CtrlK
BlogDocsLog inGet started
Tessl Logo

security-threat-model

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Use when the user asks to threat model a codebase or path, enumerate threats or abuse paths, or perform AppSec threat modeling. Do NOT use for general architecture summaries, code review, security best practices (use security-best-practices), or non-security design work.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, repository-grounded workflow with clear sequencing, explicit validation checkpoints, and appropriately offloaded reference files. Minor conciseness and actionability refinements would push it to full marks.

Suggestions

De-duplicate the assets list between step 2 and step 3 to tighten conciseness.

Add one short inline example of a completed abuse-path entry or threat row to make the instruction-only guidance more immediately actionable.

Consider a one-line sample of the expected Markdown output shape inline so Claude can match the contract without always opening the prompt template.

DimensionReasoningScore

Conciseness

Mostly lean, action-oriented bullet lists with no padding of concepts Claude already knows; a couple of minor restatements (assets appear in both step 2 and step 3) could be tightened.

4 / 5

Actionability

Provides concrete enumeration targets, control-type lists, and a specific mitigation phrasing example, and delegates the exact output contract to the prompt template; minor gaps since it is instruction-only with no executable code.

4 / 5

Workflow Clarity

Eight clearly sequenced steps including a user-validation checkpoint with feedback loop (step 6: pause, wait, reflect non-responses) and a dedicated quality-check checklist before finalizing (step 8).

5 / 5

Progressive Disclosure

Body points to two real, one-level-deep reference files (prompt-template.md, security-controls-and-assets.md) with clear 'Only load the reference files you need' signaling and no nested references.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A high-quality description that states concrete capabilities, explicit trigger conditions, and a clear negative boundary against sibling skills. Only minor synonym coverage for trigger terms is missing.

DimensionReasoningScore

Specificity

Enumerates concrete actions — trust boundaries, assets, attacker capabilities, abuse paths, mitigations — and the output artifact (a concise Markdown threat model), giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both 'what' (enumerates and writes a threat model) and 'when' (Use when the user asks to threat model...) with concrete trigger phrases and a negative boundary.

5 / 5

Trigger Term Quality

Includes natural user phrases like 'threat model a codebase or path', 'enumerate threats or abuse paths', and 'AppSec threat modeling'; a few common synonyms (e.g. 'security review') are not covered, but coverage is strong.

4 / 5

Distinctiveness Conflict Risk

Clear AppSec threat-modeling niche reinforced by an explicit 'Do NOT use for' clause that names the sibling skill security-best-practices, minimizing wrong-skill triggering.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
tech-leads-club/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.