Agent Skills
› codexstar69/bug-hunter
› threat-model-generation
threat-model-generation
GitHub基于STRIDE模型为仓库生成威胁建模和安全配置,识别信任边界与漏洞模式,供下游安全技能使用。
Trigger Scenarios
仓库无现有威胁模型
架构发生重大变更
需要更新信任边界上下文的安全审查
用户明确要求生成威胁模型
Install
npx skills add codexstar69/bug-hunter --skill threat-model-generation -g -y
SKILL.md
Frontmatter
{
"name": "threat-model-generation",
"description": "Generate or refresh a STRIDE-based threat model for the current repository using Bug Hunter-native artifacts. Use whenever the repository has no threat model yet, the architecture changed materially, a security review needs fresh trust-boundary context, or the user explicitly asks for a threat model."
}
Threat Model Generation
This is a bundled local Bug Hunter companion skill. It generates portable threat-model artifacts under .bug-hunter/.
Purpose
Create the security context that the other security skills depend on:
- trust boundaries
- major components
- STRIDE threats
- vulnerability pattern library
- severity/config defaults
Required outputs
Write:
.bug-hunter/threat-model.md.bug-hunter/security-config.json
Workflow
- Read
.bug-hunter/triage.jsonif available for file structure and domain hints. - Inspect the repository to identify:
- languages and frameworks
- public/authenticated/internal entry points
- data stores and external integrations
- sensitive assets and trust boundaries
- Generate a concise STRIDE threat model.
- Generate a matching security config with thresholds and tech-stack metadata.
Compatibility
prompts/threat-model.md is generated from this skill for older clients. This
skill is the canonical source and must be edited instead of the generated
compatibility prompt.
Output rules
- Keep the threat model short enough for downstream agents to consume.
- Be specific about trust boundaries and vulnerable code patterns.
- Keep all artifacts under
.bug-hunter/, never.factory/.
Version History
-
fa0cc06
Current 2026-08-16 08:03
移除对旧版prompts/threat-model.md的依赖说明,改为直接编辑本skill作为规范来源。
- 8dedbbb 2026-07-24 16:56


