security-threat-model
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- Repository-Grounded Analysis: The skill is designed to perform application security threat modeling by analyzing source code, architecture, and trust boundaries. It provides a disciplined approach to identifying security risks specific to a project's context.
- Secret Redaction Guidance: The prompt templates specifically instruct the agent to never output secrets encountered in the codebase, requiring them to be redacted and only described in terms of presence and location.
- Evidence-Based Reporting: The instructions emphasize that every architectural claim or threat must be backed by evidence (anchors) found within the repository, reducing the risk of hallucinations or misinterpretations of the system's security posture.
- Scope Separation: The workflow explicitly separates production/runtime behavior from CI/CD, build tools, and test environments, ensuring that the threat model focuses on the appropriate context.
Audit Metadata