What you can do
- Map assets, trust boundaries, abuse paths, and mitigations using repository evidence.
Before you start
- An authorized source repository plus deployment and authentication context.
Try your first task
After installing, send this example to your AI tool.
Use security-threat-model. Threat-model this file-upload service, identifying trust boundaries and the highest-impact abuse paths.
What to look for
A repository-grounded Markdown threat model with explicit assumptions.
Keep in mind
- The result depends on supplied architecture and deployment information.
Open source, traceable origins
Source, license, and package contents have been reviewed. End-to-end tasks have not been verified across agents; examples describe expected results.
Source reviewed:
FAQ
Agent Skills FAQ
Practical answers for choosing, installing, and using your first skill.
How do I install and start using Model application threats?
Download the complete ZIP and keep the security-threat-model folder and supporting files together. For a project installation, use .claude/skills/security-threat-model/ in Claude Code or .agents/skills/security-threat-model/ in Codex, with SKILL.md directly inside it. Complete this page's prerequisites, confirm discovery, and start with the example in the first-task card.
What do I need to use Model application threats?
An authorized source repository plus deployment and authentication context.
Can I use these Skills with Chinese requests?
You can ask an agent that supports Chinese to work with Chinese materials and produce Chinese output. Specify the desired language, audience, and terminology in your request. Results depend on the agent and skill, so check the output against your task requirements.
Who created this skill and which license is included?
The original author is OpenAI, from openai/skills, with the Apache-2.0 license included. AILesson preserves the files and source version, and GitHub Releases provides the download. Use the source card to inspect the pinned version and original files.
Have all Skills been tested, and what should I review?
The current collection has source, license, and package-content checks. It does not claim that every skill has completed real tasks in every agent. Review the files and prerequisites before enabling a skill, and check facts, citations, generated code, and proposed actions in its output. The examples describe expected results rather than verified demonstrations.






