Threat Model Generation

codexstar69/bug-hunter/skills/threat-model-generation

by codexstar693be69733a27aa04d4f5620df203c05350d162067No license519 starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 7 weeks ago

Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. Use whenever the repository has no threat model yet, the architecture changed materially, a security review needs fresh trust-boundary context, or the user explicitly asks for a threat model.

Instructions onlySecurity
AI-generated overview

Generates a STRIDE-based threat model and matching security config for a repository under .bug-hunter/.

What it does
This skill inspects a repository to identify languages, frameworks, entry points, data stores, integrations, sensitive assets and trust boundaries. It then produces a concise STRIDE threat model and a matching security configuration with severity thresholds and tech-stack metadata. Outputs are written as .bug-hunter/threat-model.md and .bug-hunter/security-config.json, and it may read an existing .bug-hunter/triage.json for structural hints.
When to use it
Use it when a repository has no threat model yet, when the architecture has changed materially, when a security review needs fresh trust-boundary context, or when the user explicitly asks for a threat model.
Requirements
No scripts are shipped; it is instructions only. It needs read access to the repository and write access to a .bug-hunter/ directory, and optionally an existing .bug-hunter/triage.json file.

Threat Model Generation

This is a bundled local Bug Hunter companion skill. It generates portable threat-model artifacts under .bug-hunter/.

Purpose

Create the security context that the other security skills depend on:

  • trust boundaries
  • major components
  • STRIDE threats
  • vulnerability pattern library
  • severity/config defaults

Required outputs

Write:

  • .bug-hunter/threat-model.md
  • .bug-hunter/security-config.json

Workflow

  1. Read .bug-hunter/triage.json if available for file structure and domain hints.
  2. Inspect the repository to identify:
    • languages and frameworks
    • public/authenticated/internal entry points
    • data stores and external integrations
    • sensitive assets and trust boundaries
  3. Generate a concise STRIDE threat model.
  4. Generate a matching security config with thresholds and tech-stack metadata.

Compatibility

prompts/threat-model.md is generated from this skill for older clients. This skill is the canonical source and must be edited instead of the generated compatibility prompt.

Output rules

  • Keep the threat model short enough for downstream agents to consume.
  • Be specific about trust boundaries and vulnerable code patterns.
  • Keep all artifacts under .bug-hunter/, never .factory/.

Source and attribution

Source:codexstar69/bug-hunterinskills/threat-model-generationat commit3be6973

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal