Security threat model
Produces a threat model for a feature or system — assets, entry points, trust boundaries, mitigations.
Installation
$ npx skills add openai/skillsThe CLI's unit is the repository, so this installs everything in openai/skills, not security-threat-model alone. It writes into whichever agent directories it finds — Claude Code, Codex, Cursor, Copilot, Windsurf, Zed.
Summary
Produces a threat model for a feature or system — assets, entry points, trust boundaries, mitigations.
- Reach for it when a new externally-reachable surface, before it is built rather than after it is pentested.
- Spans Design & architect and Secure, so it is usually worth loading for the whole piece of work rather than at one moment in it.
- Stack-agnostic — nothing in it assumes a particular language or framework.
- Published by OpenAI, who ship the thing it is about — a stronger claim than a well-regarded engineer having written something good.
- Installing pulls the whole openai/skills repository: this catalogue lists 4 other entries from it, and the repo may hold more.
Where it sits in delivery
Design & architectInterfaces, module boundaries and domain language — decided before the code sets them in concrete.Everything in Design →
SecureThreat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.Everything in Secure →
The agent itself
The full text lives with its publisher and changes when they change it. Read it there rather than here — a mirrored copy of somebody else's procedure goes stale silently, and this page would have no way of telling you.
Related
More in Design & architect
- Agentic actions auditorAudits CI workflows that invoke AI agents — where prompt injection becomes a repository write.
trailofbits/skills - Differential security reviewSecurity-focused review of a PR, commit or diff — risk-first, evidence-backed, with stated coverage limits.
trailofbits/skills - Fix reviewChecks that a fix actually closes the reported issue and did not just move it.
trailofbits/skills - Supply chain risk auditorAudits dependencies and their provenance for supply-chain risk.
trailofbits/skills - Variant analysisFinds the other instances of a bug you already found — one root cause usually has several manifestations.
trailofbits/skills - Frontend designAnthropic's guidance for producing interfaces that look designed rather than defaulted.Skill
anthropics/skills