Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    stride threat modeling

    1

    Systematic STRIDE threat modeling for architecture, data flows, and cloud integrations.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    stride threat modeling

    stride threat modeling

    Example session with this skill installed

    Perform a STRIDE threat model for a new customer-facing REST API. It uses OAuth2 for auth, stores PII in a managed PostgreSQL DB, and runs on AWS EKS. Users can upload profile photos to S3.

    • Read your context and instructions
    • Compiled the stride threat modeling
    • Generated the document

    I have analyzed the REST API architecture on AWS EKS using the STRIDE framework. The analysis focuses on the trust boundaries between the Public Internet, the EKS Cluster, and the Managed Data Services (RDS/S3).

    STRIDE Threat Model: Customer REST API

    IDSTRIDE CategoryThreat DescriptionAffected ComponentMitigation Strategy
    T01SpoofingAttacker steals or forges OAuth2 tokens to impersonate users.API Gateway / Auth LayerImplement token revocation, short TTLs, and PKCE flow.
    T02TamperingUnauthorized modification of profile photos in S3 via insecure direct links.S3 Bucket / IAMUse S3 Presigned URLs and restrict bucket access to the EKS IAM Role.
    T03RepudiationUser denies performing a specific data deletion because logs lack non-repudiable identity.Audit Logs / PostgreSQLEnable detailed CloudTrail logging and application-level audit trails with user IDs.
    T04Info DisclosurePII leakage through verbose API error messages or unencrypted RDS snapshots.REST API / RDSSanitize error responses; enforce AWS KMS encryption at rest and in transit (TLS 1.3).
    T05Denial of ServiceResource exhaustion via large file uploads to the profile photo endpoint.S3 / EKS PodsImplement request rate limiting and file size validation at the API Gateway.
    T06Elevation of PrivilegeAttacker exploits EKS pod vulnerabilities to gain access to the Node IAM Role.EKS Node / IAMUse IRSA (IAM Roles for Service Accounts) to enforce least privilege for pods.

    Architecture Assumptions & Validation Questions

    • Assumption: The OAuth2 provider is an external OIDC compliant service (e.g., Auth0, Cognito).
    • Validation: Are the S3 buckets configured with "Block Public Access" enabled at the account level?
    • Validation: Is there a Web Application Firewall (WAF) in front of the API Gateway to handle L7 DoS?

    Next steps

    1. Review the T02 and T05 mitigations with the DevOps team to ensure S3 bucket policies are locked down.
    2. Verify the OAuth2 token validation logic handles expired and malformed tokens correctly.
    3. Integrate the security requirements derived from T04 into the current sprint backlog.

    stride-threat-modeling.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate structured threat registers for new feature designs.Identify security gaps in data flows between trust boundaries.Create mitigation plans and security validation requirements.Support GRC and security architecture review workflows.Perform a full STRIDE analysis across a system or platform architectureConvert a data flow diagram into a prioritised threat register with mitigationsDerive security requirements and acceptance criteria from confirmed threatsPrepare a threat model summary for security architecture review or audit

    About this skill

    The problem

    Security reviews often result in generic checklists rather than architectural insights. Developers and architects struggle to identify specific structural weaknesses across trust boundaries without a formal framework.

    What it does

    • Analyzes system architecture and data flows against the six STRIDE categories.
    • Maps threats to specific components, entry points, and trust boundaries.
    • Generates structured threat registers with impact, likelihood, and residual risk.
    • Translates identified threats into actionable security requirements and validation questions.
    • Identifies evidence gaps and architecture assumptions that require manual verification.

    Why this beats prompting it yourself

    General prompts often miss subtle categories like Repudiation or Information Disclosure in complex integrations. This skill enforces a systematic methodology that ties every threat to a specific asset or flow, preventing the "hallucinated threat" problem common in generic security prompts.

    Use cases

    • Reviewing cloud-native architecture for trust boundary violations.
    • Building a threat register for a new API integration or microservice.
    • Preparing security documentation for governance, risk, and compliance (GRC) audits.
    • Converting Data Flow Diagrams (DFDs) into prioritized mitigation plans.

    Known limitations

    Requires detailed system context to be effective. It will not provide exploit code, offensive payloads, or automated vulnerability scanning results.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 29 days ago

    • Passed all security checks, Safe to install

    Listed29 days ago

    What's inside

    Frequently Asked Questions