CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/stride-threat-modeling

Enumerates security threats against a feature specification or design using Microsoft's six STRIDE categories (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege), each paired with the security property it violates. Covers the asset-and-trust-boundary walk that produces threat rows, the threat-row output schema, a likelihood x impact triage rule labelled plainly as practitioner convention rather than standard, a worked example, and an anti-pattern catalog. Enumerates threats against a design; it does not scan code, run a penetration test, or audit control compliance. Use when a PRD section, user story, design doc, or architecture sketch touching authentication, user data, payments, file uploads, or an external integration is about to enter implementation and no threat model exists for it yet.

75

Quality

94%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files

Quality

Content

85%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable threat-modeling skill with a clear sequenced workflow and properly split-off reference material. Its only weakness is conciseness: verbatim source quotes and conceptual exposition push the body longer than necessary for a reader that already understands STRIDE.

Suggestions

Trim the six verbatim Microsoft definition quotes in the STRIDE category table to the property-violated mapping and a short phrase each, keeping citations without restating full definitions Claude already knows.

Tighten the 'Limitations' section to the non-obvious claims (ASVS version scoping, category ambiguity) and drop the general statements about threat models being unproven that the body already establishes.

Reduce repeated citation prose (e.g. restating the same Microsoft link context across sections) by consolidating source references once.

DimensionReasoningScore

Conciseness

Mostly efficient and information-dense, but the six verbatim Microsoft definition quotes, repeated citation prose, and the conceptual 'Limitations' section restate material (e.g. STRIDE category meanings) Claude already knows and could be tightened.

2 / 3

Actionability

Provides a concrete scoring formula, an exact output schema with column-by-column notes, a worked example with specific ASVS 4.0.3 anchors, an element x STRIDE matrix, and real referenced mitigations — copy-paste-ready guidance for an instruction-only skill.

3 / 3

Workflow Clarity

Clear five-step sequence (Inventory -> STRIDE question -> Filter -> Score -> Mitigation) with an explicit filtering checkpoint in Step 3, decision-rule score thresholds, and an anti-pattern table acting as a review checklist.

3 / 3

Progressive Disclosure

SKILL.md stays an overview of the process while the detailed mitigation catalog and worked example are split into the real, one-level-deep references/mitigations.md, clearly signaled by descriptive link text.

3 / 3

Total

11

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A precise, third-person description that names concrete capabilities, includes natural trigger terms, gives an explicit 'Use when' clause, and explicitly fences off adjacent activities to avoid mis-triggering. It satisfies every dimension at the top anchor.

DimensionReasoningScore

Specificity

Lists multiple concrete actions in third person ('Enumerates security threats... using Microsoft's six STRIDE categories', 'Covers the asset-and-trust-boundary walk... the threat-row output schema, a likelihood x impact triage rule... a worked example, and an anti-pattern catalog'), matching the multiple-specific-actions anchor.

3 / 3

Completeness

Explicitly answers both what ('Enumerates security threats against a feature specification or design') and when via a full 'Use when...' clause, satisfying the explicit-triggers anchor.

3 / 3

Trigger Term Quality

Natural user-facing triggers are well covered ('PRD section, user story, design doc, or architecture sketch touching authentication, user data, payments, file uploads, or an external integration'), terms a user would actually say when needing this skill.

3 / 3

Distinctiveness Conflict Risk

Clear niche with explicit disambiguation ('it does not scan code, run a penetration test, or audit control compliance'), making conflict with adjacent security skills unlikely.

3 / 3

Total

12

/

12

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents