CtrlK
BlogDocsLog inGet started
Tessl Logo

stride-analysis-patterns

Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

39

Quality

38%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/AI-Agents-Safe-Coding-Skills/skills/stride-analysis-patterns/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

18%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is essentially a hollow placeholder that provides no actionable guidance on STRIDE threat modeling. The instructions consist entirely of generic meta-advice ('apply best practices', 'provide actionable steps') without any STRIDE-specific content — no explanation of the six threat categories, no analysis templates, no examples, and no workflow. The single reference to an implementation playbook cannot compensate for the complete absence of substantive content in the skill body itself.

Suggestions

Add concrete STRIDE-specific content: define each threat category (Spoofing, Tampering, Repudiation, Information Disclosure, DoS, Elevation of Privilege) with brief examples of how to identify each in a system architecture.

Provide a clear multi-step workflow for conducting a STRIDE analysis session, e.g.: 1) Enumerate system components, 2) Create data flow diagrams, 3) Apply each STRIDE category to each component, 4) Rate and prioritize threats, 5) Document mitigations.

Include at least one concrete example showing a system component analyzed against STRIDE categories with specific threat descriptions and mitigations.

Either provide the referenced `resources/implementation-playbook.md` bundle file or inline the essential patterns and templates needed to make the skill functional.

DimensionReasoningScore

Conciseness

The content is relatively short but includes generic filler like 'Clarify goals, constraints, and required inputs' and 'Apply relevant best practices and validate outcomes' which add no STRIDE-specific value. The 'Do not use' section is boilerplate. Some unnecessary padding exists but it's not severely verbose.

3 / 5

Actionability

The instructions are entirely vague and abstract — 'Apply relevant best practices and validate outcomes' and 'Provide actionable steps and verification' are meta-instructions with zero concrete guidance on how to actually perform STRIDE analysis. There are no examples of threat categories, no templates, no specific steps for identifying Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, or Elevation of Privilege threats.

1 / 5

Workflow Clarity

There is no discernible workflow or sequence of steps for conducting a STRIDE analysis. The four bullet points in Instructions are generic platitudes with no sequencing, no validation checkpoints, and no concrete process. A threat modeling skill absolutely requires a clear multi-step workflow.

1 / 5

Progressive Disclosure

The skill references `resources/implementation-playbook.md` for detailed patterns, which is a reasonable structure, but no bundle files are provided so the reference is unverifiable. The SKILL.md itself contains almost no substantive content, making it an empty shell that delegates everything to a file that may not exist. The reference is at least one-level deep and clearly signaled, preventing a score of 1.

2 / 5

Total

7

/

20

Passed

Description

57%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description establishes a clear niche around STRIDE threat modeling and includes an explicit 'Use when' clause, which is good. However, it lacks specificity in describing what concrete actions the skill performs beyond 'identify threats', and the trigger terms could be expanded to include the individual STRIDE categories and related synonyms users might naturally use.

Suggestions

Add specific concrete actions like 'generate threat matrices, enumerate STRIDE categories (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege), map threats to mitigations, and produce data flow diagrams'.

Expand trigger terms to include natural user phrases like 'security review', 'attack surface analysis', 'DFD', 'security assessment', and the individual STRIDE category names.

Differentiate more clearly from general security skills by specifying output formats or unique capabilities, e.g., 'produces structured threat reports with risk ratings and recommended countermeasures'.

DimensionReasoningScore

Specificity

Names the domain (STRIDE threat modeling) and one vague action ('identify threats'), but doesn't describe concrete actions like 'enumerate spoofing vectors', 'generate threat matrices', 'produce DFD diagrams', or 'map mitigations to threats'. The description stays at a high level.

2 / 5

Completeness

Has both 'what' (apply STRIDE methodology to identify threats) and 'when' ('Use when analyzing system security, conducting threat modeling sessions, or creating security documentation'). The 'what' is somewhat thin and the 'when' could be more specific with additional trigger scenarios, but both components are present.

4 / 5

Trigger Term Quality

Includes relevant keywords like 'STRIDE', 'threat modeling', 'security documentation', and 'system security', but misses natural user phrases like 'security review', 'attack surface', 'data flow diagram', 'DFD', 'spoofing', 'tampering', 'repudiation', 'information disclosure', 'denial of service', 'elevation of privilege', or 'security assessment'.

3 / 5

Distinctiveness Conflict Risk

The mention of 'STRIDE methodology' specifically distinguishes this from generic security skills. However, 'analyzing system security' and 'security documentation' are broad enough to potentially overlap with other security-related skills like vulnerability scanning or security policy writing.

4 / 5

Total

13

/

20

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.