CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/stride-threat-modeling

Enumerates security threats against a feature specification or design using Microsoft's six STRIDE categories (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege), each paired with the security property it violates. Covers the asset-and-trust-boundary walk that produces threat rows, the threat-row output schema, a likelihood x impact triage rule labelled plainly as practitioner convention rather than standard, a worked example, an anti-pattern catalog, and the from-spec workflow: read the spec, run the walk end to end, and write the threat-model document into the repo, with a no-fabrication rule for asset-free specs. Enumerates threats against a design; it does not scan code, run a penetration test, or audit control compliance. Use when a PRD section, user story, design doc, or architecture sketch touching authentication, user data, payments, file uploads, or an external integration is about to enter implementation and no threat model exists for it yet.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Overview
Quality
Evals
Security
Files

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, highly actionable methodology skill with clean progressive disclosure and a clear sequenced workflow. The main weakness is conciseness: several sections quote authoritative definitions of concepts Claude already knows (STRIDE categories, DREAD vs CVSS) that could be trimmed without losing the grounding citations.

Suggestions

Replace the verbatim Microsoft definition quotes in the six-row STRIDE table with a one-line gloss per category; keep the citation links but drop the full quoted definitions of spoofing, tampering, etc. that Claude already knows.

Condense the DREAD and 'not CVSS' digressions in Step 4 to a single sentence each — the distinction matters but the blog-quote and multi-bullet treatment over-explains a side point.

Trim the 'no magic sources or sinks' / 'no psychokinesis as transport' quoted rationale in Step 1 to a compact bullet stating the two sanity rules without the quoted exposition.

DimensionReasoningScore

Conciseness

Mostly efficient and accurate, but verbatim Microsoft definitions for all six STRIDE categories (e.g. spoofing as 'illegally accessing and then using another user's authentication information'), the 'no magic sources / no psychokinesis' quotes, and the DREAD/CVSS digressions explain concepts Claude already knows and could be tightened.

3 / 5

Actionability

Highly actionable for a methodology skill: a concrete 5-step procedure, a copy-paste output format with defined columns and four example threat rows, a file-path convention, a worked example, and a tabulated ASVS anchor table — specific guidance covering the common cases.

5 / 5

Workflow Clarity

Clear sequenced workflow (Steps 1–5 plus a 3-step from-spec workflow) with checkpoints such as 'Record the inventory before you write a single threat', the Step 3 filter gate, the no-fabrication rule, and ambiguity routing to 'Open questions'; the anti-patterns table acts as a review checklist, though there is no explicit validate→fix→retry feedback loop.

4 / 5

Progressive Disclosure

SKILL.md is a well-sectioned overview that links to a single one-level-deep reference, references/mitigations.md, in two clearly signaled places (Step 5 anchors and the worked example), with the bulky ASVS table and full worked example appropriately split out into that file.

5 / 5

Total

17

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A high-quality description: third-person, comprehensive in concrete capabilities, explicit on both what and when with concrete trigger artifacts and domains, and sharply bounded against adjacent security activities. Nothing vague or padded.

DimensionReasoningScore

Specificity

Lists multiple concrete actions — 'Enumerates security threats ... using Microsoft's six STRIDE categories', 'asset-and-trust-boundary walk that produces threat rows', 'threat-row output schema', 'likelihood x impact triage rule', 'write the threat-model document into the repo', 'no-fabrication rule' — giving comprehensive coverage rather than just naming the domain.

5 / 5

Completeness

Explicitly answers both what (enumerate STRIDE threats against a design and write the threat-model document) and when ('Use when a PRD section ... is about to enter implementation and no threat model exists for it yet'), with concrete trigger phrases and an explicit negative-scope clause.

5 / 5

Trigger Term Quality

Comprehensive natural-term coverage including the synonym set 'PRD section, user story, design doc, or architecture sketch' plus concrete trigger domains 'authentication, user data, payments, file uploads, or an external integration', alongside 'STRIDE' and 'threat model' themselves.

5 / 5

Distinctiveness Conflict Risk

Clear niche (design-stage STRIDE threat modeling) with explicit boundary language — 'it does not scan code, run a penetration test, or audit control compliance' — minimizing overlap with adjacent security skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Reviewed

Table of Contents