Topic · Security
Best threat modeling skills for Claude Code, Codex and other agents.
- skills
- 228
- official
- 12
Threat modeling skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Hardens code against vulnerabilities. An agent skill from penpot/penpot. | penpot/ | 61k | 6 repos | ~4.7k | Automated safety check: Notes | MPL-2.0 | today |
| 2 | Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo. | fla-org/ | 5.8k | — | ~6.3k | Automated safety check: Pass | MIT | today |
| 3 | 3.X Ray Generates an x-ray.md pre-audit report covering overview, enhanced threat model (protocol-type profiling, git-weighted attack surfaces, temporal risk analysis, composability dependency mapping)… | pashov/ | 1.2k | 1 repo | ~10k | Automated safety check: Pass | MIT | 2 days ago |
| 4 | Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report. | ruvnet/ | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | today |
| 5 | Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics. | alexgreensh/ | 188 | — | ~2.5k | Automated safety check: Notes | Unknown | 10 days ago |
| 6 | Builds a cited research base on normal system behavior and adversary abuse patterns before a threat hunt hypothesis gets written. | OTRF/ | 4.7k | — | ~1.3k | Automated safety check: Pass | MIT | 8 mo ago |
| 7 | Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection. | open-edge-platform/ | 6.2k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT. | responsibleai/ | 328 | — | ~11k | Automated safety check: Notes | MIT | yesterday |
| 9 | Author a Cartography security rule (one or more Cypher Facts plus a Pydantic Finding output model) under cartography/rules/data/rules/. | cartography-cncf/ | 4.1k | — | ~3k | Automated safety check: Pass | Apache-2.0 | today |
| 10 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API/bridge surface), Spec (the originating Linear/GitHub issue or PR), and Correctness (runtime bugs + the… | getsentry/ | 1.8k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 11 | Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. | elementalsouls/ | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | 1 mo ago |
| 12 | Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data. | addyosmani/ | 103k | 1 repo | ~4.4k | Automated safety check: Notes | MIT | 4 days ago |
| 13 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 14 | Translates a threat hunt's investigative intent into query-agnostic analytics that describe how adversary behavior should appear in data, grounded in table schemas. | OTRF/ | 4.7k | — | ~819 | Automated safety check: Pass | MIT | 8 mo ago |
| 15 | Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must… | samugit83/ | 3k | — | ~2.2k | Automated safety check: Pass | MIT | today |
| 16 | Token-efficient smart contract security auditing via Behavioral State Analysis (BSA). | quillai-network/ | 129 | — | ~1.4k | Automated safety check: Pass | MIT | 6 mo ago |
| 17 | Three-axis review of the branch diff — Standards (this repo's documented standards + public API surface), Spec (the originating Linear issue / PR), and Correctness (runtime bugs + the SDK threat… | getsentry/ | 873 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 18 | Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. | codexstar69/ | 519 | — | ~629 | Automated safety check: Pass | MIT | 1 mo ago |
| 19 | Ultimate AI-powered cybersecurity code review skill. An agent skill from AgriciDaniel/claude-cybersecurity. | AgriciDaniel/ | 227 | — | ~11k | Automated safety check: Warn | MIT | 5 mo ago |
| 20 | 20.Security Use before shipping to production. An agent skill from garagon/nanostack. | garagon/ | 207 | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 27 days ago |
| 21 | Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. | trilwu/ | 156 | — | ~3.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview. | ccashwell/ | 131 | — | ~25k | Automated safety check: Pass | MIT | 8 days ago |
| 23 | Builds attack trees that map how an attacker could reach a goal, with AND and OR nodes and cost, time, skill and detection ratings, to find defense gaps. | wshobson/ | 40k | 8 repos | ~623 | Automated safety check: Pass | MIT | 3 days ago |
| 24 | Match identified threats to preventive, detective and corrective controls across network, application, data, endpoint and process layers to plan remediation. | wshobson/ | 40k | 8 repos | ~742 | Automated safety check: Pass | MIT | 3 days ago |
| 25 | Finds security threats in a design with a STRIDE pass per component, rates severity and records fixes, with extra checks for AI agent and tool risks. | dralgorhythm/ | 125 | — | ~581 | Automated safety check: Pass | No licence | 2 mo ago |
| 26 | Audit browser-engine changes that process untrusted content or cross native-memory, origin, network, storage, extension, decoder, sandbox, or operating-system boundaries. | nordstjernen-web/ | 116 | — | ~920 | Automated safety check: Pass | GPL-3.0 | yesterday |
| 27 | Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows. | xenitV1/ | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | 8 mo ago |
| 28 | A skill your agent uses when stitching kernels into a multi-launch ELF and the AIE compiler rejects the merged module (BD exhaustion, channel routing, herd shape conflict, IR validation error, DMA… | Xilinx/ | 150 | — | ~1.8k | Automated safety check: Pass | MIT | today |
| 29 | Apply STRIDE methodology to systematically identify threats. | sangrokjung/ | 850 | 9 repos | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 30 | Design, evaluate, and challenge quantitative investment ideas using an integrated research workflow that covers factor and asset-pricing logic, signal generation, signal validation, backtesting… | monarchjuno/ | 299 | — | ~1.1k | Automated safety check: Pass | MIT | 5 mo ago |
| 31 | Runs a parallel security audit with three vulnerability hunters and two proof-of-concept engineers, rating each finding by whether it is actually exploitable. | code-yeongyu/ | 70k | — | ~1.9k | Automated safety check: Pass | Unknown | today |
| 32 | 32.Hunter Deep behavioral code analysis agent for Bug Hunter. An agent skill from codexstar69/bug-hunter. | codexstar69/ | 519 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | 1 repo | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 34 | 34.Fabric Intelligent pattern selection for Fabric CLI. An agent skill from ynulihao/AgentSkillOS. | ynulihao/ | 617 | 2 repos | ~3.4k | Automated safety check: Pass | No licence | 7 mo ago |
| 35 | Analyse Mitre ATT&CK tactics, techniques and sub-techniques. | tsale/ | 324 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 4 mo ago |
| 36 | Security audit skill. An agent skill from blueberrycongee/termcanvas. | blueberrycongee/ | 406 | — | ~966 | Automated safety check: Notes | MIT | 4 mo ago |
| 37 | A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research… | magnus919/ | 113 | — | ~4.1k | Automated safety check: Pass | MIT | yesterday |
| 38 | 38.Cso Chief Security Officer mode. An agent skill from no-session/pstack. | no-session/ | 134 | — | ~12k | Automated safety check: Notes | MIT | 6 mo ago |
| 39 | Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. | davila7/ | 32k | 2 repos | ~1.1k | Automated safety check: Notes | MIT | today |
| 40 | 40.Vuln Hunter Hunt for vulnerabilities in a running debuggee by analyzing imports/exports, triaging attack surface, and iteratively testing for bugs with PoC generation. | dariushoule/ | 209 | — | ~3.9k | Automated safety check: Notes | MIT | 6 mo ago |
| 41 | Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel… | utkusen/ | 1.3k | — | ~5.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 42 | 42.History Mine repository history for security fixes that were never published as advisories, producing a cached worklist for threat-model and advisory-deep-dive. | alpha-omega-security/ | 231 | — | ~2.9k | Automated safety check: Notes | MIT | today |
| 43 | Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. | fabricioctelles/ | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 44 | Analyzes Solidity contract entry points to map attack surface. | alt-research2/ | 104 | — | ~959 | Automated safety check: Pass | Unknown | 3 mo ago |
| 45 | 45.Threat Model MCP threat-model artifact for a scaffolded harness. An agent skill from ruvnet/metaharness. | ruvnet/ | 690 | — | ~637 | Automated safety check: Notes | MIT | today |
| 46 | Expert in threat modeling methodologies, security architecture review, and risk assessment. | davila7/ | 32k | 8 repos | ~529 | Automated safety check: Pass | MIT | today |
| 47 | Run a focused STRIDE-based security review using Bug Hunter-native artifacts. | codexstar69/ | 519 | — | ~567 | Automated safety check: Pass | MIT | 1 mo ago |
| 48 | Analyze code changes for security vulnerabilities using LLM reasoning and threat model patterns. | Factory-AI/ | 110 | — | ~2.3k | Automated safety check: Pass | No licence | today |
Questions, answered from the data.
What is the best threat modeling skill?
Security And Hardening from penpot/penpot ranks first of the 228 threat modeling skills listed here, with the highest score: its repository has 61k GitHub stars, 6 other GitHub owners carry a copy, its SKILL.md loads about 4.7k tokens and it has informational notes only in the automated safety check. Next come Fla Ascend Performance and X Ray.
Which threat modeling skills are official?
12 of the 228 threat modeling skills are official, published by the vendor's own GitHub organization: Review, Review, Trailmark Code Graphs, Openai Security Threat Model, Trailmark Structural and 7 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38