PoliticianDTO mapToDTO(Politician politician, UserDetails user) {
PoliticianDTO dto = new PoliticianDTO();
// Always include public information
dto.setFirstName(politician.getFirstName());
dto.setLastName(politician.getLastName());
dto.setParty(politician.getParty());
dto.setDistrict(politician.getDistrict());
// Only include sensitive data for authorized users
if (hasRole(user, "ADMIN") || hasRole(user, "RESEARCHER")) {
// Redact instead of exposing full data
dto.setEmail(redactEmail(politician.getEmail()));
dto.setPhone(redactPhone(politician.getPhone()));
}
return dto;
}
private String redactEmail(String email) {
if (email == null) return null;
int atIndex = email.indexOf('@');
if (atIndex > 2) {
return email.substring(0, 2) + "***" + email.substring(atIndex);
}
return "***" + email.substring(atIndex);
}
}
@Configuration
public class SecurityHeadersConfig {
@Bean
public SecurityFilterChain securityHeaders(HttpSecurity http) throws Exception {
http.headers(headers -> headers
.contentSecurityPolicy("default-src 'self'; script-src 'self'; style-src 'self'")
.xssProtection()
.frameOptions().deny()
.httpStrictTransportSecurity()
.maxAgeInSeconds(31536000)
.includeSubDomains(true)
);
return http.build();
}
}Threats to Consider:
CIA Platform Attack Scenarios:
Threat: Attacker overwhelms system with expensive political data queries
├─ Entry Point: Public search API /api/search?query=*
├─ Attack Vector: Recursive queries, unbounded result sets
├─ Impact: Service unavailability, degraded performance for legitimate users
└─ Mitigation:
├─ Implement rate limiting (100 requests/minute per IP)
├─ Query result pagination (max 100 results per page)
├─ Timeout for long-running queries (30 seconds)
└─ Resource quotas per user tierMitigation Checklist:
Code Pattern:
@Configuration
public class RateLimitingConfig {
@Bean
public RateLimiter apiRateLimiter() {
return RateLimiter.create(100.0); // 100 requests per second
}
}
@Component
public class RateLimitingInterceptor implements HandlerInterceptor {
@Autowired
private RateLimiter rateLimiter;
private final LoadingCache<String, AtomicInteger> requestCounts = CacheBuilder.newBuilder()
.expireAfterWrite(1, TimeUnit.MINUTES)
.build(new CacheLoader<String, AtomicInteger>() {
public AtomicInteger load(String key) {
return new AtomicInteger(0);
}
});
@Override
public boolean preHandle(HttpServletRequest request, HttpServletResponse response,
Object handler) throws Exception {
String clientIp = getClientIP(request);
// Apply rate limit
if (!rateLimiter.tryAcquire(1, TimeUnit.SECONDS)) {
response.setStatus(HttpStatus.TOO_MANY_REQUESTS.value());
response.getWriter().write("Rate limit exceeded. Try again later.");
return false;
}
// Check per-IP limit
int requestCount = requestCounts.get(clientIp).incrementAndGet();
if (requestCount > 1000) {
response.setStatus(HttpStatus.TOO_MANY_REQUESTS.value());
response.getWriter().write("IP-based rate limit exceeded.");
return false;
}
return true;
}
}
@Repository
public interface PoliticianSearchRepository extends JpaRepository<Politician, Long> {
// Pageable prevents unbounded result sets
@Query("SELECT p FROM Politician p WHERE " +
"LOWER(p.firstName) LIKE LOWER(CONCAT('%', :searchTerm, '%')) OR " +
"LOWER(p.lastName) LIKE LOWER(CONCAT('%', :searchTerm, '%'))")
@QueryHints(@QueryHint(name = "org.hibernate.timeout", value = "30")) // 30 second timeout
Page<Politician> search(@Param("searchTerm") String searchTerm, Pageable pageable);
}
@RestController
public class SearchController {
private static final int MAX_PAGE_SIZE = 100;
@GetMapping("/api/search")
public Page<PoliticianDTO> search(
@RequestParam String query,
@RequestParam(defaultValue = "0") int page,
@RequestParam(defaultValue = "20") int size) {
// Enforce maximum page size
if (size > MAX_PAGE_SIZE) {
size = MAX_PAGE_SIZE;
}
Pageable pageable = PageRequest.of(page, size);
return searchService.search(query, pageable);
}
}Threats to Consider:
CIA Platform Attack Scenarios:
Threat: Regular user gains administrative access to modify site configuration
├─ Entry Point: Admin API endpoint /api/admin/settings
├─ Attack Vector: Missing @PreAuthorize annotation on controller method
├─ Impact: Unauthorized configuration changes, system compromise
└─ Mitigation:
├─ Enforce role-based access control on all endpoints
├─ Use Spring Security annotations (@PreAuthorize, @Secured)
├─ Implement defense in depth (controller + service layer checks)
└─ Regular access control auditsMitigation Checklist:
Code Pattern:
@RestController
@RequestMapping("/api/admin")
@PreAuthorize("hasRole('ADMIN')") // Controller-level authorization
public class AdminController {
@PostMapping("/settings")
@PreAuthorize("hasAuthority('MODIFY_SETTINGS')") // Method-level check
public ResponseEntity<SystemSettings> updateSettings(
@RequestBody @Valid SystemSettingsRequest request,
@AuthenticationPrincipal UserDetails currentUser) {
// Log privileged action
auditLogger.logPrivilegedAction(
currentUser.getUsername(),
"UPDATE_SYSTEM_SETTINGS",
request.toString()
);
// Service layer also enforces authorization
SystemSettings updated = adminService.updateSettings(request);
return ResponseEntity.ok(updated);
}
}
@Service
public class AdminService {
@PreAuthorize("hasRole('ADMIN')")
public SystemSettings updateSettings(SystemSettingsRequest request) {
// Verify authorization again at service layer (defense in depth)
Authentication auth = SecurityContextHolder.getContext().getAuthentication();
if (!auth.getAuthorities().stream()
.anyMatch(a -> a.getAuthority().equals("ROLE_ADMIN"))) {
throw new AccessDeniedException("Admin role required");
}
// Perform update
SystemSettings settings = settingsRepository.findCurrent();
settings.updateFrom(request);
return settingsRepository.save(settings);
}
}
// Global method security enabled
@Configuration
@EnableGlobalMethodSecurity(prePostEnabled = true, securedEnabled = true)
public class MethodSecurityConfig extends GlobalMethodSecurityConfiguration {
@Override
protected MethodSecurityExpressionHandler createExpressionHandler() {
DefaultMethodSecurityExpressionHandler handler =
new DefaultMethodSecurityExpressionHandler();
handler.setPermissionEvaluator(new CustomPermissionEvaluator());
return handler;
}
}ROOT: Compromise Politician Voting Record Data
├─ AND: Gain Write Access
│ ├─ OR: Exploit Authentication
│ │ ├─ Brute force credentials [Mitigated: Rate limiting]
│ │ ├─ Credential stuffing [Mitigated: 2FA]
│ │ └─ Session hijacking [Mitigated: Secure cookies]
│ └─ OR: Exploit Authorization
│ ├─ Privilege escalation [Mitigated: RBAC]
│ └─ IDOR vulnerability [Mitigated: Ownership checks]
└─ AND: Modify Data
├─ OR: Direct Database Access
│ ├─ SQL injection [Mitigated: Parameterized queries]
│ └─ Database credential theft [Mitigated: Secrets management]
└─ OR: API Manipulation
├─ Parameter tampering [Mitigated: Input validation]
└─ CSRF attack [Mitigated: CSRF tokens]Internet Users (Untrusted)
│
├─→ Application Firewall / Rate Limiter
│ │
│ ├─→ Spring Boot Application (DMZ)
│ │ │
│ │ ├─→ Authentication Filter
│ │ ├─→ Authorization Filter
│ │ └─→ CSRF Protection
│ │
│ └─→ Internal Network (Trusted)
│ │
│ ├─→ PostgreSQL Database (Encrypted)
│ └─→ Redis Session Store (Encrypted)
│
└─→ External APIs (Semi-Trusted)
├─→ Riksdagen API (HTTPS only)
├─→ World Bank API (HTTPS only)
└─→ Election Authority API (HTTPS only)Level 0 DFD - Context Diagram:
[Public Users] → (CIA Web App) → [Database]
[Admin Users] → (CIA Web App) → [External APIs]Security Analysis:
# Threat Model: [Feature Name]
## Overview
- **Component**: [Component being analyzed]
- **Last Updated**: [Date]
- **Reviewer**: [Name]
- **Risk Rating**: [Critical/High/Medium/Low]
## Assets
1. Politician personal information (GDPR protected)
2. Voting records (integrity critical)
3. User credentials (confidentiality critical)
4. API keys for external services
## Trust Boundaries
- Internet → Application Server
- Application Server → Database
- Application Server → External APIs
## STRIDE Analysis
### Spoofing
- **Threat**: [Description]
- **Likelihood**: [High/Medium/Low]
- **Impact**: [High/Medium/Low]
- **Risk**: [Critical/High/Medium/Low]
- **Mitigation**: [Controls in place]
- **Residual Risk**: [Accepted/Needs treatment]
[Repeat for T, R, I, D, E]
## Attack Trees
[Attach attack tree diagrams]
## Security Requirements
1. [Requirement 1]
2. [Requirement 2]
## Security Test Cases
1. Test authentication bypass attempts
2. Test authorization escalation
3. Test input validation
## ISMS Compliance
- ISO 27001:2022 A.5.15 (Access Control)
- NIST CSF PR.AC-4 (Access Permissions)
- CIS Control 6.1 (Access Control Management)
## Sign-off
- **Security Team**: [Approved/Rejected]
- **Development Team**: [Approved/Rejected]
- **Date**: [Date]Threat Management Framework:
All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC
© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/threat-modeling of Hack23/cia.
Open the folder on GitHubat commit 6a9797b
Threat Modeling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Threat Modeling this skillHack23/cia | 239 | — | ~6.8k | Automated safety check: Pass | Apache-2.0 | |
| Fla Ascend Performancefla-org/flash-linear-attention | 5.8k | — | ~5.6k | Automated safety check: Pass | MIT | |
| Forensifyalexgreensh/repo-forensics | 187 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Create Rulecartography-cncf/cartography | 4.1k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT | |
| Auditing Code For Vulnerabilitiestrilwu/secskills | 156 | — | ~3.2k | Automated safety check: Pass | MIT |
fla-org/flash-linear-attention
Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
cartography-cncf/cartography
Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
nordstjernen-web/northstar-browser
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Categories
Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform. Threat Modeling is an agent skill from Hack23/cia.
Threat Modeling fits situations like: tasks that involve Threat modeling.
Run `npx skills add Hack23/cia --skill threat-modeling -a claude-code`. Or copy the skill folder (.github/skills/threat-modeling in Hack23/cia) into .claude/skills/threat-modeling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill threat-modeling -a codex`. Or copy the skill folder (.github/skills/threat-modeling in Hack23/cia) into .agents/skills/threat-modeling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill threat-modeling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-modeling, .gemini/skills/threat-modeling, .github/skills/threat-modeling and .opencode/skills/threat-modeling in your project.
SKILL.md names no scripts, command-line tools or credentials: Threat Modeling is instructions for the agent only.
SKILL.md names 8 domains. As links in the text: github.com, owasp.org, learn.microsoft.com, versprite.com, attack.mitre.org, iso.org, csrc.nist.gov and microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Threat Modeling is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Threat Modeling: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Forensify (alexgreensh/repo-forensics, 187 stars), Create Rule (cartography-cncf/cartography, 4.1k stars) and Commit Security Scan (codexstar69/bug-hunter, 519 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.