Topic · Security
Best threat modeling skills, page 2
Threat modeling skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. | trailofbits/ | 512 | 9 repos | ~1.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 mo ago |
| 50 | Classify game-cheat capabilities and their defensive implications across memory, injection, rendering, input, engines, kernels, DMA, and remote transports. | gmh5225/ | 3.6k | — | ~356 | Automated safety check: Pass | MIT | today |
| 51 | 51.Web2 Recon Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis… | awarexone/ | 5.3k | 2 repos | ~6.4k | Automated safety check: Warn | MIT | 3 days ago |
| 52 | Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark… | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 53 | 53.Recon Crawl Attack-surface crawling with the crawl tool — BFS link/form/hidden-field collection, JS-bundle API route extraction, and auth boundary mapping through the scoped browser. | Ch1nfo/ | 113 | — | ~718 | Automated safety check: Pass | MIT | 16 days ago |
| 54 | 安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex. | ReJeCtAll/ | 113 | — | ~780 | Automated safety check: Pass | MIT | 3 mo ago |
| 55 | Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and… | sangrokjung/ | 850 | 2 repos | ~7.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 56 | A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit. | ccashwell/ | 131 | — | ~1.4k | Automated safety check: Pass | MIT | 8 days ago |
| 57 | Classify project-used dependency members and record taint sources as rule-authoring units. | seqra/ | 162 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 58 | Conduct threat modeling using STRIDE methodology. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~4.3k | Automated safety check: Pass | MIT | today |
| 59 | Usar para sincronizar la documentación viva del proyecto después de una fase. | 686f6c61/ | 117 | — | ~382 | Automated safety check: Pass | MIT | 1 mo ago |
| 60 | 安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust… | telagod/ | 243 | — | ~712 | Automated safety check: Pass | MIT | 2 mo ago |
| 61 | Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml). | github/ | 40k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 62 | Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere. | trailofbits/ | 7.4k | — | ~996 | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 63 | [omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. | rlaope/ | 3.2k | — | ~2.6k | Automated safety check: Pass | MIT | today |
| 64 | 64.Pytm Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification. | AgentSecOps/ | 220 | 2 repos | ~4.4k | Automated safety check: Notes | Unknown | 5 mo ago |
| 65 | 65.007 Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project. | sickn33/ | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | today |
| 66 | Full STRIDE-A threat model analysis and incremental update skill for repositories and systems. | github/ | 40k | 1 repo | ~1.5k | Automated safety check: Pass | MIT | today |
| 67 | Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 241 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | today |
| 68 | Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. | codexstar69/ | 519 | — | ~408 | Automated safety check: Pass | MIT | 1 mo ago |
| 69 | Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 70 | Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements. | mukul975/ | 34k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 71 | Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements. | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 72 | Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT. | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 73 | Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 74 | Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. | trilwu/ | 156 | — | ~3.1k | Automated safety check: Notes | MIT | 1 mo ago |
| 75 | A skill your agent uses when a B200/Blackwell kernel shows wrong results, uncoalesced global memory access, SMEM bank conflicts, a TMA swizzle that mismatches the Tensor Core read, or confused… | mirage-project/ | 2.5k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 76 | Threat-model and find vulnerabilities, with practical remediation. | antonbabenko/ | 169 | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 77 | A skill your agent uses for security reviews of VoxBento code. | fossasia/ | 1.6k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 78 | Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries. | dzhalaevd/ | 135 | — | ~5.1k | Automated safety check: Notes | Apache-2.0 | 4 days ago |
| 79 | Analyze a codebase and produce a structured threat model at .turbo/threat-model.md covering assets, trust boundaries, attack surfaces with existing mitigations, attacker stories, and calibrated… | tobihagemann/ | 407 | — | ~2.5k | Automated safety check: Pass | MIT | today |
| 80 | Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 81 | Configures Windows Group Policy Objects to block ransomware execution and lateral spread, covering AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 82 | Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 83 | Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 84 | Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 85 | 85.Recon Osint A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover… | hypnguyen1209/ | 386 | — | ~2.2k | Automated safety check: Pass | MIT | 10 days ago |
| 86 | A skill your agent uses when an application or system — including one built quickly with AI coding agents — needs a security review with regulatory grounding: a STRIDE threat model, a LINDDUN… | davila7/ | 32k | 1 repo | ~6.4k | Automated safety check: Notes | CC-BY-4.0 | today |
| 87 | A skill your agent uses when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the… | alirezarezvani/ | 28k | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 88 | Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles. | ancoleman/ | 526 | — | ~3.5k | Automated safety check: Pass | MIT | 10 mo ago |
| 89 | A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis. | sangrokjung/ | 850 | — | ~1k | Automated safety check: Notes | MIT | 1 mo ago |
| 90 | Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP… | MaplePrivacyLabs/ | 100 | — | ~7.1k | Automated safety check: Pass | MIT | today |
| 91 | 91.Vc Security STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit. | withkynam/ | 1.1k | — | ~1.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 92 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 156 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 93 | Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. | forefy/ | 152 | — | ~3.1k | Automated safety check: Pass | MIT | 3 days ago |
| 94 | 94.Xctf Data NCAA cross country and track & field athlete data via TFRRS (tfrrs.org) and news via The Stride Report. | machina-sports/ | 242 | — | ~2k | Automated safety check: Pass | MIT | 2 days ago |
| 95 | Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 96 | Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. | transilienceai/ | 562 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
Explore related skills
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38