Security Threat Model

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a…

About this skill

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not

Maintained by OpenAI. The source includes the instructions and any supporting files needed to use this skill.

Inside the instructions

  • 01Quick start
  • 02Workflow
  • 031) Scope and extract the system model
  • 042) Derive boundaries, assets, and entry points
  • 053) Calibrate assets and attacker capabilities
  • 064) Enumerate threats as abuse paths

Before you start

  1. Read the instructions and check tool or account requirements.
  2. Install the complete folder when the skill references scripts or other files.
  3. Provide your task context, then review the agent's output.

Source

openai/skills / security-threat-model

Source reviewed October 2, 2026 · Apache-2.0