Threat Model Generation

codexstar69/bug-hunter/skills/threat-model-generation

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067无许可证519 个星标收录于 2026年10月9日更新于 2026年10月9日仓库7周前更新

Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. Use whenever the repository has no threat model yet, the architecture changed materially, a security review needs fresh trust-boundary context, or the user explicitly asks for a threat model.

仅含说明Security
AI 生成的概览

为代码仓库生成基于 STRIDE 的威胁模型及配套安全配置,输出到 .bug-hunter/ 目录。

功能
该技能检查代码仓库,识别语言与框架、公开/需认证/内部入口、数据存储与外部集成、敏感资产以及信任边界。随后生成简洁的 STRIDE 威胁模型,以及包含严重性阈值和技术栈元数据的配套安全配置。输出文件为 .bug-hunter/threat-model.md 和 .bug-hunter/security-config.json,并可能读取已有的 .bug-hunter/triage.json 以获取结构线索。
适用场景
适用于仓库尚无威胁模型、架构发生重大变化、安全审查需要最新的信任边界上下文,或用户明确要求生成威胁模型时。
运行要求
不附带脚本,仅为指令。需要仓库的读取权限和 .bug-hunter/ 目录的写入权限,可选读取已有的 .bug-hunter/triage.json 文件。

Threat Model Generation

This is a bundled local Bug Hunter companion skill. It generates portable threat-model artifacts under .bug-hunter/.

Purpose

Create the security context that the other security skills depend on:

  • trust boundaries
  • major components
  • STRIDE threats
  • vulnerability pattern library
  • severity/config defaults

Required outputs

Write:

  • .bug-hunter/threat-model.md
  • .bug-hunter/security-config.json

Workflow

  1. Read .bug-hunter/triage.json if available for file structure and domain hints.
  2. Inspect the repository to identify:
    • languages and frameworks
    • public/authenticated/internal entry points
    • data stores and external integrations
    • sensitive assets and trust boundaries
  3. Generate a concise STRIDE threat model.
  4. Generate a matching security config with thresholds and tech-stack metadata.

Compatibility

prompts/threat-model.md is generated from this skill for older clients. This skill is the canonical source and must be edited instead of the generated compatibility prompt.

Output rules

  • Keep the threat model short enough for downstream agents to consume.
  • Be specific about trust boundaries and vulnerable code patterns.
  • Keep all artifacts under .bug-hunter/, never .factory/.

来源与署名

来源:codexstar69/bug-hunter位于skills/threat-model-generation提交3be6973

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架