Skip to content
rd-skills
All skills

threat-modeling

FoundationJIT only

analysis-agent/task-agent/review-agent: use for changed assets, trust boundaries, reachable abuse paths, impact, or control placement; skip without a security delta.

Group
Security & privacy
Supported roles
MainAnalysisTaskReview
Source
SKILL.md

Use when

Trigger signals that make this skill the right owner

  • model changed protected assets trust boundaries reachable abuse paths impacts controls and residual risk

Do not use when

Anti-triggers — as binding as the triggers above

  • no task-local protected asset trust boundary abuse path or control-placement decision is required

Required inputs

What must be supplied before this skill can decide anything

  • current task contract
  • selected primary Professional Skill
  • task-local trigger evidence

Output contract

What this skill owes the next role

  • changed threat model with protected outcomes, actor capabilities, reachable abuse paths, impact and blast radius, control placement and bypass analysis, fresh validation and detection evidence, proof limits, and residual-risk owners

Escalation signals

When this skill must hand the decision back

  • Abuse-path reachability, control placement, validation, or residual ownership remains ambiguous

Loaded by

This skill never owns a task. These professionals may pull it in as Layer 3.

Targeted references

Each reference carries its own load condition. None of them enter context by default.

ReferenceLoad whenDo not load whenRequired by
benchmarks-and-patterns.mdbenchmark-patterncompeting abuse-path impact control-placement bypass validation detection or residual-risk patterns remain viablecurrent graph and protected outcome resolve the changed threat decisionAnalysisTaskReview
checklist.mddecision-checklistseveral graph path impact control validation detection or residual-risk decisions must close togetherone bounded changed threat path is already complete from the root contractAnalysisTaskReview
evidence-patterns.mdevidence-patterngraph-delta actor-capability reachability impact control bypass validation detection or residual-risk claims need fresh proofcurrent graph control evidence and selected validation prove the bounded threat claimsAnalysisTaskReview