Agent skill

Omh Application Threat Model

by rlaope in rlaope/oh-my-hermes

[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds.

MITAuto-check passedSecurity

Install Omh Application Threat Model

skills CLI
$ npx skills add rlaope/oh-my-hermes --skill omh-application-threat-model -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rlaope/oh-my-hermes omh-application-threat-model --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rlaope/oh-my-hermes.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/omh-application-threat-model .claude/skills/omh-application-threat-model && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
omh-application-threat-model
GitHub stars
3.2k
Token cost
~2.6k tokens
SKILL.md length
1,345 words
Files
2 (incl. references)
Skills in repo
143
Repo updated
First seen
Licence
MIT

At a glance

[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds.

  • The user says: application-threat-model
  • SKILL.md covers Why This Exists, Do Not Use When, Examples and Completion Checklist, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Application threat model

What it does

Omh Application Threat Model is an agent skill from rlaope/oh-my-hermes. [omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Use when the user says: application-threat-model, application threat model, threat model, threat modeling, threat modelling, threat modeling session, threat modeling workshop, security threat model.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/threat-model-method.md`).

It sits in Security, covering Threat modeling. The repository describes itself as: All in one plugin for Hermes Agent ⚚ the coding intelligence, a long-term memory system and model optimized workflow packages. The licence is MIT.

When your agent uses it

  • The user says: application-threat-model
  • Application threat model
  • Threat modeling
  • Threat modelling

Example prompts

  • “/omh-application-threat-model”

What it can do on your machine

Read from SKILL.md and the folder at commit 7cd0d02. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Omh Application Threat Model loads about 2.6k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,345 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from rlaope/oh-my-hermes at commit 7cd0d02, republished under its MIT licence (© rlaope). 1,345 words, ~2,576 tokens.

Download SKILL.mdSave it as .claude/skills/omh-application-threat-model/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
omh-application-threat-model
description
[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Use when the user says: application-threat-model, application threat model, threat model, threat modeling, threat modelling, threat modeling session, threat modeling workshop, security threat model.

Application Threat Model

This is a Hermes-native application-threat-model workflow skill.

Why This Exists

application-threat-model exists because the nearest neighbour does not merely miss this request. security-safety-review maps the agent's own prompt, tool, credential, and dependency surface, so an application threat-model request came back as an agent tool inventory under a near-identical name — a confident wrong artifact rather than a miss, in the one domain where that costs most.

Do Not Use When

  • The subject is the agent's own prompts, tools, files, credentials, dependencies, or destructive actions; use security-safety-review, which maps that runtime surface.
  • The user wants defects found in a diff or a file; use code-review.
  • The user asks whether a release is ready across rollout, rollback, and observability; use production-audit.
  • The user asks which commands prove a merge is safe; use verification-gate.
  • The user asks for a contractual or regulatory obligation rather than an attacker; use legal-compliance-review.

Examples

Good example:

  • Prompt: build a threat model for our payment service architecture
  • Expected behavior: Prepare application_threat_model/v1: ask for the component map and data flows, register card data and settlement records as assets, mark the merchant API edge and the PSP callback as trust boundaries, derive scenarios per boundary, decide a control for each, and name the test that fails when the control is removed.
  • Why: The subject is an application the user operates, and the goal needs assets, boundaries, scenarios, controls, and tests.

Bad example:

  • Prompt: application-threat-model check whether this agent can be prompt-injected through its file tool
  • Expected behavior: Route to security-safety-review: prompts, tools, and credentials are the agent's runtime surface, not an application this workflow models.
  • Why: The two surfaces share vocabulary and nothing else; modeling the agent's runtime here is how the artifacts get confused.

Completion Checklist

  • Every asset carries a data class and one named loss; every boundary names what crosses it and what authenticates the crossing.
  • Every scenario resolves to mitigate, transfer, accept, or eliminate, with an owner.
  • Every mitigating control carries a security test and the observable that fails without it.
  • Controls read deployed, planned, or unverified; none is inferred from the architecture description.
  • Residual risk is listed, and the model is not offered as a scan, a penetration test, or an attestation.

Recovery Notes

  • If the architecture is not described, ask for the component map and the data flows before modeling; never substitute a generic checklist for the real system.
  • If a scenario has no boundary and no asset, drop it with the reason rather than carrying an unreachable threat.
  • If the user asks for exploit code, give the precondition and the detection signal instead, then hand remediation to an executor.
  • If the request turns out to be about the agent's own prompts, tools, or credentials, stop and hand it to security-safety-review.

Workflow Lane

  • Current lane: Coding handoff (idea-to-deploy, llm-app-dev, cto-loop, deploy-and-monitor, code-review, build-failure-triage, verification-gate, security-safety-review, +28 more) - coding owners, handoffs, review, CI, and merge evidence.
  • If intent belongs to another lane, hand back to oh-my-hermes or name the adjacent workflow.
  • Shared product, routing, compatibility, and evidence rules: omh-routing/references/skill-common-rail.md.

Use When

Use when Hermes must model the security of an application, service, or deployed system the user operates: which assets are worth taking, where trust changes hands, how an attacker reaches each asset, which control stops them, and which security test fails when that control is removed. The subject is the modeled system, never the agent's own runtime.

Strong routing signals: `application-threat-model`, `application threat model`, `threat model`, `threat modeling`, `threat modelling`, `threat modeling session`, `threat modeling workshop`, `security threat model`, `build a threat model`, `model the threats`, `threat scenarios`, `stride analysis`, `stride model`, `trust boundary`, `trust boundaries`, `attack scenario`, `attack scenarios`, `attack tree`, `attack trees`, `abuse case`, `abuse cases`, `security design review`, `security architecture review`, `architecture security review`, `how would an attacker`, `how could an attacker`, `what could an attacker do`, `attacker perspective`

Catalog Metadata

Category: review Phase: application-threat-model Hermes role: reviewer Quality tier: security-safety-gated Reasoning demand: standard

Quality bar:

  • Name every component, data store, and external dependency of the real system before naming one threat; a model of a system nobody described is a checklist.
  • Give each asset a data class and exactly one loss: disclosure, corruption, unavailability, or fraud.
  • For each trust boundary, state what crosses it, what authenticates the crossing, and what the receiver assumes without checking.
  • Run all six STRIDE prompts from omh-application-threat-model/references/threat-model-method.md per boundary; drop an unreachable scenario with its reason instead of carrying it.
  • Resolve every scenario to one decision (mitigate, transfer, accept, eliminate) with an owner, and give every mitigating control a test whose observable fails when the control is removed.

Handoff policy:

Keep the model in Hermes: assets, boundaries, scenarios, control decisions, and test definitions are analysis over architecture the user supplies. Writing the tests, running a scanner, changing an IAM policy, or patching a component is executor work and needs observed evidence before a control counts as deployed.

Required inputs:

  • the system under review: components, which component calls which, and where each is deployed
  • data flows and data classes: what every store, queue, and message carries
  • known trust boundaries: authentication points, network edges, tenant separation, third parties
  • controls already deployed, and who owns each
  • scope exclusions and the threat actors in scope
Show full SKILL.md (478 more words)Show less

Expert clarification questions:

  • the system under review: components, which component calls which, and where each is deployed
    • English: Which components make up the system, which of them call each other, and where does each one run?
    • Korean: 이 시스템은 어떤 컴포넌트로 구성되고, 서로 어떤 호출 관계이며, 각각 어디에서 실행되나요?
  • scope exclusions and the threat actors in scope
    • English: Which attackers are in scope — external, authenticated tenant, insider, compromised dependency — and what is out of scope?
    • Korean: 어떤 공격자를 범위에 포함하나요 — 외부, 인증된 테넌트, 내부자, 침해된 의존성 — 그리고 제외 범위는 무엇인가요?

Expected outputs:

  • application_threat_model/v1
  • asset register: data class plus the one loss that makes each asset worth defending
  • trust boundaries: what crosses, what authenticates the crossing, what the receiver assumes unchecked
  • attack scenarios: entry point, path, precondition, impact
  • one decision per scenario (mitigate, transfer, accept, eliminate) with an owner
  • per-control security test naming the observable that fails without it, plus residual risk

Artifact expectations:

  • application_threat_model/v1 with asset register, trust boundaries, attack scenarios, control decisions, and per-control tests
  • every control marked deployed, planned, or unverified; a scenario with no boundary and no asset is dropped, never carried

Safety rules:

  • Never write working exploit code, a payload, or a runnable attack script; a scenario names the entry point, the path, and the precondition, not the weapon.
  • Do not record a control as deployed because the architecture describes it; an unobserved control is unverified until configuration or a passing test says otherwise.
  • Do not model the agent's own prompts, tools, credentials, or dependencies here; that surface belongs to security-safety-review.
  • Never print secrets, tokens, keys, connection strings, or live customer records pulled in as examples.
  • A model is not a penetration test, a scan, or a compliance attestation; name which of the three the user still needs.

Runtime Evidence

Record observed delegation results; otherwise return not_available or not_observed. Prepared OMH routing is not execution, review, CI, merge-readiness, or merge evidence.

  • Treat wrapper memory/context summaries as advisory local context, not proof of opaque Hermes memory reads or changes. Preserve workflow intent and stop conditions; verify before claiming completion. Reply in the user's own words and the host's own voice: its SOUL.md persona owns reply language, tone, speech level, and sentence endings, progress updates included (where it sets no language, use the one the user wrote in), and OMH shapes structure and content only; OMH's record terms (surface, lane, wrapper, handoff, evidence boundary, not_observed) stay in records and tool calls, never in the sentence the user reads unless they ask about one; and when a stop condition or a decision the user owns ends the turn, offer the next action as a question rather than declaring what will not be done.

Use Hermes-native subagent/delegation features when available: native subagents -> Hermes delegation when available, otherwise sequential lanes.

Shared product, compatibility, topology, memory, harness, and execution rules: omh-routing/references/skill-common-rail.md. Load it when applicable; otherwise name an unavailable capability.

© rlaope, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/omh-application-threat-model of rlaope/oh-my-hermes.

  • SKILL.md
  • references/threat-model-method.md

Open the folder on GitHubat commit 7cd0d02

Compare with similar skills

Omh Application Threat Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Omh Application Threat Model compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Omh Application Threat Model this skillrlaope/oh-my-hermes3.2k—~2.6kAutomated safety check: PassMIT
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Create Rulecartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0
Commit Security Scancodexstar69/bug-hunter520—~629Automated safety check: PassMIT
Auditing Code For Vulnerabilitiestrilwu/secskills157—~3.2kAutomated safety check: PassMIT
Threat Mitigation Mappingwshobson/agents40k8 repos~742Automated safety check: PassMIT

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check: notes
  • Create Rule

    cartography-cncf/cartography

    Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

    4.1k GitHub stars~3k tokensUpdated today
    SecurityAuto-check passed
  • Commit Security Scan

    codexstar69/bug-hunter

    Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

    520 GitHub stars~629 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

    40k GitHub starsUsed in 8 repos~742 tokens
    SecurityAuto-check passed
  • Audit Browser Security Boundaries

    nordstjernen-web/northstar-browser

    Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

    127 GitHub stars~920 tokensUpdated today
    SecurityAuto-check passed

More from rlaope/oh-my-hermes

All 143 skills in this repo
  • Omh Accessibility Audit

    rlaope/oh-my-hermes

    [omh] Screen-reader or keyboard accessibility gaps: prepare WCAG, keyboard, focus, screen-reader, target-size, and reflow evidence gates for UI surfaces.

    3.2k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Omh Agent Evaluation

    rlaope/oh-my-hermes

    [omh] Choosing between coding agents on evidence: compare executor or agent choices on reproducible tasks using quality, cost, time, tool, and evidence metrics.

    3.2k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Omh Agent Instructions

    rlaope/oh-my-hermes

    [omh] Agent instruction file for a repo -- AGENTS.md, CLAUDE.md, a Cursor rule: write or update what an agent cannot derive from the code, inside a marked region, with every command verified or…

    3.2k GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Omh Agent Ops Review

    rlaope/oh-my-hermes

    [omh] AI agent progress for managers: help managers inspect AI-agent progress, blockers, quality gates, and throughput levers.

    3.2k GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Omh AI Slop Cleaner

    rlaope/oh-my-hermes

    [omh] Messy or AI-generated code to clean up: delete AI-generated slop, dead code, and duplication while observable behavior stays identical.

    3.2k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Omh App Debugging

    rlaope/oh-my-hermes

    [omh] Application code misbehaves -- a wrong value, a flaky test, a lost update: reproduce it first, form competing hypotheses, discriminate them with the cheapest observation, and only then fix the…

    3.2k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Omh Application Threat Model

What does Omh Application Threat Model do?

[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Omh Application Threat Model is an agent skill from rlaope/oh-my-hermes. [omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds.

When should I use Omh Application Threat Model?

Omh Application Threat Model fits situations like: the user says: application-threat-model; application threat model; threat modeling; threat modelling.

How do I install Omh Application Threat Model in Claude Code?

Run `npx skills add rlaope/oh-my-hermes --skill omh-application-threat-model -a claude-code`. Or copy the skill folder (skills/omh-application-threat-model in rlaope/oh-my-hermes) into .claude/skills/omh-application-threat-model in your project. Claude Code loads it when a task matches its description.

How do I install Omh Application Threat Model in Codex?

Run `npx skills add rlaope/oh-my-hermes --skill omh-application-threat-model -a codex`. Or copy the skill folder (skills/omh-application-threat-model in rlaope/oh-my-hermes) into .agents/skills/omh-application-threat-model in your project. Codex loads it when a task matches its description.

Can I use Omh Application Threat Model in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rlaope/oh-my-hermes --skill omh-application-threat-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/omh-application-threat-model, .gemini/skills/omh-application-threat-model, .github/skills/omh-application-threat-model and .opencode/skills/omh-application-threat-model in your project.

What does Omh Application Threat Model need to run?

SKILL.md names no scripts, command-line tools or credentials: Omh Application Threat Model is instructions for the agent only.

Does Omh Application Threat Model access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Omh Application Threat Model safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Omh Application Threat Model use?

Omh Application Threat Model is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Omh Application Threat Model use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Omh Application Threat Model?

Skills that share tags, products or a category with Omh Application Threat Model: Forensify (alexgreensh/repo-forensics, 190 stars), Create Rule (cartography-cncf/cartography, 4.1k stars), Commit Security Scan (codexstar69/bug-hunter, 520 stars) and Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Omh Application Threat Model?

rlaope (a GitHub user) maintains it in rlaope/oh-my-hermes, which has 3,243 GitHub stars. The repository holds 143 skills in this directory. The repository was last updated on October 10, 2026.

Source: rlaope/oh-my-hermes on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.