What problem does it solve? Organizations often skip structured threat analysis because it seems too technical, leaving security risks undiscovered until after incidents occur. This Skill walks non-technical stakeholders through a systematic threat modeling process without requiring deep security engineering expertise. ## Core Features & Use Cases - Asset and Data Flow Mapping: Identifies valuable data, trust boundaries, and how information moves through a system in plain business language. - STRIDE-Based Threat Questioning: Translates the STRIDE framework (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege) into plain-language questions anyone can answer. - Risk Prioritization and Mitigation Planning: Uses a simple impact-versus-likelihood matrix and produces actionable reports with owners and deadlines. - Use Case: Before launching a new customer-facing feature, a product manager uses this Skill to map data flows, surface threats like unauthorized data access by partners, and produce a documented risk register for auditors. ## Quick Start Ask the agent to run a threat modeling session for your system by describing its users, most sensitive data, and main data flows.