Commit Security Scan
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
$ npx skills add wshobson/agents --skill threat-mitigation-mapping -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install wshobson/agents threat-mitigation-mapping --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/security-scanning/skills/threat-mitigation-mapping .claude/skills/threat-mitigation-mapping && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "threat-mitigation-mapping" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping into .claude/skills/threat-mitigation-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-mitigation-mapping", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mappingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add wshobson/agents --skill threat-mitigation-mapping -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install wshobson/agents threat-mitigation-mapping --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/security-scanning/skills/threat-mitigation-mapping .agents/skills/threat-mitigation-mapping && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "threat-mitigation-mapping" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping into .agents/skills/threat-mitigation-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-mitigation-mapping", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill threat-mitigation-mapping -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install wshobson/agents threat-mitigation-mapping --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/security-scanning/skills/threat-mitigation-mapping .cursor/skills/threat-mitigation-mapping && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "threat-mitigation-mapping" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping into .cursor/skills/threat-mitigation-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-mitigation-mapping", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/wshobson/agents.git --path plugins/security-scanning/skills/threat-mitigation-mapping--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add wshobson/agents --skill threat-mitigation-mapping -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install wshobson/agents threat-mitigation-mapping --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/security-scanning/skills/threat-mitigation-mapping .gemini/skills/threat-mitigation-mapping && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "threat-mitigation-mapping" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping into .gemini/skills/threat-mitigation-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-mitigation-mapping", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install wshobson/agents threat-mitigation-mappingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add wshobson/agents --skill threat-mitigation-mapping -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/security-scanning/skills/threat-mitigation-mapping .github/skills/threat-mitigation-mapping && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "threat-mitigation-mapping" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping into .github/skills/threat-mitigation-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-mitigation-mapping", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add wshobson/agents --skill threat-mitigation-mapping -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install wshobson/agents threat-mitigation-mapping --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/wshobson/agents.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/security-scanning/skills/threat-mitigation-mapping .opencode/skills/threat-mitigation-mapping && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "threat-mitigation-mapping" agent skill from https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping into .opencode/skills/threat-mitigation-mapping/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "threat-mitigation-mapping", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
threat-mitigation-mappingMatch identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.
The skill connects a list of known threats to the controls that address them. Controls are sorted into preventive, detective and corrective types and into five layers: network, application, data, endpoint and process, with examples such as firewalls, WAF, input validation, encryption, EDR and security training. A nested defense-in-depth diagram starts at the perimeter.
Its guidance asks for every threat to be mapped, controls to be layered and mixed, effectiveness to be tracked and reviewed regularly, cost to be weighed, and single or untested controls to be avoided. Templates in references/details.md cover a mitigation model, defense-in-depth scoring, an executive summary, critical gaps, recommendations, an implementation roadmap and results by control.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 46891e7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Threat Mitigation Mapping loads about 742 tokens when it runs, and up to ~6.6k if it reads all its reference files. Until then it costs about 52 tokens; SKILL.md has 182 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from wshobson/agents at commit 46891e7, republished under its MIT licence (© wshobson). 182 words, ~742 tokens.
.claude/skills/threat-mitigation-mapping/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Connect threats to controls for effective security planning.
Preventive ────► Stop attacks before they occur
│ (Firewall, Input validation)
│
Detective ─────► Identify attacks in progress
│ (IDS, Log monitoring)
│
Corrective ────► Respond and recover from attacks
(Incident response, Backup restore)| Layer | Examples |
|---|---|
| Network | Firewall, WAF, DDoS protection |
| Application | Input validation, authentication |
| Data | Encryption, access controls |
| Endpoint | EDR, patch management |
| Process | Security training, incident response |
┌──────────────────────┐
│ Perimeter │ ← Firewall, WAF
│ ┌──────────────┐ │
│ │ Network │ │ ← Segmentation, IDS
│ │ ┌────────┐ │ │
│ │ │ Host │ │ │ ← EDR, Hardening
│ │ │ ┌────┐ │ │ │
│ │ │ │App │ │ │ │ ← Auth, Validation
│ │ │ │Data│ │ │ │ ← Encryption
│ │ │ └────┘ │ │ │
│ │ └────────┘ │ │
│ └──────────────┘ │
└──────────────────────┘Full template library and detailed mitigation/control mappings live in references/details.md. Read that file when you need the concrete templates for: Mitigation Model, Defense in Depth scoring, Executive Summary scaffolding, Critical Gaps reporting, Recommendations, Implementation Roadmap, Results by Control.
© wshobson, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in plugins/security-scanning/skills/threat-mitigation-mapping of wshobson/agents.
Open the folder on GitHubat commit 46891e7
We found 18 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 8 other GitHub owners. This page covers the copy in wshobson/agents, which our catalogue first saw on October 7, 2026.
Threat Mitigation Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Threat Mitigation Mapping this skillwshobson/agents | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | |
| Commit Security Scancodexstar69/bug-hunter | 519 | — | ~629 | Automated safety check: Pass | MIT | |
| Auditing Code For Vulnerabilitiestrilwu/secskills | 157 | — | ~3.2k | Automated safety check: Pass | MIT | |
| Audit Browser Security Boundariesnordstjernen-web/northstar-browser | 124 | — | ~920 | Automated safety check: Pass | GPL-3.0 | |
| Security Auditblueberrycongee/termcanvas | 406 | — | ~966 | Automated safety check: Notes | MIT | |
| Security Reviewcodexstar69/bug-hunter | 519 | — | ~567 | Automated safety check: Pass | MIT |
codexstar69/bug-hunter
Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
nordstjernen-web/northstar-browser
Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.
blueberrycongee/termcanvas
Security audit skill. An agent skill from blueberrycongee/termcanvas.
codexstar69/bug-hunter
Run a focused STRIDE-based security review using Bug Hunter-native artifacts.
Factory-AI/factory-plugins
Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns.
wshobson/agents
Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.
wshobson/agents
Covers building subscription billing: billing cycles, subscription states, invoice generation, proration, tax handling and dunning for failed payments.
wshobson/agents
Profiles slow Python code with cProfile and memory profilers, then applies targeted fixes for CPU, memory, I/O and query bottlenecks.
wshobson/agents
Writes unit tests for shell scripts with Bats: error-condition tests, fixtures and mocks, cross-shell checks, parallel runs, helper files and CI integration.
wshobson/agents
Implement distributed tracing with Jaeger and Tempo to track requests across microservices and identify performance bottlenecks.
wshobson/agents
Reference for designing and tuning production LLM prompts: few-shot examples, chain-of-thought, structured outputs, templates and system prompts.
Categories
Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation. The skill connects a list of known threats to the controls that address them. Controls are sorted into preventive, detective and corrective types and into five layers: network, application, data, endpoint and process, with examples such as firewalls, WAF, input validation, encryption, EDR and security training.
Threat Mitigation Mapping fits situations like: turning a threat model into a prioritized remediation plan; checking whether existing controls cover every identified threat; reviewing a security architecture for defense in depth; justifying security spending with a control coverage summary.
Run `npx skills add wshobson/agents --skill threat-mitigation-mapping -a claude-code`. Or copy the skill folder (plugins/security-scanning/skills/threat-mitigation-mapping in wshobson/agents) into .claude/skills/threat-mitigation-mapping in your project. Claude Code loads it when a task matches its description.
Run `npx skills add wshobson/agents --skill threat-mitigation-mapping -a codex`. Or copy the skill folder (plugins/security-scanning/skills/threat-mitigation-mapping in wshobson/agents) into .agents/skills/threat-mitigation-mapping in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add wshobson/agents --skill threat-mitigation-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/threat-mitigation-mapping, .gemini/skills/threat-mitigation-mapping, .github/skills/threat-mitigation-mapping and .opencode/skills/threat-mitigation-mapping in your project.
SKILL.md names no scripts, command-line tools or credentials: Threat Mitigation Mapping is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Threat Mitigation Mapping is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 742 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Threat Mitigation Mapping: Commit Security Scan (codexstar69/bug-hunter, 519 stars), Auditing Code For Vulnerabilities (trilwu/secskills, 157 stars), Audit Browser Security Boundaries (nordstjernen-web/northstar-browser, 124 stars) and Security Audit (blueberrycongee/termcanvas, 406 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
wshobson (a GitHub user) maintains it in wshobson/agents, which has 40,305 GitHub stars. The repository holds 142 skills in this directory. The repository was last updated on October 5, 2026.
Source: wshobson/agents on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.