Topic · Security

Best threat modeling skills, page 2

Skills #49–96 of 228, ranked by score.

Threat modeling skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Threat modeling skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model.

trailofbits/skills-curated5129 repos~1.4kAutomated safety check: PassCC-BY-SA-4.02 mo ago
50

Classify game-cheat capabilities and their defensive implications across memory, injection, rendering, input, engines, kernels, DMA, and remote transports.

gmh5225/awesome-game-security3.6k—~356Automated safety check: PassMITtoday
51

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis…

awarexone/Agentic-Bug-Hunter5.3k2 repos~6.4kAutomated safety check: WarnMIT3 days ago
52

Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…

trailofbits/skills7.4k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0today
53

Attack-surface crawling with the crawl tool — BFS link/form/hidden-field collection, JS-bundle API route extraction, and auth boundary mapping through the scoped browser.

Ch1nfo/RiftX113—~718Automated safety check: PassMIT16 days ago
54

安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

ReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT3 mo ago
55

Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

sangrokjung/claude-forge8502 repos~7.2kAutomated safety check: PassMIT1 mo ago
56

A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

ccashwell/evm-cortex131—~1.4kAutomated safety check: PassMIT8 days ago
57

Classify project-used dependency members and record taint sources as rule-authoring units.

seqra/opentaint162—~1.7kAutomated safety check: PassApache-2.0today
58

Conduct threat modeling using STRIDE methodology. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~4.3kAutomated safety check: PassMITtoday
59

Usar para sincronizar la documentación viva del proyecto después de una fase.

686f6c61/alfred-dev117—~382Automated safety check: PassMIT1 mo ago
60

安全架构与治理:威胁建模 (STRIDE/PASTA/LINDDUN)、零信任身份架构、IAM/SSO/MFA/PAM、合规框架 (SOC2/PCI/HIPAA/GDPR)、DLP、隐私工程、安全控制设计。Use when designing security architecture, threat modeling new systems, implementing zero-trust…

telagod/code-abyss243—~712Automated safety check: PassMIT2 mo ago
61

Security hardening reviewer for GitHub Actions workflow files (.github/workflows/.yml).

github/awesome-copilot40k1 repo~2.4kAutomated safety check: PassMITtoday
62

Understand a codebase before looking for bugs in it - what each function assumes, what it guarantees, and what it depends on elsewhere.

trailofbits/skills7.4k—~996Automated safety check: PassCC-BY-SA-4.0today
63

[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds.

rlaope/oh-my-hermes3.2k—~2.6kAutomated safety check: PassMITtoday
64
64.Pytm

Python-based threat modeling using pytm library for programmatic STRIDE analysis, data flow diagram generation, and automated security threat identification.

AgentSecOps/SecOpsAgentKit2202 repos~4.4kAutomated safety check: NotesUnknown5 mo ago
65
65.007

Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.

sickn33/agentic-awesome-skills47k2 repos~410Automated safety check: PassMITtoday
66

Full STRIDE-A threat model analysis and incremental update skill for repositories and systems.

github/awesome-copilot40k1 repo~1.5kAutomated safety check: PassMITtoday
67

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

unxed/f42412 repos~3.6kAutomated safety check: PassMITtoday
68

Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts.

codexstar69/bug-hunter519—~408Automated safety check: PassMIT1 mo ago
69

Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
70

Hardens Linux endpoints using CIS Benchmark recommendations for Ubuntu, RHEL, and CentOS to reduce attack surface, enforce security baselines, and meet compliance requirements.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: NotesApache-2.01 mo ago
71

Hardens Windows endpoints using CIS (Center for Internet Security) Benchmark recommendations to reduce attack surface, enforce security baselines, and meet compliance requirements.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
72

Implements application whitelisting using Windows AppLocker to restrict unauthorized software execution on endpoints, reducing attack surface from malware, unauthorized tools, and shadow IT.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: PassApache-2.01 mo ago
73

Reduces container attack surface by building application images on Google distroless base images that ship only the application runtime - no shell, package manager, or OS utilities - using…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.7kAutomated safety check: PassApache-2.01 mo ago
74

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

trilwu/secskills156—~3.1kAutomated safety check: NotesMIT1 mo ago
75

A skill your agent uses when a B200/Blackwell kernel shows wrong results, uncoalesced global memory access, SMEM bank conflicts, a TMA swizzle that mismatches the Tensor Core read, or confused…

mirage-project/mirage2.5k—~1.8kAutomated safety check: PassApache-2.0today
76

Threat-model and find vulnerabilities, with practical remediation.

antonbabenko/deliberation169—~1.1kAutomated safety check: PassMITtoday
77

A skill your agent uses for security reviews of VoxBento code.

fossasia/eventyay-interpretation1.6k—~1.3kAutomated safety check: PassApache-2.02 days ago
78

Review or harden security-sensitive behavior involving authentication, authorization, secrets, sessions, untrusted input, sensitive data, or trust boundaries.

dzhalaevd/Donatello135—~5.1kAutomated safety check: NotesApache-2.04 days ago
79

Analyze a codebase and produce a structured threat model at .turbo/threat-model.md covering assets, trust boundaries, attack surfaces with existing mitigations, attacker stories, and calibrated…

tobihagemann/turbo407—~2.5kAutomated safety check: PassMITtoday
80

Discover and inventory shadow API endpoints that operate outside documented OpenAPI/Swagger specs, using traffic analysis against API gateways (Kong, AWS API Gateway, Envoy), cloud configuration…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.6kAutomated safety check: PassApache-2.01 mo ago
81

Configures Windows Group Policy Objects to block ransomware execution and lateral spread, covering AppLocker rules, Software Restriction Policies, Controlled Folder Access, attack surface reduction…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
82

Implements external attack surface management (EASM) using Shodan, Censys, and ProjectDiscovery tools (subfinder, httpx, nuclei) for asset discovery, subdomain enumeration, service fingerprinting…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
83

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
84

Develops comprehensive threat actor profiles for APT groups, criminal organizations, and hacktivist collectives by aggregating TTP documentation, historical campaign data, tooling fingerprints, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
85

A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

hypnguyen1209/offensive-claude386—~2.2kAutomated safety check: PassMIT10 days ago
86

A skill your agent uses when an application or system — including one built quickly with AI coding agents — needs a security review with regulatory grounding: a STRIDE threat model, a LINDDUN…

davila7/claude-code-templates32k1 repo~6.4kAutomated safety check: NotesCC-BY-4.0today
87

A skill your agent uses when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the…

alirezarezvani/claude-skills28k—~1.3kAutomated safety check: PassMIT1 mo ago
88

Reduces attack surface across OS, container, cloud, network, and database layers using CIS Benchmarks and zero-trust principles.

ancoleman/ai-design-components526—~3.5kAutomated safety check: PassMIT10 mo ago
89

A skill your agent uses when security verification is needed - pre-commit security checks, vulnerability scanning, STRIDE threat analysis.

sangrokjung/claude-forge850—~1kAutomated safety check: NotesMIT1 mo ago
90

Review Maple security across authentication, account isolation, local persistence, Tauri IPC and capabilities, OAuth and deep links, the Local OpenAI Proxy, Agent Mode tools and permissions, MCP…

MaplePrivacyLabs/Maple100—~7.1kAutomated safety check: PassMITtoday
91

STRIDE + OWASP-based security audit with optional auto-fix. An agent skill from withkynam/vibecode-pro-max-kit.

withkynam/vibecode-pro-max-kit1.1k—~1.2kAutomated safety check: PassMIT3 mo ago
92

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

trilwu/secskills156—~2.9kAutomated safety check: PassMIT1 mo ago
93

Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

forefy/.context152—~3.1kAutomated safety check: PassMIT3 days ago
94

NCAA cross country and track & field athlete data via TFRRS (tfrrs.org) and news via The Stride Report.

machina-sports/sports-skills242—~2kAutomated safety check: PassMIT2 days ago
95

Uses OWASP Threat Dragon (web or desktop) to build data flow diagrams, identify threats with STRIDE, LINDDUN, CIA, DIE, or PLOT4ai methodologies via its auto-generation rule engine, and produce PDF…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.01 mo ago
96

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface.

transilienceai/communitytools562—~1.4kAutomated safety check: PassMIT2 mo ago