This skill provides a systematic approach to security by applying the STRIDE framework—Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege—to identify and mitigate threats. It offers structured templates for threat modeling, Python-based analysis helpers for calculating risk scores, and guidance for analyzing data flow diagrams to detect trust boundary crossings. Ideal for architecture reviews, compliance preparation, and security-first development, it helps teams proactively address risks before they become vulnerabilities.
주요 기능
0123,139 GitHub stars
02Data flow diagram (DFD) trust boundary analysis guidance
03Pre-defined mitigation strategies for common security patterns
04Standardized threat model documentation and reporting templates
05Automated risk scoring based on impact and likelihood
06STRIDE category mapping for systematic threat identification