Topic · Security
Best threat modeling skills, page 5
Threat modeling skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF… | trilwu/ | 156 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 194 | Produce a repository-grounded application security threat model with assets, boundaries, abuse paths, priorities, and mitigations. | nightly-labs/ | 453 | — | ~379 | Automated safety check: Pass | Unknown | today |
| 195 | 195.Threat Model Threat modeling and attack surface analysis. An agent skill from hashgraph-online/awesome-codex-plugins. | hashgraph-online/ | 1.2k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 196 | 196.Vuln Scan Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords. | hashgraph-online/ | 1.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 197 | Security Ownership Map workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. | diegosouzapw/ | 159 | — | ~4.6k | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 198 | 198.QA Methodology Design and apply QA methodology for software teams: test strategy, regression testing, CI failure triage, test automation, quality gates and metrics, risk-based testing, exploratory testing, test… | magnus919/ | 113 | — | ~3.2k | Automated safety check: Pass | MIT | 2 days ago |
| 199 | Vulnerability review, threat modeling, OWASP patterns, and secure coding assessment. | rsmdt/ | 551 | — | ~1.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 200 | 200.Security Review AI-powered security analysis of code changes — traces data flow, detects injection, auth bypass, secrets exposure, and unsafe deserialization across files. | danielvm-git/ | 257 | — | ~1.5k | Automated safety check: Pass | MIT | 17 days ago |
| 201 | Plans and runs authorized reconnaissance to enumerate a target's external attack surface (DNS, subdomains, ports, web tech) and produces a prioritized report. | criptogus/ | 288 | — | ~1.2k | Automated safety check: Pass | CC-BY-SA-4.0 | 29 days ago |
| 202 | Trigger Pattern Any external module interaction detected in attacksurface.md - Inject Into Breadth agents (merged via M5 hierarchy) | PlamenTSV/ | 303 | — | ~1.1k | Automated safety check: Pass | MIT | 12 days ago |
| 203 | Generate a STRIDE-based security threat model for a repository. | Factory-AI/ | 110 | — | ~2.1k | Automated safety check: Pass | No licence | yesterday |
| 204 | 204.Security Auditor Assess vulnerabilities and audit for security compliance using OWASP and STRIDE methodology — a user-invoked Security Auditor workflow. | dralgorhythm/ | 125 | — | ~496 | Automated safety check: Pass | No licence | 2 mo ago |
| 205 | A skill your agent uses when drafting an ACM CCS rebuttal during the HotCRP author-response window, covering threat-model defenses, adaptive-attack objections, ethics and disclosure questions… | brycewang-stanford/ | 1.2k | — | ~949 | Automated safety check: Pass | MIT | 11 days ago |
| 206 | A skill your agent uses when strengthening ACM CCS reproducibility evidence, including the artifact-availability posture, threat-model-to-evidence mapping, attack reproduction steps, defense… | brycewang-stanford/ | 1.2k | — | ~903 | Automated safety check: Pass | MIT | 11 days ago |
| 207 | A skill your agent uses when deciding whether a security project fits ACM CCS versus IEEE S&P, USENIX Security, NDSS, PETS, or a crypto/theory venue, identifying the security contribution type, and… | brycewang-stanford/ | 1.2k | — | ~945 | Automated safety check: Pass | MIT | 11 days ago |
| 208 | A skill your agent uses when revising an ACM CCS paper for a precise threat model, calibrated attack/defense claims, 12-page ACM sigconf compression, double-blind wording, adaptive-evaluation… | brycewang-stanford/ | 1.2k | — | ~918 | Automated safety check: Pass | MIT | 11 days ago |
| 209 | A skill your agent uses when drafting the IEEE S&P (Oakland) rebuttal for second-round papers or the response plan for a Revise decision, including triaging reviews under the ~5-day window… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 11 days ago |
| 210 | A skill your agent uses when deciding whether a security or privacy project belongs at IEEE S&P (Oakland), including the threat-model test, SoK fit, routing among USENIX Security, CCS, NDSS, PETS… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 11 days ago |
| 211 | A skill your agent uses when writing or revising an IEEE S&P (Oakland) paper's prose, including the threat-model-first structure, calibrating security claims to evaluated boundaries, the first-round… | brycewang-stanford/ | 1.2k | — | ~1.2k | Automated safety check: Pass | MIT | 11 days ago |
| 212 | A skill your agent uses when revising an ISSTA paper for a clear testing/analysis contribution, covering the threat-model-then-technique structure, the evaluation contract, a threats-to-validity… | brycewang-stanford/ | 1.2k | — | ~1.1k | Automated safety check: Pass | MIT | 11 days ago |
| 213 | A skill your agent uses to rehearse peer review before submitting — a calibrated Associate Editor desk-screen plus 2–3 distinct-lens referees for the target venue, adversarially verified and… | brycewang-stanford/ | 1.2k | — | ~707 | Automated safety check: Pass | MIT | 11 days ago |
| 214 | A skill your agent uses when designing or auditing the evaluation of a USENIX Security Symposium paper — building threat-model-faithful experiments, adaptive-attacker analysis for defenses… | brycewang-stanford/ | 1.2k | — | ~1.5k | Automated safety check: Pass | MIT | 11 days ago |
| 215 | A skill your agent uses when drafting or revising prose for a USENIX Security Symposium paper — threat-model-first structure, calibrated security claims, disclosure narrative woven into the text… | brycewang-stanford/ | 1.2k | — | ~1.3k | Automated safety check: Pass | MIT | 11 days ago |
| 216 | 216.Security Audit Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Notes | MIT | 1 mo ago |
| 217 | 217.Threat Modeling Conduct structured threat modeling for software systems using established methodologies to identify, prioritize, and mitigate security threats before they are exploited. | seb1n/ | 206 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 218 | 218.Risk Manager Risk management specialist who assesses, analyzes, and mitigates financial and operational risks with expertise in quantitative risk modeling, compliance frameworks, and enterprise risk assessment | majiayu000/ | 666 | 1 repo | ~2.7k | Automated safety check: Pass | MIT | yesterday |
| 219 | A skill your agent uses when analyzing, selecting, validating, or communicating models for insurance, actuarial, financial-risk, or other consequential uncertain outcomes. | magnus919/ | 113 | — | ~3.2k | Automated safety check: Pass | MIT | 2 days ago |
| 220 | A skill your agent uses when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. | CoWork-OS/ | 473 | — | ~8.6k | Automated safety check: Pass | MIT | today |
| 221 | 221.Defender Easm Guidance for Microsoft Defender External Attack Surface Management (Defender EASM) — discovers and inventories an organization's internet-facing assets (domains, hosts, IPs, SSL certs, ASNs, web… | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 222 | Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation… | vinayaklatthe/ | 175 | — | ~2.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 223 | 223.Threat Modelling Guidance for threat modelling using STRIDE and the Microsoft Security Development Lifecycle (SDL). | vinayaklatthe/ | 175 | — | ~1.8k | Automated safety check: Pass | MIT | 3 mo ago |
| 224 | Complete guide to LINDDUN privacy threat modeling methodology covering seven threat categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. | mukul975/ | 295 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 225 | 225.Security Auditor MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 507 | — | ~440 | Automated safety check: Pass | Unknown | 3 mo ago |
| 226 | Advanced vulnerability analysis principles. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 507 | — | ~494 | Automated safety check: Pass | Unknown | 3 mo ago |
| 227 | Expert knowledge for Azure External Attack Surface Management development including configuration. | MicrosoftDocs/ | 777 | — | ~935 | Automated safety check: Pass | CC-BY-4.0 | 2 days ago |
| 228 | Security design principles, STRIDE threat modeling, OWASP Top 10 architectural mitigations, and secure patterns. | nWave-ai/ | 617 | — | ~2.4k | Automated safety check: Pass | MIT | 22 days ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38