All skills
threat-modeling
FoundationJIT onlyanalysis-agent/task-agent/review-agent: use for changed assets, trust boundaries, reachable abuse paths, impact, or control placement; skip without a security delta.
- Group
- Security & privacy
- Supported roles
- MainAnalysisTaskReview
- Source
- SKILL.md
Use when
Trigger signals that make this skill the right owner
- model changed protected assets trust boundaries reachable abuse paths impacts controls and residual risk
Do not use when
Anti-triggers — as binding as the triggers above
- no task-local protected asset trust boundary abuse path or control-placement decision is required
Required inputs
What must be supplied before this skill can decide anything
- current task contract
- selected primary Professional Skill
- task-local trigger evidence
Output contract
What this skill owes the next role
- changed threat model with protected outcomes, actor capabilities, reachable abuse paths, impact and blast radius, control placement and bypass analysis, fresh validation and detection evidence, proof limits, and residual-risk owners
Escalation signals
When this skill must hand the decision back
- Abuse-path reachability, control placement, validation, or residual ownership remains ambiguous
Loaded by
This skill never owns a task. These professionals may pull it in as Layer 3.
Targeted references
Each reference carries its own load condition. None of them enter context by default.
| Reference | Load when | Do not load when | Required by |
|---|---|---|---|
| benchmarks-and-patterns.mdbenchmark-pattern | competing abuse-path impact control-placement bypass validation detection or residual-risk patterns remain viable | current graph and protected outcome resolve the changed threat decision | AnalysisTaskReview |
| checklist.mddecision-checklist | several graph path impact control validation detection or residual-risk decisions must close together | one bounded changed threat path is already complete from the root contract | AnalysisTaskReview |
| evidence-patterns.mdevidence-pattern | graph-delta actor-capability reachability impact control bypass validation detection or residual-risk claims need fresh proof | current graph control evidence and selected validation prove the bounded threat claims | AnalysisTaskReview |