Topic · Security
Best threat modeling skills, page 3
Threat modeling skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before… | hypnguyen1209/ | 386 | — | ~660 | Automated safety check: Pass | MIT | 10 days ago |
| 98 | Creates valid Microsoft Threat Modeling Tool (.tm7) files compatible with the Microsoft Threat Modeling Tool v7.3+. | github/ | 40k | — | ~3.7k | Automated safety check: Pass | MIT | today |
| 99 | Threat-model and harden AI agents, RAG systems, assistants, and tool-using workflows against direct, indirect, stored, cross-agent, and multimodal prompt injection. | seb1n/ | 206 | — | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 100 | Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains. | mukul975/ | 34k | — | ~4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 101 | Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs. | mukul975/ | 34k | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 102 | Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 103 | 103.Bio Sra Data Download raw sequencing reads from NCBI SRA using sra-tools (prefetch, fasterq-dump, vdb-validate) or the ENA mirror. | GPTomics/ | 1.2k | 2 repos | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 104 | This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths. | mukul975/ | 34k | — | ~6.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 105 | 105.Security Auditor Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 430 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 106 | 106.Secure By Design Run an enterprise security review of a system design or existing code before it ships. | ooiyeefei/ | 494 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 107 | Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo. | ruvnet/ | 74k | — | ~720 | Automated safety check: Notes | MIT | today |
| 108 | 108.Recon Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs. | briiirussell/ | 413 | — | ~1.1k | Automated safety check: Notes | MIT | 4 mo ago |
| 109 | 109.Threat Modeling Run a structured threat-modeling session for a new feature, system, or architecture — STRIDE, attack trees, data flow diagrams, abuse cases. | briiirussell/ | 413 | — | ~2.7k | Automated safety check: Notes | MIT | 4 mo ago |
| 110 | Enforce output quality, evidence verification, and quality gates across security audits. | github/ | 40k | — | ~1k | Automated safety check: Pass | MIT | today |
| 111 | 111.Threat Model A skill your agent uses when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a… | vlinx-io/ | 270 | 1 repo | ~756 | Automated safety check: Pass | MIT | yesterday |
| 112 | Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). | ancoleman/ | 526 | — | ~6.3k | Automated safety check: Pass | MIT | 10 mo ago |
| 113 | Draw a testable attack surface from one authorized target URL or one application. | yaklang/ | 2.4k | — | ~2.6k | Automated safety check: Pass | MIT | 25 days ago |
| 114 | 114.Threat Model Usar para modelar amenazas con metodología STRIDE. An agent skill from 686f6c61/alfred-dev. | 686f6c61/ | 117 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 115 | 115.Security Review When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"… | shawnpang/ | 341 | — | ~1.8k | Automated safety check: Pass | MIT | 6 mo ago |
| 116 | 116.Research Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 117 | 117.Wiki Recon External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. | Encod3d-Sec/ | 329 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 118 | 118.Security Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks. | notque/ | 438 | — | ~2.6k | Automated safety check: Notes | MIT | 5 days ago |
| 119 | 119.Reconnaissance Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis. | transilienceai/ | 562 | — | ~1.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 120 | Harden code against vulnerabilities. An agent skill from BlackBeltTechnology/pi-agent-dashboard. | BlackBeltTechnology/ | 315 | — | ~4.7k | Automated safety check: Notes | MIT | today |
| 121 | External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 1 repo | ~4.3k | Automated safety check: Warn | MIT | yesterday |
| 122 | 122.Senior Security Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. | LeoYeAI/ | 2.2k | — | ~3.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 123 | A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing… | jabrena/ | 446 | — | ~885 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 124 | Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. | majiayu000/ | 286 | — | ~561 | Automated safety check: Pass | MIT | today |
| 125 | Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF… | LUC4N3X/ | 531 | — | ~2.3k | Automated safety check: Pass | GPL-3.0 | today |
| 126 | Software-engineering heuristics based on Mark Seemann's Code That Fits in Your Head (2021), updated for agent-driven development. | CodeAlive-AI/ | 157 | — | ~1.7k | Automated safety check: Pass | MIT | 2 days ago |
| 127 | Run an AWS Security Agent threat model review on spec/design documents. | aws/ | 2.8k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 128 | Enterprise-review-grade threat model from harness threat-model <path. | ruvnet/ | 74k | — | ~363 | Automated safety check: Notes | MIT | today |
| 129 | 安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。 | devcodex-labs/ | 439 | — | ~771 | Automated safety check: Pass | AGPL-3.0 | 21 days ago |
| 130 | Tile two-dimensional torch.gather(dim=1) kernels for Triton-Ascend so the logical grid stays near the physical vector-core count while each program handles multiple batch rows and loops over K. | Krusty84/ | 106 | — | ~583 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 131 | 131.Threat Modeling Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE. | hardw00t/ | 104 | — | ~2.6k | Automated safety check: Pass | No licence | 5 mo ago |
| 132 | 132.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 243 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 133 | Advanced CV for infrastructure inspection including forest fire detection, wildfire precondition assessment, roof inspection, hail damage analysis, thermal imaging, and 3D Gaussian Splatting… | curiositech/ | 243 | 1 repo | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 134 | 134.Windows Parity Writing Windows-safe Infinite code from macOS: keep WIN32 out of nodes, three-sided Platform:: obligation, Windows trap catalogue (WASAPI, WinMM, GDI glyphs, Media Foundation stride, wide paths… | n1m21n/ | 264 | — | ~4.6k | Automated safety check: Pass | Unknown | yesterday |
| 135 | Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 136 | Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and… | trilwu/ | 156 | — | ~4.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 137 | Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 138 | 138.Threat Model Security threat modeling, attack surface mapping, and trust boundary analysis on a codebase. | pproenca/ | 215 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 139 | 139.Threat Patch Remediate security findings by producing minimal, surgical code patches. | pproenca/ | 215 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 140 | 140.Recon Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits. | alpha-omega-security/ | 231 | — | ~951 | Automated safety check: Pass | MIT | today |
| 141 | Threat-model and harden a BambooHR integration that handles employee PII, OAuth tokens, API keys, files, and webhooks. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 142 | Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 143 | Secure Clari identities, credentials, exported revenue data, Copilot content, and ingestion mutations. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 144 | Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | today |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38