More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    STRIDE Web API Threat Model

    1

    Turn a web API architecture into a traceable STRIDE-per-element threat model.

    $24.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    STRIDE Web API Threat Model

    STRIDE Web API Threat Model

    Example session with this skill installed

    Threat-model this fictional multi-tenant SaaS API. A browser user sends HTTPS requests to an Express API, which queries PostgreSQL. The client supplies organization_id, and the API trusts it when loading tenant records. Reconstruct the DFD, mark trust boundaries, apply STRIDE per element, verify coverage and DREAD arithmetic, then return a prioritized mitigation roadmap.

    • Read your context and instructions
    • Compiled the stride web api

    STRIDE Coverage Summary

    Elements: browser_user (external entity), express_api (process), postgres (data store), https_request_flow and sql_query_flow (data flows). Three elements cross a trust boundary.

    IDSTRIDEElementDREADTierEvidence
    WA-01Elevation of Privilegeexpress_api44CRITICALThe client supplies organization_id and the process uses it as the tenant selector without server-side membership authorization.
    WA-02Spoofingbrowser_user31HIGHThe request identity and organization selector can be presented independently.
    WA-04Denial of Serviceexpress_api34HIGHThe boundary process has no supplied resource-control evidence.
    WA-03Information Disclosurehttps_request_flow29MEDIUMTenant-scoped response data crosses the public request boundary.

    Coverage gate: each entity, process, store, and flow received only valid STRIDE categories; DREAD totals reconcile with their five inputs.

    Priority mitigation: derive organization scope from the authenticated server-side session, enforce object-level authorization before every tenant read, reject client attempts to override the organization context, and log denied cross-tenant access.

    Verification test: authenticate as a user from organization A and request an object owned by organization B while supplying both organization IDs. Pass only if every route returns the same denial and no tenant-B data appears in the response or logs.

    Scope: this model covers only the supplied architecture and controls.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Threat-model a REST or GraphQL API before release.Audit authorization at tenant and object trust boundaries.Validate STRIDE coverage and DREAD arithmetic.Turn findings into a prioritized mitigation and verification plan.

    About this skill

    Build a rigorous STRIDE-per-element threat model for a web app, REST or GraphQL API, backend service, or authentication flow. The Skill reconstructs the supplied architecture as external entities, processes, data stores, data flows, and trust boundaries; applies only valid STRIDE categories per element; checks boundary-crossing authorization; validates DREAD arithmetic; and maps each evidence-bounded finding to a concrete mitigation.

    The package includes the full SKILL.md workflow, DFD method, STRIDE matrix, mitigation catalog, structured sample, coverage schema, deterministic coverage checker, tests, and a six-page PDF buyer guide.

    It does not run penetration tests, generate exploit payloads, inspect live systems, certify security, or cover AI-agent, cloud-IAM, or IoT-specific threat models.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago

    What's inside

    Frequently Asked Questions