Threat Model Generation

codexstar69/bug-hunter/skills/threat-model-generation

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067無授權條款519 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫7 週前更新

Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. Use whenever the repository has no threat model yet, the architecture changed materially, a security review needs fresh trust-boundary context, or the user explicitly asks for a threat model.

僅含說明Security
AI 產生的概覽

為程式碼儲存庫產生以 STRIDE 為基礎的威脅模型與對應安全設定,輸出至 .bug-hunter/ 目錄。

功能
此技能會檢查儲存庫,辨識語言與框架、公開/需驗證/內部進入點、資料存放區與外部整合、敏感資產以及信任邊界。接著產生精簡的 STRIDE 威脅模型,以及包含嚴重性門檻與技術堆疊中繼資料的對應安全設定。輸出檔案為 .bug-hunter/threat-model.md 與 .bug-hunter/security-config.json,並可能讀取既有的 .bug-hunter/triage.json 以取得結構線索。
適用情境
適用於儲存庫尚無威脅模型、架構有重大變更、安全審查需要最新的信任邊界脈絡,或使用者明確要求產生威脅模型時。
執行需求
未隨附指令碼,僅為指示。需要儲存庫的讀取權限與 .bug-hunter/ 目錄的寫入權限,並可選擇讀取既有的 .bug-hunter/triage.json 檔案。

Threat Model Generation

This is a bundled local Bug Hunter companion skill. It generates portable threat-model artifacts under .bug-hunter/.

Purpose

Create the security context that the other security skills depend on:

  • trust boundaries
  • major components
  • STRIDE threats
  • vulnerability pattern library
  • severity/config defaults

Required outputs

Write:

  • .bug-hunter/threat-model.md
  • .bug-hunter/security-config.json

Workflow

  1. Read .bug-hunter/triage.json if available for file structure and domain hints.
  2. Inspect the repository to identify:
    • languages and frameworks
    • public/authenticated/internal entry points
    • data stores and external integrations
    • sensitive assets and trust boundaries
  3. Generate a concise STRIDE threat model.
  4. Generate a matching security config with thresholds and tech-stack metadata.

Compatibility

prompts/threat-model.md is generated from this skill for older clients. This skill is the canonical source and must be edited instead of the generated compatibility prompt.

Output rules

  • Keep the threat model short enough for downstream agents to consume.
  • Be specific about trust boundaries and vulnerable code patterns.
  • Keep all artifacts under .bug-hunter/, never .factory/.

來源與署名

來源:codexstar69/bug-hunter位於skills/threat-model-generation提交3be6973

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架