Topic · Security

Best threat modeling skills, page 3

Skills #97–144 of 228, ranked by score.

Threat modeling skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Threat modeling skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
97

A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

hypnguyen1209/offensive-claude386—~660Automated safety check: PassMIT10 days ago
98
98.Tm7 Threat ModelOfficial

Creates valid Microsoft Threat Modeling Tool (.tm7) files compatible with the Microsoft Threat Modeling Tool v7.3+.

github/awesome-copilot40k—~3.7kAutomated safety check: PassMITtoday
99

Threat-model and harden AI agents, RAG systems, assistants, and tool-using workflows against direct, indirect, stored, cross-agent, and multimodal prompt injection.

seb1n/awesome-ai-agent-skills206—~2.6kAutomated safety check: PassMIT1 mo ago
100

Monitors Certificate Transparency (CT) logs to detect unauthorized certificate issuance, discover subdomains via CT data, and alert on suspicious certificate activity for owned domains.

mukul975/Anthropic-Cybersecurity-Skills34k—~4kAutomated safety check: PassApache-2.01 mo ago
101

Performs API inventory and discovery to identify all API endpoints in an organization's environment including documented, undocumented, shadow, zombie, and deprecated APIs.

mukul975/Anthropic-Cybersecurity-Skills34k—~4.3kAutomated safety check: PassApache-2.01 mo ago
102

Enumerates DNS records, attempts zone transfers, brute-forces subdomains, and maps DNS infrastructure during authorized reconnaissance to identify attack surface, misconfigurations, and information…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
103

Download raw sequencing reads from NCBI SRA using sra-tools (prefetch, fasterq-dump, vdb-validate) or the ENA mirror.

GPTomics/bioSkills1.2k2 repos~4kAutomated safety check: PassMIT1 mo ago
104

This skill covers conducting comprehensive security assessments of Operational Technology (OT) networks including SCADA systems, DCS architectures, and industrial control system communication paths.

mukul975/Anthropic-Cybersecurity-Skills34k—~6.1kAutomated safety check: PassApache-2.01 mo ago
105

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

aiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNo licenceyesterday
106

Run an enterprise security review of a system design or existing code before it ships.

ooiyeefei/ccc494—~1.5kAutomated safety check: PassMIT2 mo ago
107

Composite Phase-2 audit worker (ADR-150). An agent skill from ruvnet/ruflo.

ruvnet/ruflo74k—~720Automated safety check: NotesMITtoday
108
108.Recon

Perform structured reconnaissance and attack surface enumeration for authorized penetration tests, CTF challenges, and bug bounty programs.

briiirussell/cybersecurity-skills413—~1.1kAutomated safety check: NotesMIT4 mo ago
109

Run a structured threat-modeling session for a new feature, system, or architecture — STRIDE, attack trees, data flow diagrams, abuse cases.

briiirussell/cybersecurity-skills413—~2.7kAutomated safety check: NotesMIT4 mo ago
110
110.Audit IntegrityOfficial

Enforce output quality, evidence verification, and quality gates across security audits.

github/awesome-copilot40k—~1kAutomated safety check: PassMITtoday
111

A skill your agent uses when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a…

vlinx-io/VelaTerm2701 repo~756Automated safety check: PassMITyesterday
112

Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001).

ancoleman/ai-design-components526—~6.3kAutomated safety check: PassMIT10 mo ago
113

Draw a testable attack surface from one authorized target URL or one application.

yaklang/hack-skills2.4k—~2.6kAutomated safety check: PassMIT25 days ago
114

Usar para modelar amenazas con metodología STRIDE. An agent skill from 686f6c61/alfred-dev.

686f6c61/alfred-dev117—~1.2kAutomated safety check: PassMIT1 mo ago
115

When the user needs a security assessment — threat modeling, vulnerability review, auth flow audit, dependency scanning, or says "is this secure", "review for vulnerabilities", "threat model"…

shawnpang/startup-founder-skills341—~1.8kAutomated safety check: PassMIT6 mo ago
116

Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
117

External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

Encod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT1 mo ago
118

Security: review git changes for vulnerabilities, threat-model a system's attack surface, audit supply-chain risks.

notque/vexjoy-agent438—~2.6kAutomated safety check: NotesMIT5 days ago
119

Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis.

transilienceai/communitytools562—~1.4kAutomated safety check: PassMIT2 mo ago
120

Harden code against vulnerabilities. An agent skill from BlackBeltTechnology/pi-agent-dashboard.

BlackBeltTechnology/pi-agent-dashboard315—~4.7kAutomated safety check: NotesMITtoday
121

External recon for software supply-chain attack surface. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k1 repo~4.3kAutomated safety check: WarnMITyesterday
122

Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing.

LeoYeAI/openclaw-master-skills2.2k—~3.8kAutomated safety check: PassMIT2 mo ago
123

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

jabrena/plinth446—~885Automated safety check: PassApache-2.0yesterday
124

Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation.

majiayu000/spellbook286—~561Automated safety check: PassMITtoday
125

Perform an evidence-based Levyra security review and Codex Security workflow covering threat modeling, attack paths, validation, remediation, revalidation, secrets, provider URLs, redirects, SSRF…

LUC4N3X/Levyra-deepsound531—~2.3kAutomated safety check: PassGPL-3.0today
126

Software-engineering heuristics based on Mark Seemann's Code That Fits in Your Head (2021), updated for agent-driven development.

CodeAlive-AI/ai-driven-development157—~1.7kAutomated safety check: PassMIT2 days ago
127

Run an AWS Security Agent threat model review on spec/design documents.

aws/agent-toolkit-for-aws2.8k—~1.1kAutomated safety check: PassApache-2.0yesterday
128

Enterprise-review-grade threat model from harness threat-model <path.

ruvnet/ruflo74k—~363Automated safety check: NotesMITtoday
129

安全威胁建模专家 Owner — 当任务涉及权限、认证、授权、输入输出信任边界、密钥策略、审计、攻击面、Webhook/OAuth、敏感操作或用户要求安全专家视角时使用;要求识别滥用路径并绑定缓解验证。

devcodex-labs/devcodex439—~771Automated safety check: PassAGPL-3.021 days ago
130

Tile two-dimensional torch.gather(dim=1) kernels for Triton-Ascend so the logical grid stays near the physical vector-core count while each program handles multiple batch rows and loops over K.

Krusty84/triton-ascend-agent-dev-kit106—~583Automated safety check: PassApache-2.01 mo ago
131

Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE.

hardw00t/ai-security-arsenal104—~2.6kAutomated safety check: PassNo licence5 mo ago
132

Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…

telagod/code-abyss243—~907Automated safety check: PassMIT2 mo ago
133

Advanced CV for infrastructure inspection including forest fire detection, wildfire precondition assessment, roof inspection, hail damage analysis, thermal imaging, and 3D Gaussian Splatting…

curiositech/some_claude_skills2431 repo~2.2kAutomated safety check: PassMIT1 mo ago
134

Writing Windows-safe Infinite code from macOS: keep WIN32 out of nodes, three-sided Platform:: obligation, Windows trap catalogue (WASAPI, WinMM, GDI glyphs, Media Foundation stride, wide paths…

n1m21n/Infinite264—~4.6kAutomated safety check: PassUnknownyesterday
135

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh…

trilwu/secskills156—~3.5kAutomated safety check: PassMIT1 mo ago
136

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

trilwu/secskills156—~4.4kAutomated safety check: PassMIT1 mo ago
137

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
138

Security threat modeling, attack surface mapping, and trust boundary analysis on a codebase.

pproenca/dot-skills215—~1.7kAutomated safety check: PassMIT1 mo ago
139

Remediate security findings by producing minimal, surgical code patches.

pproenca/dot-skills215—~1.3kAutomated safety check: PassMIT1 mo ago
140
140.Recon

Map distinct externally reachable input-processing subsystems into focus areas for the threat-model skill to carry into later security audits.

alpha-omega-security/scrutineer231—~951Automated safety check: PassMITtoday
141

Threat-model and harden a BambooHR integration that handles employee PII, OAuth tokens, API keys, files, and webhooks.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITtoday
142

Implement the Canva Connect security baseline for backend OAuth, least privilege, tenant isolation, logging, revocation, and preview webhook verification.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITtoday
143

Secure Clari identities, credentials, exported revenue data, Copilot content, and ingestion mutations.

jeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMITtoday
144

Harden ClickUp credentials, OAuth callbacks, Workspace boundaries, webhooks, logging, and incident response with least-privilege controls.

jeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMITtoday