Curated
Chapter 33 of 44
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model.
3 minutes · 673 words · 13 sections
Deliver an actionable AppSec-grade threat model that is specific to the repository or a project path, not a generic checklist. Anchor every architectural claim to evidence in the repo and keep assumptions explicit. Prioritizing realistic attacker goals and concrete impacts over generic checklists.
references/prompt-template.md to generate a repository summary.references/prompt-template.md. Use it verbatim when possible.references/prompt-template.md<repo-or-dir-name>-threat-model.md (use the basename of the repo root, or the in-scope directory if you were asked to model a subpath).references/prompt-template.mdreferences/security-controls-and-assets.mdOnly load the reference files you need. Keep the final result concise, grounded, and reviewable.
Install this repository
npx skills add openai/skillsSkills install per repository, not per chapter — the CLI has no documented per-skill form, so we do not print one.
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.
The verbatim description from this skill’s front matter — the string an agent matches on to decide whether to load it.
main, last pushed 14 July 2026.SKILL.md, not by matching a directory convention. 2 distinct layouts observed: skills/.curated/*/SKILL.md, skills/.system/*/SKILL.md.h1 and no skipped levels:/openai/skills.md, and each chapter at its own .md URL.4 files · 25 KB
Everything this skill ships beside its prose. All of it is set here, as subchapters of chapter 33.
Documentation the agent loads on demand, rather than up front.
Everything else published alongside the skill.