Agent skill

Performing Threat Modeling With Owasp Threat Dragon

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF…

Apache-2.0Auto-check passedSecurity

Install Performing Threat Modeling With Owasp Threat Dragon

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-threat-modeling-with-owasp-threat-dragon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-threat-modeling-with-owasp-threat-dragon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-threat-modeling-with-owasp-threat-dragon .claude/skills/performing-threat-modeling-with-owasp-threat-dragon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-threat-modeling-with-owasp-threat-dragon
GitHub stars
34k
Token cost
~2.1k tokens
SKILL.md length
810 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF…

  • Works in 7 steps: Install Threat Dragon → Define the Scope → Create Data Flow Diagrams → …
  • Tasks that involve Threat modeling
  • SKILL.md covers Overview, When to Use, Prerequisites and Threat Modeling Methodologies, plus 5 more sections
  • Runs Python scripts from its folder; calls openssl and docker; needs ENCRYPTION_JWT_SIGNING_KEY and ENCRYPTION_JWT_REFRESH_SIGNING_KEY

What it does

Performing Threat Modeling With Owasp Threat Dragon is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF threat model reports. Use during secure design review of an application architecture to build a formal threat model and document mitigations for GRC compliance.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Threat modeling and Web application vulnerabilities. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “Use the performing-threat-modeling-with-owasp-threat-dragon skill to use OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify…”
  • “/performing-threat-modeling-with-owasp-threat-dragon”

Requirements

  • Python 3
  • Docker
  • A credential in ENCRYPTION_JWT_SIGNING_KEY
  • A credential in ENCRYPTION_JWT_REFRESH_SIGNING_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Install Threat Dragon
  2. Define the Scope
  3. Create Data Flow Diagrams
  4. Identify Threats
  5. Define Mitigations
  6. Generate Reports
  7. Integrate into SDLC

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • openssl
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • owasp.org
    • cheatsheetseries.owasp.org
    • learn.microsoft.com
    • linddun.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ENCRYPTION_JWT_SIGNING_KEY
    • ENCRYPTION_JWT_REFRESH_SIGNING_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Threat Modeling With Owasp Threat Dragon loads about 2.1k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 810 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 810 words, ~2,136 tokens.

Download SKILL.mdSave it as .claude/skills/performing-threat-modeling-with-owasp-threat-dragon/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-threat-modeling-with-owasp-threat-dragon
description
Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF threat model reports. Use during secure design review of an application architecture to build a formal threat model and document mitigations for GRC compliance.
domain
cybersecurity
subdomain
devsecops
tags
threat-modeling, owasp, threat-dragon, stride, linddun, secure-design, dfd, data-flow
version
1.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
nist_csf
PR.PS-01, GV.SC-07, ID.IM-04, PR.PS-04
mitre_attack
T1195, T1554, T1059.004

Performing Threat Modeling with OWASP Threat Dragon

Overview

OWASP Threat Dragon is an open-source threat modeling tool that enables security teams and developers to create threat model diagrams, identify threats using established methodologies (STRIDE, LINDDUN, CIA, DIE, PLOT4ai), and generate comprehensive reports. Threat Dragon runs as both a web application and desktop application (Windows, macOS, Linux), supporting distributed teams working collaboratively on threat models. Version 2.x provides drag-and-drop diagram creation, an auto-generation rule engine for threats and mitigations, and PDF report output for documentation and GRC compliance.

When to Use

  • When conducting security assessments that involve performing threat modeling with owasp threat dragon
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • OWASP Threat Dragon desktop application or web instance
  • Understanding of data flow diagram (DFD) notation
  • Familiarity with STRIDE or LINDDUN threat classification
  • Application architecture documentation and network diagrams
  • Stakeholder access for design review sessions

Threat Modeling Methodologies

STRIDE
CategoryThreat TypeDescriptionExample
SSpoofingImpersonating a user or systemStolen session tokens
TTamperingModifying data in transit or at restSQL injection altering records
RRepudiationDenying an action occurredMissing audit logs
IInformation DisclosureExposing sensitive dataAPI returning excessive fields
DDenial of ServiceMaking a service unavailableResource exhaustion attack
EElevation of PrivilegeGaining unauthorized accessBroken access control
LINDDUN (Privacy-Focused)
CategoryThreat TypeDescription
LLinkabilityAssociating data items across contexts
IIdentifiabilityIdentifying an individual from data
NNon-repudiationInability to deny an action (privacy risk)
DDetectabilityDetermining if data about a subject exists
DDisclosureExposing personal information
UUnawarenessUser unaware of data collection
NNon-complianceViolating privacy regulations

Workflow

Step 1 --- Install Threat Dragon

Desktop Application: Download the installer from the OWASP Threat Dragon releases page for Windows (.exe), macOS (.dmg), or Linux (.AppImage/.deb/.rpm).

Web Application (Docker):

bash
docker run -p 3000:3000 \
  -e ENCRYPTION_JWT_SIGNING_KEY=$(openssl rand -hex 32) \
  -e ENCRYPTION_JWT_REFRESH_SIGNING_KEY=$(openssl rand -hex 32) \
  -e ENCRYPTION_KEYS='[{"isPrimary":true,"id":0,"value":"'$(openssl rand -hex 16)'"}]' \
  -e NODE_ENV=production \
  owasp/threat-dragon:latest
Step 2 --- Define the Scope

Before creating diagrams, document the scope:

  • System name and description
  • Assets being protected (user data, credentials, payment info)
  • External dependencies (third-party APIs, cloud services)
  • Compliance requirements (GDPR, HIPAA, PCI DSS)
  • Trust boundaries (network segments, authentication zones)
Step 3 --- Create Data Flow Diagrams

In Threat Dragon, create a new threat model and add diagrams using the following DFD elements:

Processes: Applications, microservices, API endpoints that transform data. Represented as circles/rounded rectangles.

Data Stores: Databases, file systems, caches, message queues that persist data. Represented as parallel lines.

External Entities: Users, external systems, third-party services outside the trust boundary. Represented as rectangles.

Data Flows: Communication channels between elements showing data direction. Represented as arrows with labels describing the data.

Trust Boundaries: Dashed lines separating zones of different trust levels (internet/DMZ/internal network, user/admin).

Show full SKILL.md (358 more words)Show less
Step 4 --- Identify Threats

For each DFD element, apply the STRIDE methodology:

Element TypeApplicable STRIDE Categories
External EntitySpoofing, Repudiation
ProcessSpoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege
Data StoreTampering, Information Disclosure, DoS
Data FlowTampering, Information Disclosure, DoS

Threat Dragon's rule engine automatically suggests threats based on element types. Review each suggestion and mark as:

  • Mitigated: Existing controls address the threat
  • Not Applicable: Threat does not apply to this context
  • Open: Threat needs to be addressed (assign priority and owner)
Step 5 --- Define Mitigations

For each open threat, document:

  • Mitigation strategy (prevent, detect, respond, transfer)
  • Specific technical controls (encryption, authentication, rate limiting)
  • Owner responsible for implementation
  • Priority and timeline for remediation
Step 6 --- Generate Reports

Threat Dragon produces PDF reports containing:

  • Executive summary of the threat model
  • Data flow diagrams with annotations
  • Threat inventory with severity ratings
  • Mitigation status and recommendations
  • Compliance mapping where applicable
Step 7 --- Integrate into SDLC
  • Conduct threat modeling during the design phase of new features
  • Update threat models when architecture changes occur
  • Review threat models during security design reviews
  • Store threat model files in version control alongside code
  • Reference threat model findings in security acceptance criteria

Threat Model File Format

Threat Dragon uses JSON format for threat models, enabling version control and programmatic manipulation:

json
{
  "version": "2.2.0",
  "summary": {
    "title": "E-Commerce Application",
    "owner": "Security Team",
    "description": "Threat model for the checkout flow"
  },
  "detail": {
    "contributors": [
      {"name": "Security Architect"}
    ],
    "diagrams": [
      {
        "id": 0,
        "title": "Checkout Flow",
        "diagramType": "STRIDE",
        "cells": []
      }
    ]
  }
}

CycloneDX TMBOM Integration

Threat Dragon participates in the CycloneDX Threat Model Bill of Materials (TMBOM) effort, enabling export to a common format that can be consumed by other threat modeling tools and GRC platforms, preventing vendor lock-in.

Best Practices

  1. Start simple: Begin with high-level DFDs (Level 0) before decomposing into detailed diagrams
  2. Involve developers: Include development team members in threat modeling sessions for realistic threat assessment
  3. Time-box sessions: Limit initial sessions to 90 minutes; iterate in follow-up sessions
  4. Prioritize by risk: Use severity ratings (Critical, High, Medium, Low) to prioritize mitigations
  5. Living documents: Treat threat models as living documents that evolve with the system
  6. Automate where possible: Use the rule engine for initial threat generation, then refine manually

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-threat-modeling-with-owasp-threat-dragon of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Threat Modeling With Owasp Threat Dragon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Threat Modeling With Owasp Threat Dragon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Threat Modeling With Owasp Threat Dragon this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Audit Scannerruvnet/ruflo74k1 repos~823Automated safety check: PassMIT
Security and Hardeningaddyosmani/agent-skills105k1 repos~4.4kAutomated safety check: NotesMIT
CybersecurityAgriciDaniel/claude-cybersecurity228—~11kAutomated safety check: WarnMIT
Securitygaragon/nanostack207—~3.7kAutomated safety check: NotesApache-2.0

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 1 repo~823 tokens
    SecurityAuto-check passed
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    105k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Cybersecurity

    AgriciDaniel/claude-cybersecurity

    Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

    228 GitHub stars~11k tokensUpdated 5 mo ago
    SecurityAuto-check: warnings
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Vulnerability Scanner

    xenitV1/Antigravity-Workflows

    Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 7 repos~1.8k tokens
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Threat Modeling With Owasp Threat Dragon

What does Performing Threat Modeling With Owasp Threat Dragon do?

Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF…. Performing Threat Modeling With Owasp Threat Dragon is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF threat model reports.

When should I use Performing Threat Modeling With Owasp Threat Dragon?

Performing Threat Modeling With Owasp Threat Dragon fits situations like: tasks that involve Threat modeling; tasks that involve Web application vulnerabilities.

How do I install Performing Threat Modeling With Owasp Threat Dragon in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-threat-modeling-with-owasp-threat-dragon -a claude-code`. Or copy the skill folder (skills/performing-threat-modeling-with-owasp-threat-dragon in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-threat-modeling-with-owasp-threat-dragon in your project. Claude Code loads it when a task matches its description.

How do I install Performing Threat Modeling With Owasp Threat Dragon in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-threat-modeling-with-owasp-threat-dragon -a codex`. Or copy the skill folder (skills/performing-threat-modeling-with-owasp-threat-dragon in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-threat-modeling-with-owasp-threat-dragon in your project. Codex loads it when a task matches its description.

Can I use Performing Threat Modeling With Owasp Threat Dragon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-threat-modeling-with-owasp-threat-dragon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-threat-modeling-with-owasp-threat-dragon, .gemini/skills/performing-threat-modeling-with-owasp-threat-dragon, .github/skills/performing-threat-modeling-with-owasp-threat-dragon and .opencode/skills/performing-threat-modeling-with-owasp-threat-dragon in your project.

What does Performing Threat Modeling With Owasp Threat Dragon need to run?

Going by SKILL.md and its folder, Performing Threat Modeling With Owasp Threat Dragon needs Python for the scripts in its folder, the command-line tools its instructions call (openssl and docker) and credentials named ENCRYPTION_JWT_SIGNING_KEY and ENCRYPTION_JWT_REFRESH_SIGNING_KEY. Our summary lists: Python 3; Docker; A credential in ENCRYPTION_JWT_SIGNING_KEY; A credential in ENCRYPTION_JWT_REFRESH_SIGNING_KEY.

Does Performing Threat Modeling With Owasp Threat Dragon access the network?

SKILL.md names 5 domains. As links in the text: github.com, owasp.org, cheatsheetseries.owasp.org, learn.microsoft.com and linddun.org. This is read from the text; nothing was executed.

Is Performing Threat Modeling With Owasp Threat Dragon safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Threat Modeling With Owasp Threat Dragon use?

Performing Threat Modeling With Owasp Threat Dragon is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Threat Modeling With Owasp Threat Dragon use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Performing Threat Modeling With Owasp Threat Dragon?

Skills that share tags, products or a category with Performing Threat Modeling With Owasp Threat Dragon: Security And Hardening (penpot/penpot, 61k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars), Security and Hardening (addyosmani/agent-skills, 105k stars) and Cybersecurity (AgriciDaniel/claude-cybersecurity, 228 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Threat Modeling With Owasp Threat Dragon?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.