Security Threat Model
Independent PiSkill directory guide. The original skill remains hosted by OpenAI Skills.
What is Security Threat Model?
Produces repository-grounded application-security threat models by mapping assets, trust boundaries, attacker capabilities, abuse paths, and practical mitigations.
What does Security Threat Model do?
Security Threat Model is an OpenAI skill for producing a repository-grounded application-security threat model. It identifies the assets worth protecting, trust boundaries, attacker capabilities, exposed surfaces, credible abuse paths and practical mitigations based on how the codebase is actually structured.
Who is Security Threat Model best for?
- Security reviews before a major release
- Developers threat-modeling a new service or feature
- Teams reviewing trust boundaries and sensitive data flows
- Repositories that need a concise AppSec threat-model document
Common use cases
- Map assets and trust boundaries in a codebase
- Identify realistic attacker entry points and abuse paths
- Prioritize mitigations against repository-specific threats
- Document residual risks and assumptions for engineering review
How does Security Threat Model work?
The skill scopes the requested repository or path, inspects architecture and data flows, identifies assets and boundaries, models plausible attacker capabilities, enumerates abuse paths and maps each meaningful threat to concrete mitigations. The output is a concise Markdown threat model rather than a generic security checklist.
Key benefits
- Keeps threats tied to the real repository
- Separates assets, boundaries, attackers and abuse paths
- Produces actionable mitigations rather than vague warnings
- Creates a reviewable artifact for engineering and security teams
Things to know
- A codebase review cannot observe every production control or runtime dependency
- Threat likelihood and business impact may require stakeholder input
- It does not replace penetration testing or specialist security assessment
Compatible tools
Frequently asked questions
What does the Security Threat Model skill produce?
How is this different from a normal code review?
Related skills
Security Ownership Map
Builds a repository-grounded map of security-sensitive code ownership from Git history, identifying concentration, orphaned areas, and review coverage risks.
AWS IAM
Provides verified IAM guidance for policy evaluation, trust relationships, least-privilege role creation, STS sessions, condition operators, and common security edge cases.
Security Best Practices
Reviews supported codebases against language- and framework-specific security guidance and helps produce secure-by-default changes or prioritized security findings.
Agent Governance
Adds governance, policy, trust, audit, access-control, and safety patterns to AI-agent systems that call tools, APIs, databases, or other external systems.
Agent OWASP Compliance
Reviews an AI-agent codebase against the OWASP Agentic Security Initiative Top 10 and produces structured security and compliance findings for agentic systems.
Cloudflare One
Provides implementation guidance for Cloudflare One and Zero Trust products, including access policies, secure connectivity, device posture, gateways, and operational troubleshooting.