Works with
Senior Security
Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling.
Optimized workflow
This edition turns the source methodology into a repeatable agent workflow with explicit inputs, checkpoints and deliverables.
Quality standard
- Confirm scope and missing inputs before execution
- Ground decisions in available evidence and preserve source constraints
- Return an actionable result with assumptions, risks and next steps
Agent compatibility
The same core method is packaged for Claude, Codex, GPT, Gemini, Cursor and OpenCode.
Permissions & security
Source verified · conversion tested · security signals reviewed