AgentSkills.site

Skill profile · Inspected

security-threat-model

Produces a repository-grounded threat model — trust boundaries, assets, attacker capabilities, abuse paths, mitigations — written to a markdown file. Roughly half its description is negative triggers.

By

OpenAI

From

openai/skills

Verified

What it actually does

  • Produces a repository-grounded threat model — trust boundaries, assets, attacker capabilities, abuse paths, mitigations — written to a Markdown file.

When to use it — and when not to

Use it when

  • You want a structured threat model grounded in the actual repository, not a generic security checklist.

Not for

  • General architecture summaries, code review, or non-security design work — roughly half its own description is negative triggers spelling this out.

Agent compatibility

  • Codex

Confirmed means the skill’s own source or vendor states it works with that agent. Portable means it only reaches that agent through the shared SKILL.md format and a directory convention — real, but a weaker claim. An agent with no entry here isn’t known to be unsupported; it simply isn’t documented either way, so nothing is claimed. Full model on Agent Skills Compatibility.

Requirements and operational surface

What it actually does at runtime

  • Reads the repository
  • Writes a Markdown file with the resulting threat model

Workflow fit

Codebase mapping → threat modeling → mitigation planning → implementation.

Related skills

  • audit-context-buildingDifferent agents, same phase of the job — audit-context-building maps a codebase before review; this produces the review's output.

More from openai/skills

Other skills from the same source.

  • gh-fix-ciInspects failing PR checks with gh, fetches the GitHub Actions logs, summarizes the failure, then proposes a fix plan and implements it only after explicit approval.
  • gh-address-commentsFinds the open PR for your current branch and works through its review comments with the gh CLI, checking gh auth status first rather than failing halfway through.
  • playwrightDrives a real browser from the terminal for navigation, form filling, screenshots, and data extraction — CLI-first, and won't write @playwright/test files unless asked.
  • migrate-to-codexMigrates instruction files, skills, agents, and MCP config from another agent into Codex's own files, without touching the source agent's files.
  • pdfReads, creates, and reviews PDFs where layout matters, rendering pages for visual checks rather than only extracting text.

View all 6 →

Evidence and provenance

Maintained by OpenAI (official). Primary source: openai/skills, last checked against this page’s claims on . This page summarizes and analyzes that source — it isn’t a copy of its SKILL.md or README, and installation happens at the source, not here.

Topic: Security.

Also covered in The Best Codex Skills, part of the Codex guide.