Agent skill

Threat Model

by ruvnet in ruvnet/metaharness

MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

MITAuto-check: notesSecurity

Install Threat Model

skills CLI
$ npx skills add ruvnet/metaharness --skill threat-model -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ruvnet/metaharness threat-model --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ruvnet/metaharness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude-plugin/skills/threat-model .claude/skills/threat-model && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
threat-model
GitHub stars
690
Token cost
~637 tokens
SKILL.md length
208 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

  • Tasks that involve Threat modeling
  • SKILL.md covers What it does, Usage from Codex, Equivalent CLI and When to attach this to a PR, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Project scaffolding

What it does

Threat Model is an agent skill from ruvnet/metaharness. MCP threat-model artifact for a scaffolded harness. Reports allowed/denied tools, dangerous permissions count, secrets reachability, network/shell/file-write grants, default-deny posture. Verdict: clean (exit 0) / medium (exit 1) / high (exit 2). The 'enterprise gold' artifact for PR + compliance review.

Its SKILL.md is about 640 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling, Project scaffolding and Regulatory compliance. It works with Model Context Protocol. The repository describes itself as: 🛠️ The meta-harness for AI agents — scaffold your own focused, branded agent harness with its own npx CLI, MCP server, memory, learning loop, and witness-signed releases. Works… The licence is MIT.

When your agent uses it

  • Tasks that involve Threat modeling
  • Tasks that involve Project scaffolding
  • Tasks that involve Regulatory compliance

Example prompts

  • “enterprise gold”
  • “/threat-model”

What it can do on your machine

Read from SKILL.md and the folder at commit ea287d6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Threat Model loads about 637 tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 208 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~637

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:42
    use AND deny rules don't guard `.env*` AND allow rules include any

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ruvnet/metaharness at commit ea287d6, republished under its MIT licence (© ruvnet). 208 words, ~637 tokens.

Download SKILL.mdSave it as .claude/skills/threat-model/SKILL.md (or your agent's skills folder).
name
threat-model
description
MCP threat-model artifact for a scaffolded harness. Reports allowed/denied tools, dangerous permissions count, secrets reachability, network/shell/file-write grants, default-deny posture. Verdict: clean (exit 0) / medium (exit 1) / high (exit 2). The 'enterprise gold' artifact for PR + compliance review.

threat-model

Codex skill: MCP threat-model artifact for PR / compliance review (iter 112 → iter 114). User-labelled "enterprise gold."

What it does

Renders the existing mcp-scan findings as a clean threat-model artifact in the shape a security / compliance reviewer wants to see attached to a PR:

MCP Threat Model

  Allowed tools:         3
  Denied tools:          14
  Dangerous permissions: 0
  Secrets reachable:     no
  Network access:        no
  Shell access:          no
  File write:            no
  Default-deny policy:   yes
  Audit log:             yes

Verdict: clean (exit 0)

Same underlying scan as mcp-scan, presented as a single-screen artifact.

VerdictExitTriggers
clean0no dangerous perms, no secret exposure
medium1network OR file-write granted, OR no audit log
high2shell granted OR default-deny OFF OR secrets reachable

The "secrets reachable" heuristic is conservative: true when MCP is in use AND deny rules don't guard .env* AND allow rules include any Read(...) grant.

Usage from Codex

/threat-model path=./my-harness
/threat-model path=./my-harness bundle=true

Equivalent CLI

bash
harness threat-model ./my-harness                # text artifact
harness threat-model ./my-harness --json         # full envelope
harness threat-model ./my-harness --bundle       # ADR-031 schema-1
harness threat-model ./my-harness --out tm.json  # write to file

When to attach this to a PR

  • Adding a new MCP server / tool
  • Loosening a permission allow rule
  • Pulling in a new dependency that exposes shell/network capabilities
  • Any change to .harness/mcp-policy.json or .claude/settings.json permissions

The artifact is small enough to paste verbatim into the PR description.

  • validate-harness (iter 22) — release-readiness umbrella (includes mcp-scan)
  • score-harness (iter 114) — broader 0-100 scorecard; MCP safety is one of its 5 dimensions
  • repo-genome (iter 114) — pre-scaffold readiness; MCP risk is one of its 7 sections

See also

  • ADR-022 — MCP primitive · ADR-030 — Discovery Loop · ADR-031 — Bundle Pattern

© ruvnet, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude-plugin/skills/threat-model of ruvnet/metaharness.

Open the folder on GitHubat commit ea287d6

Compare with similar skills

Threat Model next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Threat Model compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Threat Model this skillruvnet/metaharness690—~637Automated safety check: NotesMIT
Forensifyalexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesCustom licence
MCP Gateway SecurityHack23/cia239—~2.4kAutomated safety check: PassApache-2.0
Vulners API Python SDKvulnersCom/api375—~2.3kAutomated safety check: PassMIT
Chatgpt AppsHaohao-end/openagent8071 repos~4.9kAutomated safety check: PassApache-2.0
Writing Pluginsnukeop/nuclear19k—~825Automated safety check: PassAGPL-3.0

Similar skills

  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    188 GitHub stars~2.5k tokensUpdated 11 days ago
    SecurityAuto-check: notes
  • MCP gateway security patterns, token management, request validation, and audit logging for MCP communications

    239 GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    375 GitHub stars~2.3k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Chatgpt Apps

    Haohao-end/openagent

    Build, scaffold, refactor, and troubleshoot ChatGPT Apps SDK applications that combine an MCP server and widget UI.

    807 GitHub starsUsed in 1 repo~4.9k tokens
    Agent WorkflowsAuto-check passed
  • Writing Plugins

    nukeop/nuclear

    A skill your agent uses when writing, scaffolding, or modifying Nuclear plugins.

    19k GitHub stars~825 tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Tsed CLI

    tsedio/tsed

    Scaffolds Ts.ED v8 projects and generates files with the Ts.ED CLI v7, through its MCP server (tools set-workspace, init-project, list-templates, get-template, generate-file) or the tsed binary…

    3.1k GitHub stars~2.7k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from ruvnet/metaharness

All 14 skills in this repo
  • Create Harness

    ruvnet/metaharness

    Scaffold your own focused AI agent harness — pick host (Claude Code, Codex, pi.dev, Hermes), template, agents, skills, and ship a npm-publishable harness with its own npx CLI.

    690 GitHub stars~777 tokensUpdated yesterday
    Auto-check passed
  • Compare Harnesses

    ruvnet/metaharness

    Diff two scaffolded harnesses (ADR-031). An agent skill from ruvnet/metaharness.

    690 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Diag Harness

    ruvnet/metaharness

    Kernel-version skew check (ADR-027). An agent skill from ruvnet/metaharness.

    690 GitHub stars~835 tokensUpdated yesterday
    Auto-check passed
  • Example Harness

    ruvnet/metaharness

    Scaffold a ready-made AI agent harness in one command from the 19 published @metaharness/ example packages — 9 host integrations (Claude Code, Codex, Hermes, pi.dev, OpenClaw, RVM, Copilot…

    690 GitHub stars~735 tokensUpdated yesterday
    Auto-check passed
  • Oia Manifest

    ruvnet/metaharness

    Emit .harness/oia-manifest.json declaring layer alignment with the OIA v0.1 9-layer reference architecture.

    690 GitHub stars~910 tokensUpdated yesterday
    Auto-check passed
  • Repo Genome

    ruvnet/metaharness

    7-section readiness scorecard for a LOCAL repo. An agent skill from ruvnet/metaharness.

    690 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Questions about Threat Model

What does Threat Model do?

MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness. Threat Model is an agent skill from ruvnet/metaharness. MCP threat-model artifact for a scaffolded harness.

When should I use Threat Model?

Threat Model fits situations like: tasks that involve Threat modeling; tasks that involve Project scaffolding; tasks that involve Regulatory compliance.

How do I install Threat Model in Claude Code?

Run `npx skills add ruvnet/metaharness --skill threat-model -a claude-code`. Or copy the skill folder (.claude-plugin/skills/threat-model in ruvnet/metaharness) into .claude/skills/threat-model in your project. Claude Code loads it when a task matches its description.

How do I install Threat Model in Codex?

Run `npx skills add ruvnet/metaharness --skill threat-model -a codex`. Or copy the skill folder (.claude-plugin/skills/threat-model in ruvnet/metaharness) into .agents/skills/threat-model in your project. Codex loads it when a task matches its description.

Can I use Threat Model in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ruvnet/metaharness --skill threat-model -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-model, .gemini/skills/threat-model, .github/skills/threat-model and .opencode/skills/threat-model in your project.

What does Threat Model need to run?

SKILL.md names no scripts, command-line tools or credentials: Threat Model is instructions for the agent only.

Does Threat Model access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Threat Model safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Threat Model use?

Threat Model is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Threat Model use?

About 637 tokens (SKILL.md is roughly 2.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Threat Model?

Skills that share tags, products or a category with Threat Model: Forensify (alexgreensh/repo-forensics, 188 stars), MCP Gateway Security (Hack23/cia, 239 stars), Vulners API Python SDK (vulnersCom/api, 375 stars) and Chatgpt Apps (Haohao-end/openagent, 807 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Threat Model?

ruvnet (a GitHub user) maintains it in ruvnet/metaharness, which has 690 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: ruvnet/metaharness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.