Threat Lens

A threat model from a description — boundaries, attacker model, ranked threats, focus areas.

Back to SkillSafe
Or pick files: docs are read locally, nothing uploads until you run.
Context — anything out of scope, or already handled elsewhere
How it works

Nothing to hand? Load the — an internet-facing service with uploads, sharing and PII — or the , where the exposure is narrow and most severity should be downgraded.

1

Describe the system

What it does, its components and data stores, how requests get in, where it's deployed, what data it touches. The instant prescan reads it for free while you type and lists what it mechanically found: attack surfaces (APIs, uploads, webhooks, databases, queues, admin consoles), sensitive assets (credentials, PII, payment data) and exposure hints (internet-facing, multi-tenant, anonymous access).

2

The AI models the threats

A posture verdict; the primary components and trust boundaries with the data and controls on each edge; an attacker model with explicit non-capabilities so severity stays honest; entry points, five-to-ten multi-step abuse paths, and a prioritized threat table with likelihood, severity, priority and concrete mitigations. Every prescan fact is confirmed or explicitly set aside.

3

Review and act

Mark each threat accepted, already mitigated or won't-fix — your verdicts ride along into the CSV, the report and the design-doc block. Copy a “Security considerations” section straight into the doc, or a review checklist built from the focus areas. Model history follows your account when you sign in (mirrored on this device), and a second run is compared against the first: posture change, threats resolved, threats added, questions answered.

Derived from the @openai/security-threat-model skill (MIT license).