
Threat Model
OfficialFreeBuild comprehensive threat models for codebases.
Free · Opens the source repo
What Threat Model does
The Threat Model skill is designed to help developers and security professionals systematically assess potential threats to their codebases. It operates in three distinct modes: 'interview', 'bootstrap', and 'bootstrap-then-interview'. In 'interview' mode, the skill guides an application owner through a structured four-question framework, enabling them to articulate what their system does, what could go wrong, and how to mitigate those risks. This is particularly useful for new systems or during design reviews where the business logic may not be fully represented in the code.
In 'bootstrap' mode, the skill leverages static analysis to generate a threat model based on the code itself, along with historical data such as past vulnerabilities, git history, and pentest reports. This mode is ideal for inherited systems or third-party code where an application owner may not be available. It synthesizes findings into a coherent threat model, allowing teams to focus on critical vulnerabilities that could impact the system.
The 'bootstrap-then-interview' mode combines both approaches, allowing for an initial draft to be created from the code before refining it through a conversation with the application owner. This method maximizes the efficiency of the owner's time by focusing on validating and enhancing a code-grounded draft rather than starting from scratch.
Regardless of the mode used, the output is a standardized THREAT_MODEL.md file that adheres to a defined schema, ensuring consistency and usability across different teams and tools. This skill is particularly valuable for security teams looking to proactively manage risks and for developers who need to understand the security implications of their code.
When to use it
Use this skill when you need to assess the security posture of a codebase, especially during development or before deployment.
When not to use it
This skill is not suitable for real-time vulnerability testing or when immediate execution of code is required.
What you can build with it
Assessing New Applications
Use the interview mode to engage with application owners during the development of new software, ensuring potential threats are identified early.
Evaluating Legacy Code
Apply the bootstrap mode to analyze older codebases where documentation may be lacking, leveraging historical vulnerability data for insights.
Combining Insights
Utilize the bootstrap-then-interview mode to create a draft threat model from code analysis, then refine it through discussions with the application owner.
How to install Threat Model
View source1. Install with the skills CLI
npx skills add anthropics/defending-code-reference-harness/threat-model --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by anthropicsthreat-model
A threat model answers "what could go wrong with this system, who would do it, and what should we do about it?" independently of whether any specific bug has been found yet. It is the map; vulnerability discovery is the metal detector. A good threat model tells the pipeline where to look and tells triage which findings matter.
Litmus test: If patching one line of code makes an entry disappear, it was
a vulnerability, not a threat. A threat ("attacker achieves RCE via untrusted
media parsing") still stands after every known bug is fixed; a vulnerability
("dr_wav.h:412 doesn't bounds-check chunk_size") does not. This skill
produces threats. Vulnerabilities appear only as evidence that raises a
threat's likelihood score.
Invocation: /threat-model [bootstrap-then-interview|bootstrap|interview] <target-dir> [flags]
Step 0 — Safety preamble (always runs first)
This skill performs static analysis only. It reads source, git history,
and any vulnerability reports the user supplies, and writes a single output
file (<target-dir>/THREAT_MODEL.md). It does not build, execute, fuzz, or
modify the target, and does not make network requests against the target's
infrastructure.
Before proceeding, confirm and state in your first response:
- The target directory exists and is a local checkout you can read.
- You will not execute any code from the target directory.
- If
--vulnspoints at a URL or you are asked to "fetch CVEs", you will query only public advisory databases (NVD, GitHub Security Advisories, the project's own issue tracker) and never the target's live deployment.
If the user asks you to validate a threat by running an exploit, decline and
point them at the vuln-pipeline (README Step 2) instead.
Step 1 — Route to a mode
Parse $ARGUMENTS:
| First token | Route to |
|---|---|
interview | Read interview.md in this directory and follow it. |
bootstrap | Read bootstrap.md in this directory and follow it. |
bootstrap-then-interview | Bootstrap first, then interview seeded from the draft. See below. |
| anything else, or empty | Ask the user: "Is someone who owns or built this system available to answer questions in this session?" Yes and the codebase is checked out → recommend bootstrap-then-interview. Yes but no codebase → interview.md. No → bootstrap.md. |
All modes write the same artifact (THREAT_MODEL.md, schema in schema.md)
so downstream consumers (pipeline recon/judge, verifier agents) do not need
to know which mode produced it.
interview | bootstrap | |
|---|---|---|
| Needs | An application owner present in the session | A local checkout; optionally past vulns |
| Method | Four-question framework: conversational walk through what are we working on → what can go wrong → what are we going to do about it → did we do a good job | Five stages: parallel research swarm → synthesize sections 1-3 + vuln table → generalize vulns into threat classes → STRIDE gap-fill → emit |
| Best for | New systems, design reviews, systems where the risk lives in business logic the code doesn't show | Inherited systems, third-party code, OSS dependencies, anything with a CVE history |
| Provenance tag | interview | bootstrap |
Context durability. Interview mode is multi-turn; tool results from early reads may be evicted before you need them. To stay resilient:
- Do not read
interview.mdorbootstrap.mdin full up front. Read the mode file (or the relevant section of it) at the point you need it, one question or stage at a time. - If a re-read via the Read tool is refused as "file unchanged", the prior
result was evicted; reload with
cat <path>via Bash instead.
Interview backbone (so you can proceed even if interview.md is
unavailable mid-session):
| Q | Question | Fills schema sections |
|---|---|---|
| Q1 | What are we working on? | section 1 context, section 2 assets, section 3 entry points |
| Q2 | What can go wrong? | section 4 threat rows (id, threat, actor, surface, asset) |
| Q3 | What are we going to do about it? | section 4 impact/likelihood/status/controls; section 5 deprioritized; section 8 recommended mitigations |
| Q4 | Did we do a good job? | validate ranking, coverage check, section 6 open questions |
bootstrap-then-interview mode
When the owner is available and the codebase is checked out, this is the recommended path: the owner's time goes to refining a code-grounded draft instead of describing the system from scratch.
- Tell the owner: "I'll read the code first and come back with a draft
(about 5-10 min), then we'll walk it together. Want that, or would you
rather start cold?" Only proceed if they opt in; otherwise fall back to
interview.md. - Read
bootstrap.mdand follow it end-to-end. Write<target-dir>/THREAT_MODEL.md. - Immediately continue into interview mode: read
interview.mdand follow it with--seed <target-dir>/THREAT_MODEL.mdin effect. The section 6 open questions from bootstrap become your Q1-Q4 prompts; the owner confirms, corrects, and adds rather than starting from nothing. - Overwrite
<target-dir>/THREAT_MODEL.mdwith the refined model. Set provenancemode: bootstrap-then-interview.
The same flow is available manually: run bootstrap first, then
interview --seed <THREAT_MODEL.md> in a later session.
Step 2 — Shared output contract
All modes MUST emit <target-dir>/THREAT_MODEL.md conforming to schema.md
in this directory. Read schema.md immediately before you write the file,
not at routing time; in interview mode the gap between routing and emit can be
many turns, and an early read will be evicted before it's used.
After writing the file, print to the user:
- The path to
THREAT_MODEL.md. - The top 5 threats by likelihood × impact (id, one-line description, L×I).
- For
bootstrap: any open questions the code could not answer (these seed a laterinterviewpass). - For
interview: any owner statements that could not be verified in code (these seed follow-up code review).
References
- docs/security.md and docs/prompting.md for the engagement-context and authorization framing this skill inherits.
Frequently asked questions about Threat Model
Similar skills
Microsoft Threat Modeling Tool Generator
Easily create .tm7 files for threat modeling.
Threat Model Analyst
Perform comprehensive threat modeling and analysis.
Modeling Threats with OpenCTI
Centralize and visualize cyber threat intelligence effectively.
Zero Trust DNS with NextDNS
Secure your DNS queries with encrypted protection and threat blocking.
STIX/TAXII Feed Integration
Integrate STIX/TAXII threat intelligence feeds seamlessly.
Attack Path Analysis with XM Cyber
Identify and prioritize vulnerabilities in your security landscape.
