Agent skill

Linddun Threat Model

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance.

Apache-2.0Auto-check passedSecurity

Install Linddun Threat Model

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill linddun-threat-model -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills linddun-threat-model --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/linddun-threat-model .claude/skills/linddun-threat-model && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
linddun-threat-model
GitHub stars
301
Token cost
~3.2k tokens
SKILL.md length
1,270 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance.

  • Works in 4 steps: Create Privacy-Annotated Data Flow Diagram → Map Threats to DFD Elements → Build Threat Trees → …
  • Tasks that involve Threat modeling
  • SKILL.md covers Overview, The Seven LINDDUN Threat…, DFD-Based Threat Analysis… and LINDDUN and STRIDE Integration, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Linddun Threat Model is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat trees, privacy-specific mitigation strategies, and integration with STRIDE security threat modeling.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Security, covering Threat modeling. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Threat modeling

Example prompts

  • “/linddun-threat-model”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Create Privacy-Annotated Data Flow Diagram
  2. Map Threats to DFD Elements
  3. Build Threat Trees
  4. Prioritize and Mitigate

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Linddun Threat Model loads about 3.2k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 1,270 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,270 words, ~3,205 tokens.

Download SKILL.mdSave it as .claude/skills/linddun-threat-model/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
linddun-threat-model
description
Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat trees, privacy-specific mitigation strategies, and integration with STRIDE security threat modeling.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
privacy-engineering
metadata.tags
linddun, threat-modeling, privacy-threats, dfd-analysis, privacy-mitigation

LINDDUN Privacy Threat Modeling

Overview

LINDDUN is a systematic privacy threat modeling methodology developed by the DistriNet research group at KU Leuven. It provides a structured approach to identify and mitigate privacy threats in software systems. The acronym represents seven privacy threat categories that map to violations of privacy properties defined in ISO/IEC 29100.

The Seven LINDDUN Threat Categories

L — Linking

Definition: The ability to associate two or more data items or actions with an individual or group, beyond what is intended by the data subject.

Privacy Property Violated: Unlinkability

Threat Scenarios:

  • Cross-referencing anonymized datasets to re-identify individuals
  • Correlating browsing behavior across websites using fingerprinting
  • Linking social media profiles to real identities through metadata
  • Combining location data points to infer home/work addresses

Mitigation Strategies:

StrategyTechniqueImplementation
Data minimizationCollect only necessary attributesReview each data field against stated purpose
PseudonymizationReplace identifiers with tokensUse cryptographic pseudonymization with key separation
Mix networksObscure communication patternsRoute messages through anonymity networks
AggregationPresent only group-level dataEnforce minimum group size (k>=5) for any query result
Session unlinkabilityPrevent cross-session trackingRotate session tokens, avoid persistent identifiers
I — Identifying

Definition: The ability to identify a data subject from a set of data items, connecting them to a known individual.

Privacy Property Violated: Anonymity

Threat Scenarios:

  • Direct identification from unmasked PII in logs
  • Quasi-identifier attacks (combining age, ZIP code, gender)
  • Facial recognition from images in datasets
  • Voice identification from audio recordings
  • Writing style analysis (stylometry) in anonymous forums

Mitigation Strategies:

StrategyTechniqueImplementation
AnonymizationRemove direct identifiersStrip names, emails, SSNs before processing
k-AnonymityGeneralize quasi-identifiersEnsure each record shares attributes with k-1 others
Differential privacyAdd calibrated noiseApply epsilon-differential privacy to query responses
Data maskingObscure identifying fieldsReplace with realistic synthetic values
Access controlRestrict who can see raw dataImplement need-to-know access with purpose verification
N — Non-repudiation

Definition: The inability of a data subject to deny having performed an action, even when such denial would be desirable for privacy.

Privacy Property Violated: Plausible deniability

Threat Scenarios:

  • Immutable audit logs linking users to actions
  • Digital signatures proving authorship of documents
  • Non-repudiable transaction records
  • Email delivery confirmations and read receipts
  • Blockchain-based records that cannot be denied or deleted

Mitigation Strategies:

StrategyTechniqueImplementation
Deniable encryptionEnable plausible deniabilityUse deniable encryption schemes for sensitive data
Group signaturesHide individual identity in groupImplement group signature schemes for authenticated actions
Minimal loggingLog only what is legally requiredReview and minimize audit trail scope
Aggregate reportingReport actions at group levelAggregate activity reports rather than individual-level
Configurable receiptsLet users control acknowledgmentsAllow opt-out of read receipts and delivery confirmations
D — Detecting

Definition: The ability to determine whether a data subject has been involved in an action or is present in a dataset, even without identifying them specifically.

Privacy Property Violated: Undetectability

Threat Scenarios:

  • Traffic analysis revealing communication patterns
  • Database membership inference attacks
  • Timing attacks revealing user activity
  • Side-channel attacks revealing data access patterns
  • Presence detection through network metadata

Mitigation Strategies:

StrategyTechniqueImplementation
Traffic paddingMask communication patternsGenerate dummy traffic to obscure real patterns
SteganographyHide data within other dataEmbed sensitive communications in innocuous content
Constant-time operationsPrevent timing analysisImplement constant-time algorithms for sensitive operations
Oblivious RAMHide access patternsUse ORAM protocols for privacy-critical data access
Differential privacyProvide membership privacyApply differential privacy to prevent membership inference
D — Data Disclosure

Definition: Unauthorized exposure of personal data to parties who should not have access.

Privacy Property Violated: Confidentiality

Threat Scenarios:

  • SQL injection exposing database contents
  • Misconfigured cloud storage buckets
  • Insider threats with excessive access privileges
  • Man-in-the-middle attacks on unencrypted channels
  • API responses returning excessive data fields
  • Backup media loss or theft

Mitigation Strategies:

StrategyTechniqueImplementation
EncryptionProtect data at rest and in transitAES-256 at rest, TLS 1.3 in transit
Access controlEnforce least privilegeRBAC with regular access reviews
Input validationPrevent injection attacksParameterized queries, input sanitization
API field filteringReturn only requested fieldsImplement field-level access control in APIs
DLPDetect and prevent data exfiltrationDeploy DLP at network egress and endpoints
U — Unawareness

Definition: Data subjects being insufficiently aware of data processing activities, their rights, or the consequences of providing or withholding data.

Privacy Property Violated: Transparency, Intervenability

Threat Scenarios:

  • Hidden data collection through tracking pixels
  • Opaque algorithmic decision-making
  • Buried privacy policies with complex legal language
  • Undisclosed data sharing with third parties
  • Lack of notification when processing purposes change
  • No mechanism for data subjects to exercise rights

Mitigation Strategies:

StrategyTechniqueImplementation
Layered noticesProgressive disclosureShort notice + full policy + just-in-time
Privacy dashboardsCentralized visibilityUser-facing dashboard showing all data held
Consent managementGranular, informed consentPurpose-specific consent with clear descriptions
Explainable AIAlgorithmic transparencyProvide meaningful explanations of automated decisions
Right facilitationEasy rights exerciseSelf-service portal for access, correction, deletion
Show full SKILL.md (468 more words)Show less
N — Non-compliance

Definition: Processing personal data in ways that violate applicable laws, regulations, standards, or organizational policies.

Privacy Property Violated: Policy and consent compliance

Threat Scenarios:

  • Processing without valid legal basis
  • Failing to honor data subject rights within deadlines
  • Cross-border transfers without adequate safeguards
  • Retaining data beyond the stated retention period
  • Processing children's data without parental consent
  • Failing to conduct required impact assessments

Mitigation Strategies:

StrategyTechniqueImplementation
Compliance mappingMap processing to legal basesDocument legal basis per processing activity per jurisdiction
Automated enforcementTechnical compliance controlsAutomated retention enforcement, consent verification
DPIA processImpact assessment for high-risk processingMandatory DPIA before deploying new high-risk processing
Regulatory monitoringTrack legal developmentsSubscribe to regulatory updates, conduct periodic gap analysis
Audit programVerify ongoing complianceAnnual compliance audits with corrective action tracking

DFD-Based Threat Analysis Process

Step 1: Create Privacy-Annotated Data Flow Diagram
[Data Subject] ---(personal data)--> [Web Application]
     ^                                      |
     |                                      v
  [Notice]                          [Application Server]
                                          |
                            +-------------+-------------+
                            |             |             |
                            v             v             v
                    [User Database] [Analytics DB] [Third-Party API]
                    (encrypted)     (pseudonymized) (data sharing)

Annotate each element with:

  • Data types flowing through (PII categories)
  • Trust boundaries crossed
  • Storage locations and durations
  • Processing purposes
  • Access controls in place
Step 2: Map Threats to DFD Elements
DFD ElementLIND(etect)D(isclose)UN(on-comply)
Data flowsXXXX
Data storesXXXX
ProcessesXXXXXXX
External entitiesXXXXX
Step 3: Build Threat Trees

For each applicable threat category per DFD element, construct a threat tree:

Identifying Threat to User Database
├── Direct identifier exposure
│   ├── SQL injection reveals raw PII
│   ├── Backup media contains unencrypted PII
│   └── Admin access to production database
├── Quasi-identifier attack
│   ├── Combination of age + ZIP + gender
│   └── Temporal correlation of records
└── Inference attack
    ├── Aggregate query with small group size
    └── Differential attack across query results
Step 4: Prioritize and Mitigate

Use a risk matrix to prioritize identified threats:

Likelihood / ImpactNegligibleLimitedSignificantMaximum
Very LikelyMediumHighCriticalCritical
LikelyLowMediumHighCritical
PossibleLowMediumMediumHigh
UnlikelyLowLowMediumMedium
RareLowLowLowMedium

LINDDUN and STRIDE Integration

LINDDUN CategoryRelated STRIDE CategoryOverlap Area
Data DisclosureInformation DisclosureBoth address unauthorized data exposure
Non-complianceTamperingIntegrity of consent records
DetectingInformation DisclosureMetadata leakage
IdentifyingInformation DisclosurePII exposure
Non-repudiationRepudiationOpposing perspectives on the same property

Practical Application at Cipher Engineering Labs

Threat Modeling Workshop Agenda (4 hours)
  1. System Overview (30 min): Present the system architecture and data flows
  2. DFD Construction (45 min): Collaboratively build privacy-annotated DFD
  3. Threat Identification (90 min): Walk through each LINDDUN category per DFD element
  4. Prioritization (30 min): Score threats on risk matrix
  5. Mitigation Planning (45 min): Identify controls for high and critical risks
Deliverables
  • Privacy-annotated Data Flow Diagram
  • LINDDUN Threat Register (all identified threats with risk scores)
  • Mitigation Plan (prioritized controls for high/critical threats)
  • Residual Risk Statement

References

  • Deng, M., Wuyts, K., Scandariato, R., Preneel, B., and Joosen, W. "A Privacy Threat Analysis Framework: Supporting the Elicitation and Fulfillment of Privacy Requirements." Requirements Engineering, 16(1):3-32, 2011.
  • Wuyts, K. and Joosen, W. "LINDDUN Privacy Threat Modeling: A Tutorial." CW Reports, KU Leuven, 2015.
  • LINDDUN GO — Lightweight approach: linddun.org
  • ISO/IEC 29100:2011 — Information Technology — Security Techniques — Privacy Framework
  • OWASP Privacy Risks Project

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/linddun-threat-model of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Linddun Threat Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Linddun Threat Model compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Linddun Threat Model this skillmukul975/Privacy-Data-Protection-Skills301—~3.2kAutomated safety check: PassApache-2.0
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Create Rulecartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0
Commit Security Scancodexstar69/bug-hunter520—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills157—~3.2kAutomated safety check: PassMIT
Threat Mitigation Mappingwshobson/agents40k8 repos~742Automated safety check: PassMIT

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    520 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed
  • Audit Browser Security Boundaries

    nordstjernen-web/northstar-browser

    Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

    128 GitHub stars~920 tokensUpdated today
    SecurityAuto-check passed

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Categories

Questions about Linddun Threat Model

What does Linddun Threat Model do?

Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Linddun Threat Model is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance.

When should I use Linddun Threat Model?

Linddun Threat Model fits situations like: tasks that involve Threat modeling.

How do I install Linddun Threat Model in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill linddun-threat-model -a claude-code`. Or copy the skill folder (skills/privacy/linddun-threat-model in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/linddun-threat-model in your project. Claude Code loads it when a task matches its description.

How do I install Linddun Threat Model in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill linddun-threat-model -a codex`. Or copy the skill folder (skills/privacy/linddun-threat-model in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/linddun-threat-model in your project. Codex loads it when a task matches its description.

Can I use Linddun Threat Model in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill linddun-threat-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/linddun-threat-model, .gemini/skills/linddun-threat-model, .github/skills/linddun-threat-model and .opencode/skills/linddun-threat-model in your project.

What does Linddun Threat Model need to run?

Going by SKILL.md and its folder, Linddun Threat Model needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Linddun Threat Model access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Linddun Threat Model safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Linddun Threat Model use?

Linddun Threat Model is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Linddun Threat Model use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 872 tokens, read only when the agent opens those files.

What are the alternatives to Linddun Threat Model?

Skills that share tags, products or a category with Linddun Threat Model: Forensify (alexgreensh/repo-forensics, 190 stars), Create Rule (cartography-cncf/cartography, 4.1k stars), Commit Security Scan (codexstar69/bug-hunter, 520 stars) and Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Linddun Threat Model?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.