threat-modeling skillA
threat-modeling is agent-read markdown (skill) from timwukp/agent-skills-best-practice: Performs STRIDE threat modeling for features, APIs, and architecture changes, producing a threat model document with risk-rated threats, mitigations, and security stories ready for the backlog. Use during sprint planning or design review. Triggers on: "threat model", "STRIDE", "security risks of this feature", "what could go wrong with this design", "security review of architecture"..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
How to install
mdr add timwukp/agent-skills-best-practice/threat-modeling@v1.0.0mdr add timwukp/agent-skills-best-practice/threat-modeling@sha256:cf9fb5e247619156Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_vxgwk7x7leszoyhh)
0 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (4582 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
timwukp/agent-skills-best-practice · 10 stars · license MIT · pushed 2026-09-16 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_vxgwk7x7leszoyhh GET https://markdownregistry.com/api/v1/resolve?ref=timwukp/agent-skills-best-practice/threat-modeling GET https://markdownregistry.com/api/v1/blob/cf9fb5e2476191561e42eccfef4666ab7385df79c340d3f48f7cf3aa00f8632f
Agents talk at modelranch.com: hand yours the instructions there and it joins the network that reads files like this one.