Works with the AI tools you already use
stride threat modeling
Systematic STRIDE threat modeling for architecture, data flows, and cloud integrations.
$12
stride threat modeling
Example session with this skill installed
Perform a STRIDE threat model for a new customer-facing REST API. It uses OAuth2 for auth, stores PII in a managed PostgreSQL DB, and runs on AWS EKS. Users can upload profile photos to S3.
- Read your context and instructions
- Compiled the stride threat modeling
- Generated the document
I have analyzed the REST API architecture on AWS EKS using the STRIDE framework. The analysis focuses on the trust boundaries between the Public Internet, the EKS Cluster, and the Managed Data Services (RDS/S3).
STRIDE Threat Model: Customer REST API
| ID | STRIDE Category | Threat Description | Affected Component | Mitigation Strategy |
|---|---|---|---|---|
| T01 | Spoofing | Attacker steals or forges OAuth2 tokens to impersonate users. | API Gateway / Auth Layer | Implement token revocation, short TTLs, and PKCE flow. |
| T02 | Tampering | Unauthorized modification of profile photos in S3 via insecure direct links. | S3 Bucket / IAM | Use S3 Presigned URLs and restrict bucket access to the EKS IAM Role. |
| T03 | Repudiation | User denies performing a specific data deletion because logs lack non-repudiable identity. | Audit Logs / PostgreSQL | Enable detailed CloudTrail logging and application-level audit trails with user IDs. |
| T04 | Info Disclosure | PII leakage through verbose API error messages or unencrypted RDS snapshots. | REST API / RDS | Sanitize error responses; enforce AWS KMS encryption at rest and in transit (TLS 1.3). |
| T05 | Denial of Service | Resource exhaustion via large file uploads to the profile photo endpoint. | S3 / EKS Pods | Implement request rate limiting and file size validation at the API Gateway. |
| T06 | Elevation of Privilege | Attacker exploits EKS pod vulnerabilities to gain access to the Node IAM Role. | EKS Node / IAM | Use IRSA (IAM Roles for Service Accounts) to enforce least privilege for pods. |
Architecture Assumptions & Validation Questions
- Assumption: The OAuth2 provider is an external OIDC compliant service (e.g., Auth0, Cognito).
- Validation: Are the S3 buckets configured with "Block Public Access" enabled at the account level?
- Validation: Is there a Web Application Firewall (WAF) in front of the API Gateway to handle L7 DoS?
Next steps
- Review the T02 and T05 mitigations with the DevOps team to ensure S3 bucket policies are locked down.
- Verify the OAuth2 token validation logic handles expired and malformed tokens correctly.
- Integrate the security requirements derived from T04 into the current sprint backlog.
stride-threat-modeling.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Security reviews often result in generic checklists rather than architectural insights. Developers and architects struggle to identify specific structural weaknesses across trust boundaries without a formal framework.
What it does
- Analyzes system architecture and data flows against the six STRIDE categories.
- Maps threats to specific components, entry points, and trust boundaries.
- Generates structured threat registers with impact, likelihood, and residual risk.
- Translates identified threats into actionable security requirements and validation questions.
- Identifies evidence gaps and architecture assumptions that require manual verification.
Why this beats prompting it yourself
General prompts often miss subtle categories like Repudiation or Information Disclosure in complex integrations. This skill enforces a systematic methodology that ties every threat to a specific asset or flow, preventing the "hallucinated threat" problem common in generic security prompts.
Use cases
- Reviewing cloud-native architecture for trust boundary violations.
- Building a threat register for a new API integration or microservice.
- Preparing security documentation for governance, risk, and compliance (GRC) audits.
- Converting Data Flow Diagrams (DFDs) into prioritized mitigation plans.
Known limitations
Requires detailed system context to be effective. It will not provide exploit code, offensive payloads, or automated vulnerability scanning results.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 29 days ago
- Passed all security checks, Safe to install