Topic · Security
Best threat modeling skills, page 4
Threat modeling skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Threat-model Exa credentials, query intent, retrieved web content, generated output, and retained operational evidence as separate trust boundaries. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 146 | Harden Fireflies bearer authentication, GraphQL selections, webhook signatures, logs, and privileged mutations against secret and meeting-data exposure. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | today |
| 147 | Analyze and design a Flexport integration that separates REST v3 resources, MCP tools, webhook ingress, approval, and reconciliation. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 148 | Analyze and harden Flexport credentials, tokens, webhook verification, data exposure, and mutation controls. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 149 | Harden an Ideogram integration across credentials, untrusted media, content safety, copyright controls, storage, and tenant authorization. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 150 | Harden Instantly API v2 keys, scopes, tenant boundaries, logs, webhooks, and operational access. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 151 | Harden Linear credentials, OAuth, team access, webhook verification, logging, and rotation. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 152 | Threat-model and harden Lucid API, Standard Import, editor extension, and data connector integrations. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | today |
| 153 | Threat-model Mistral credentials, untrusted content, model output, tools, files, and tenant access. | jeremylongshore/ | 2.8k | — | ~877 | Automated safety check: Pass | MIT | today |
| 154 | Threat-model a Navan integration across identity, travel, expense, payment, file, and downstream systems. | jeremylongshore/ | 2.8k | — | ~963 | Automated safety check: Pass | MIT | today |
| 155 | Threat-model a Procore integration across OAuth credentials, company routing, DMSA permissions, webhooks, files, logs, and revocation. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 156 | Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 157 | Harden Runway keys, organization access, prompts, media, generated outputs, and support evidence. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 158 | Threat-model a WebContainer or StackBlitz embed across host, runtime, user-code, filesystem, dependency, network, preview, secret, and persistence boundaries. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Notes | MIT | today |
| 159 | Harden Snagit and Camtasia automation around capture consent, license secrecy, local storage, share destinations, least privilege, and artifact review. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 160 | Secure Together AI integrations with project-scoped keys, environment isolation, prompt/output data controls, bounded model behavior, safe logging, rotation, and incident response. | jeremylongshore/ | 2.8k | — | ~1k | Automated safety check: Pass | MIT | today |
| 161 | Harden Webflow tokens, scopes, webhook verification, logs, and live-write boundaries. | jeremylongshore/ | 2.8k | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 162 | 162.Threat Modeling Identifies what could go wrong in a system before it is built or changed — the assets worth attacking, the entry points, the trust boundaries, and the controls that actually address the realistic… | cbrock84/ | 2k | — | ~841 | Automated safety check: Pass | MIT | 21 days ago |
| 163 | 163.Senior Security STRIDE threat modeling, DREAD risk scoring, secret detection, and secure architecture design. | borghei/ | 881 | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 164 | Audit or harden a defined application-security attack surface when the user explicitly requests a security audit, vulnerability investigation, or scoped security-hardening pass. | swyxio/ | 175 | — | ~962 | Automated safety check: Pass | MIT | 3 days ago |
| 165 | 165.Cso Chief Security Officer mode. An agent skill from mr-daedalium/ostack-saas. | mr-daedalium/ | 114 | — | ~7.4k | Automated safety check: Notes | MIT | 6 mo ago |
| 166 | Hack23 ISMS organization-wide compliance requirements, policy enforcement, audit preparation | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 167 | MCP gateway security patterns, token management, request validation, and audit logging for MCP communications | Hack23/ | 239 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 168 | Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC | Hack23/ | 239 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 169 | Maintain comprehensive security documentation including SECURITYARCHITECTURE.md, THREATMODEL.md per Hack23 ISMS standards | Hack23/ | 239 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 170 | 170.Repo Sentinel Full security audit for public repositories across 12 attack surfaces: git history, secrets, CI/CD, containers, dependencies, licenses. | Mathews-Tom/ | 328 | — | ~2.2k | Automated safety check: Pass | MIT | 2 days ago |
| 171 | 171.Go A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog… | ericrisco/ | 167 | — | ~3.9k | Automated safety check: Pass | MIT | today |
| 172 | 172.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 167 | — | ~2.8k | Automated safety check: Notes | MIT | today |
| 173 | 173.Audit Embedded Focused static audit of device firmware and IoT software for update, boot, provisioning, credential, debug-interface and device-communication boundary failures, using an ISVS-informed threat model. | alpha-omega-security/ | 231 | — | ~1.6k | Automated safety check: Notes | MIT | today |
| 174 | Audit package manager clients, registries, and proxies against a bundled threat model. | alpha-omega-security/ | 231 | — | ~1k | Automated safety check: Notes | MIT | today |
| 175 | 175.Audit Web Focused static audit of web applications and APIs for session, browser-origin, upload and business-workflow boundary failures, using an ASVS-informed threat model. | alpha-omega-security/ | 231 | — | ~1.3k | Automated safety check: Notes | MIT | today |
| 176 | 176.Spring AI Diagnose and operate Spring AI projects with version-aware Maven or Gradle checks for ChatClient, advisors, retrieval, conversation memory, tool/MCP boundaries, streaming, configuration, and… | magnus919/ | 113 | — | ~1.2k | Automated safety check: Pass | MIT | 2 days ago |
| 177 | Conduct LINDDUN privacy threat modeling across all seven categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. | mukul975/ | 295 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 178 | Comprehensive threat modeling for multi-agent systems using CSA MAESTRO 7-layer framework and OWASP Multi-Agentic System Threat Modeling Guide v1.0. | OWASP/ | 187 | — | ~835 | Automated safety check: Notes | Unknown | 13 days ago |
| 179 | Generates complete conventional oncology bulk-transcriptome biomarker and hub-gene research designs from a user-provided cancer type and study direction. | aipoch/ | 2k | — | ~4.6k | Automated safety check: Pass | MIT | 21 days ago |
| 180 | Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context. | cyberful/ | 135 | — | ~1.2k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 181 | 181.Threat Model Derive a project's security contract from its source and docs, then emit it as structured data other skills can cite. | alpha-omega-security/ | 231 | — | ~6.8k | Automated safety check: Pass | MIT | today |
| 182 | 182.Verify Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control. | alpha-omega-security/ | 231 | — | ~5.7k | Automated safety check: Pass | MIT | today |
| 183 | Analyze attack surface analyzer operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~585 | Automated safety check: Pass | MIT | today |
| 184 | Threat-model and harden a Mindtickle tenant and its identity, connector, API, content, and reporting integrations. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 185 | Threat-model SerpAPI credentials, query data, result retention, browser exposure, logs, and ZeroTrace tradeoffs. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 186 | Create threat model creator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~573 | Automated safety check: Pass | MIT | today |
| 187 | 187.Warden Threat Produce a threat model — assets, ranked threats, mitigations, accepted risks. | jeremylongshore/ | 2.8k | — | ~1.6k | Automated safety check: Notes | MIT | today |
| 188 | Financial risk modeling including VaR, stress testing, and credit risk | wentorai/ | 298 | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 3 mo ago |
| 189 | 189.Prose Style Reusable writing-style contract for agent outputs (reports, ARCH docs, verdicts, threat models). | avelikiy/ | 103 | — | ~1k | Automated safety check: Pass | MIT | yesterday |
| 190 | 190.Threat Modeling Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform | Hack23/ | 239 | — | ~6.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 191 | Write a STRIDE-based threat model for a service or feature. An agent skill from mohitagw15856/pm-claude-skills. | mohitagw15856/ | 1.4k | — | ~3.8k | Automated safety check: Pass | MIT | yesterday |
| 192 | 192.Threat Model Threat-model a system or feature to find where it could be attacked, before you build it. | mohitagw15856/ | 1.4k | — | ~911 | Automated safety check: Pass | MIT | yesterday |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38