threat-modeler
Generate threat models using STRIDE, PASTA, or VAST methodologies
它会碰到什么
扫了多少2 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Threat Modeler Skill
Overview
Generates threat models using STRIDE, PASTA, or VAST methodologies with attack tree generation, data flow diagram analysis, and threat prioritization using DREAD.
Capabilities
- Generate STRIDE threat models
- PASTA methodology support
- VAST methodology support
- Attack tree generation
- Data flow diagram analysis
- Threat prioritization (DREAD)
- Microsoft Threat Modeling Tool integration
- Mitigation recommendations
Target Processes
- security-architecture-review
- api-design-specification
Input Schema
{
"type": "object",
"required": ["system"],
"properties": {
"system": {
"type": "object",
"properties": {
"name": { "type": "string" },
"description": { "type": "string" },
"dataFlows": { "type": "array" },
"assets": { "type": "array" },
"trustBoundaries": { "type": "array" },
"externalEntities": { "type": "array" }
}
},
"methodology": {
"type": "string",
"enum": ["STRIDE", "PASTA", "VAST"],
"default": "STRIDE"
},
"options": {
"type": "object",
"properties": {
"prioritization": {
"type": "string",
"enum": ["DREAD", "CVSS", "custom"],
"default": "DREAD"
},
"generateAttackTrees": {
"type": "boolean",
"default": true
},
"outputFormat": {
"type": "string",
"enum": ["json", "markdown", "html"],
"default": "markdown"
}
}
}
}
}
Output Schema
{
"type": "object",
"properties": {
"threats": {
"type": "array",
"items": {
"type": "object",
"properties": {
"id": { "type": "string" },
"category": { "type": "string" },
"title": { "type": "string" },
"description": { "type": "string" },
"affectedAssets": { "type": "array" },
"riskScore": { "type": "number" },
"mitigations": { "type": "array" }
}
}
},
"attackTrees": {
"type": "array"
},
"dataFlowDiagram": {
"type": "string",
"description": "DFD in specified format"
},
"summary": {
"type": "object",
"properties": {
"totalThreats": { "type": "number" },
"byCategory": { "type": "object" },
"bySeverity": { "type": "object" }
}
}
}
}
Usage Example
{
kind: 'skill',
skill: {
name: 'threat-modeler',
context: {
system: {
name: 'E-Commerce Platform',
assets: ['User Data', 'Payment Info', 'Inventory'],
trustBoundaries: ['DMZ', 'Internal Network'],
dataFlows: [
{ from: 'User', to: 'Web Server', data: 'Credentials' }
]
},
methodology: 'STRIDE',
options: {
prioritization: 'DREAD',
generateAttackTrees: true
}
}
}
}想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。
它属于哪个仓库
星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径
library/specializations/software-architecture/skills/threat-modeler/SKILL.md