Install
openclaw skills install @mike47512/threatDeep threat modeling workflow—system decomposition, trust boundaries, STRIDE-style threats, mitigations, prioritization, and tracking. Use when designing new features, reviewing architecture, or responding to security requirements (STRIDE, PASTA light).
openclaw skills install @mike47512/threatThreat modeling turns architecture into attack scenarios and mitigations before code hardens incorrectly. It is team-facing—security is a collaborative exercise, not a gate at the end.
Trigger conditions:
Initial offer:
Use six stages: (1) scope & assets, (2) diagram & trust boundaries, (3) threats (STRIDE), (4) mitigations & controls, (5) prioritize & owners, (6) validate & iterate. Confirm time box (1–2 hour workshop vs async).
Goal: Agree what we model and what we protect.
Scope paragraph + asset list with sensitivity.
Exit condition: Shared understanding of what hurts if lost.
Goal: Visual model with boundaries where trust changes.
Exit condition: Diagram everyone in the room recognizes as their system.
Goal: Systematic brainstorm—not exhaustive fantasy.
Exit condition: Threat list with assumptions stated (e.g., “requires MITM”).
Goal: Map threats to controls—prevent, detect, respond.
Exit condition: Each high threat has at least one planned control or accepted risk with owner.
Goal: Ruthless prioritization—fix what matters.
Exit condition: Roadmap of mitigations with dates.
Goal: Model ages—revisit on major changes.