Topic · Security

Best threat modeling skills for Claude Code, Codex and other agents.

Skills that map assets, trust boundaries and attack paths to prioritise defences.
skills
228
official
12

Threat modeling skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Threat modeling skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Hardens code against vulnerabilities. An agent skill from penpot/penpot.

penpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0today
2

Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

fla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMITtoday
3

Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)…

pashov/skills1.2k1 repo~10kAutomated safety check: PassMIT2 days ago
4

Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

ruvnet/ruflo74k2 repos~823Automated safety check: PassMITtoday
5

Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

alexgreensh/repo-forensics188—~2.5kAutomated safety check: NotesUnknown10 days ago
6

Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written.

OTRF/ThreatHunter-Playbook4.7k—~1.3kAutomated safety check: PassMIT8 mo ago
7

Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.

open-edge-platform/anomalib6.2k—~1.4kAutomated safety check: PassApache-2.0today
8

Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.

responsibleai/ASSERT328—~11kAutomated safety check: NotesMITyesterday
9

Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/.

cartography-cncf/cartography4.1k—~3kAutomated safety check: PassApache-2.0today
10
10.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the…

getsentry/sentry-react-native1.8k—~1.9kAutomated safety check: PassMITtoday
11

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.

elementalsouls/Claude-OSINT2.8k—~8.7kAutomated safety check: NotesMIT1 mo ago
12

Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

addyosmani/agent-skills103k1 repo~4.4kAutomated safety check: NotesMIT4 days ago
13

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITtoday
14

Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas.

OTRF/ThreatHunter-Playbook4.7k—~819Automated safety check: PassMIT8 mo ago
15

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

samugit83/redamon3k—~2.2kAutomated safety check: PassMITtoday
16

Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).

quillai-network/quillshield_skills129—~1.4kAutomated safety check: PassMIT6 mo ago
17
17.ReviewOfficial

Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat…

getsentry/sentry-dart873—~1.3kAutomated safety check: PassMITtoday
18

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context.

codexstar69/bug-hunter519—~629Automated safety check: PassMIT1 mo ago
19

Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity.

AgriciDaniel/claude-cybersecurity227—~11kAutomated safety check: WarnMIT5 mo ago
20

Use before shipping to production. An agent skill from garagon/nanostack.

garagon/nanostack207—~3.7kAutomated safety check: NotesApache-2.027 days ago
21

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

trilwu/secskills156—~3.2kAutomated safety check: PassMIT1 mo ago
22

A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

ccashwell/evm-cortex131—~25kAutomated safety check: PassMIT8 days ago
23

Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps.

wshobson/agents40k8 repos~623Automated safety check: PassMIT3 days ago
24

Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation.

wshobson/agents40k8 repos~742Automated safety check: PassMIT3 days ago
25

Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks.

dralgorhythm/claude-agentic-framework125—~581Automated safety check: PassNo licence2 mo ago
26

Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries.

nordstjernen-web/northstar-browser116—~920Automated safety check: PassGPL-3.0yesterday
27

Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

xenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT8 mo ago
28

A skill your agent uses when stitching kernels into a multi-launch ELF and the AIE compiler rejects the merged module (BD exhaustion, channel routing, herd shape conflict, IR validation error, DMA…

Xilinx/mlir-air150—~1.8kAutomated safety check: PassMITtoday
29

Apply STRIDE methodology to systematically identify threats.

sangrokjung/claude-forge8509 repos~5.3kAutomated safety check: PassMIT1 mo ago
30

Design, evaluate, and challenge quantitative investment ideas using an integrated research workflow that covers factor and asset-pricing logic, signal generation, signal validation, backtesting…

monarchjuno/vibe-investing299—~1.1kAutomated safety check: PassMIT5 mo ago
31

Runs a parallel security audit with three vulnerability hunters and two proof-of-concept engineers, rating each finding by whether it is actually exploitable.

code-yeongyu/oh-my-openagent70k—~1.9kAutomated safety check: PassUnknowntoday
32

Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter.

codexstar69/bug-hunter519—~2.6kAutomated safety check: PassMIT1 mo ago
33

Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

trailofbits/skills7.4k1 repo~4.3kAutomated safety check: PassCC-BY-SA-4.0today
34

Intelligent pattern selection for Fabric CLI. An agent skill from ynulihao/AgentSkillOS.

ynulihao/AgentSkillOS6172 repos~3.4kAutomated safety check: PassNo licence7 mo ago
35

Analyse Mitre ATT&CK tactics, techniques and sub-techniques.

tsale/awesome-dfir-skills324—~1.4kAutomated safety check: PassApache-2.04 mo ago
36

Security audit skill. An agent skill from blueberrycongee/termcanvas.

blueberrycongee/termcanvas406—~966Automated safety check: NotesMIT4 mo ago
37

A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…

magnus919/agent-skills113—~4.1kAutomated safety check: PassMITyesterday
38
38.Cso

Chief Security Officer mode. An agent skill from no-session/pstack.

no-session/pstack134—~12kAutomated safety check: NotesMIT6 mo ago
39

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

davila7/claude-code-templates32k2 repos~1.1kAutomated safety check: NotesMITtoday
40

Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation.

dariushoule/x64dbg-skills209—~3.9kAutomated safety check: NotesMIT6 mo ago
41

Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…

utkusen/sast-skills1.3k—~5.3kAutomated safety check: PassMIT6 mo ago
42

Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive.

alpha-omega-security/scrutineer231—~2.9kAutomated safety check: NotesMITtoday
43

Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.

fabricioctelles/skills106—~2.8kAutomated safety check: PassApache-2.03 days ago
44

Analyzes Solidity contract entry points to map attack surface.

alt-research2/SolidityGuard104—~959Automated safety check: PassUnknown3 mo ago
45

MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness.

ruvnet/metaharness690—~637Automated safety check: NotesMITtoday
46

Expert in threat modeling methodologies, security architecture review, and risk assessment.

davila7/claude-code-templates32k8 repos~529Automated safety check: PassMITtoday
47

Run a focused STRIDE-based security review using Bug Hunter-native artifacts.

codexstar69/bug-hunter519—~567Automated safety check: PassMIT1 mo ago
48

Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns.

Factory-AI/factory-plugins110—~2.3kAutomated safety check: PassNo licencetoday

Questions, answered from the data.

What is the best threat modeling skill?

Security And Hardening from penpot/penpot ranks first of the 228 threat modeling skills listed here, with the highest score: its repository has 61k GitHub stars, 6 other GitHub owners carry a copy, its SKILL.md loads about 4.7k tokens and it has informational notes only in the automated safety check. Next come Fla Ascend Performance and X Ray.

Which threat modeling skills are official?

12 of the 228 threat modeling skills are official, published by the vendor's own GitHub organization: Review, Review, Trailmark Code Graphs, Openai Security Threat Model, Trailmark Structural and 7 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.