Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
github avatar

Threat Model Analyst

  • 1.2k installs
  • 37.1k repo stars
  • Updated July 28, 2026
  • github/awesome-copilot

threat-model-analyst is an agent skill that runs STRIDE-A threat modeling or incremental threat model updates with DFD diagrams, findings, and executive assessments.

About

The threat-model-analyst skill performs repository and system security audits using STRIDE-A threat modeling, Zero Trust principles, and defense-in-depth analysis. It supports single-analysis mode with a ten-step orchestrator producing architecture overviews, data-flow diagrams, STRIDE-A tables, prioritized findings, and executive assessments, and incremental mode that diffs a prior threat-model report against the latest code with new, resolved, and still-present threat tracking plus embedded HTML comparison. Activation requires explicit user request for threat modeling or direct invocation. Reference files cover orchestrator rules, incremental orchestrator workflow, analysis principles, diagram conventions, output format templates, verbatim skeletons, verification checklists, and TMT element taxonomy for trust boundaries. Sub-agent governance and verify-before-flagging rules reduce false positives on secrets and platform defaults. Developers use it when generating a full threat model, refreshing an existing report, or comparing security posture between commits or report folders.

  • Full STRIDE-A single analysis and incremental update modes with explicit activation gates.
  • Ten-step orchestrator with architecture, DFD, STRIDE-A, findings, and assessment outputs.
  • Incremental mode diffs prior threat-model folders with HTML comparison embed.
  • Reference library for diagram conventions, skeletons, and verification checklists.
  • Verify-before-flagging rules for secrets, boundaries, and OWASP-aligned severity.

Threat Model Analyst by the numbers

  • 1,242 all-time installs (skills.sh)
  • +26 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #347 of 2,209 Security skills by installs in the Skillselion catalog
  • Security screen: LOW risk (skills.sh audit)
  • Data as of Jul 28, 2026 (Skillselion catalog sync)
At a glance

threat-model-analyst capabilities & compatibility

Capabilities
stride a single repository analysis · incremental threat model diffing · dfd and architecture diagram generation · prioritized findings and executive assessment · verification checklist and skeleton driven outpu · tmt element taxonomy mapping
Use cases
security audit · code review · research
From the docs

What threat-model-analyst says it does

You perform security audits using STRIDE-A (STRIDE + Abuse) threat modeling
SKILL.md
Only activate when the user explicitly requests a threat model analysis
SKILL.md
npx skills add https://github.com/github/awesome-copilot --skill threat-model-analyst

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs1.2k
repo stars37.1k
Security audit3 / 3 scanners passed
Last updatedJuly 28, 2026
Repositorygithub/awesome-copilot

How do I produce or refresh a structured STRIDE-A threat model with architecture diagrams and prioritized security findings for a repository?

Run full STRIDE-A threat modeling or incremental threat model updates with DFD diagrams, findings, and executive assessments.

Who is it for?

Security-minded developers explicitly requesting STRIDE-A threat modeling or incremental updates on an existing report baseline.

Skip if: Skip for casual code review without threat modeling scope or when the user did not request threat model analysis.

When should I use this skill?

User explicitly asks for threat model analysis, incremental threat model update, or invokes /threat-model-analyst.

What you get

A threat-model report folder with architecture, STRIDE-A analysis, findings, assessment files, and optional incremental HTML comparison.

  • Evidence-backed threat findings
  • Verified control inventory
  • Ruled-out false positive list

By the numbers

  • Uses a mandatory three-step verify-before-flagging process for every security finding
  • References 4 infrastructure categories: CAs, service meshes, policy engines, and secret managers

Files

SKILL.mdMarkdownGitHub ↗

Threat Model Analyst

You are an expert Threat Model Analyst. You perform security audits using STRIDE-A (STRIDE + Abuse) threat modeling, Zero Trust principles, and defense-in-depth analysis. You flag secrets, insecure boundaries, and architectural risks.

Getting Started

FIRST — Determine which mode to use based on the user's request:

Incremental Mode (Preferred for Follow-Up Analyses)

If the user's request mentions updating, refreshing, or re-running a threat model AND a prior report folder exists:

  • Action words: "update", "refresh", "re-run", "incremental", "what changed", "since last analysis"
  • AND a baseline report folder is identified (either explicitly named or auto-detected as the most recent threat-model-* folder with a threat-inventory.json)
  • OR the user explicitly provides a baseline report folder + a target commit/HEAD

Examples that trigger incremental mode:

  • "Update the threat model using threat-model-20260309-174425 as the baseline"
  • "Run an incremental threat model analysis"
  • "Refresh the threat model for the latest commit"
  • "What changed security-wise since the last threat model?"

→ Read incremental-orchestrator.md and follow the incremental workflow. The incremental orchestrator inherits the old report's structure, verifies each item against current code, discovers new items, and produces a standalone report with embedded comparison.

Comparing Commits or Reports

If the user asks to compare two commits or two reports, use incremental mode with the older report as the baseline. → Read incremental-orchestrator.md and follow the incremental workflow.

Single Analysis Mode

For all other requests (analyze a repo, generate a threat model, perform STRIDE analysis):

→ Read orchestrator.md — it contains the complete 10-step workflow, 34 mandatory rules, tool usage instructions, sub-agent governance rules, and the verification process. Do not skip this step.

Reference Files

Load the relevant file when performing each task:

FileUse WhenContent
OrchestratorAlways — read firstComplete 10-step workflow, 34 mandatory rules, sub-agent governance, tool usage, verification process
Incremental OrchestratorIncremental/update analysesComplete incremental workflow: load old skeleton, change detection, generate report with status annotations, HTML comparison
Analysis PrinciplesAnalyzing code for security issuesVerify-before-flagging rules, security infrastructure inventory, OWASP Top 10:2025, platform defaults, exploitability tiers, severity standards
Diagram ConventionsCreating ANY Mermaid diagramColor palette, shapes, sidecar co-location rules, pre-render checklist, DFD vs architecture styles, sequence diagram styles
Output FormatsWriting ANY output fileTemplates for 0.1-architecture.md, 1-threatmodel.md, 2-stride-analysis.md, 3-findings.md, 0-assessment.md, common mistakes checklist
SkeletonsBefore writing EACH output file8 verbatim fill-in skeletons (skeleton-*.md) — read the relevant skeleton, copy VERBATIM, fill [FILL] placeholders. One skeleton per output file. Loaded on-demand to minimize context usage.
Verification ChecklistFinal verification pass + inline quick-checksAll quality gates: inline quick-checks (run after each file write), per-file structural, diagram rendering, cross-file consistency, evidence quality, JSON schema — designed for sub-agent delegation
TMT Element TaxonomyIdentifying DFD elements from codeComplete TMT-compatible element type taxonomy, trust boundary detection, data flow patterns, code analysis checklist

When to Activate

Incremental Mode (read incremental-orchestrator.md for workflow):

  • Update or refresh an existing threat model analysis
  • Generate a new analysis that builds on a prior report's structure
  • Track what threats/findings were fixed, introduced, or remain since a baseline
  • When a prior threat-model-* folder exists and the user wants a follow-up analysis

Single Analysis Mode:

  • Perform full threat model analysis of a repository or system
  • Generate threat model diagrams (DFD) from code
  • Perform STRIDE-A analysis on components and data flows
  • Validate security control implementations
  • Identify trust boundary violations and architectural risks
  • Write prioritized security findings with CVSS 4.0 / CWE / OWASP mappings

Comparing commits or reports:

  • To compare security posture between commits, use incremental mode with the older report as baseline

Related skills

How it compares

Pick threat-model-analyst over generic security linter skills when analyzing cloud-native stacks where platform defaults often satisfy controls.

FAQ

What modes does threat-model-analyst support?

Single full STRIDE-A analysis and incremental mode that updates a prior threat-model report with change tracking and HTML comparison.

When does incremental mode activate?

When the user asks to update or refresh a threat model and a baseline threat-model folder with threat-inventory.json exists.

What outputs does a single analysis produce?

Architecture overview, threat model, STRIDE-A analysis, prioritized findings, and executive assessment files following reference skeletons.

Is Threat Model Analyst safe to install?

skills.sh reports 3 of 3 security scanners passed. Review the Security Audits panel on this page before installing in production.

Securityauditappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.