tmdd-threat-modeling

Official

Ground threat models in real code with TMDD.

Authorattasec
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Threat modeling often relies on generic templates. This skill grounds threat modeling in the actual codebase architecture, producing actionable YAML threat models that reflect real components, data flows, and technologies to guide secure development decisions.

Core Features & Use Cases

  • Architecture-driven threat modeling grounded in real code paths (components, data flows, and technologies).
  • Automated generation of threats and mitigations tied to specific files/endpoints, with support for incremental updates in existing threat models.
  • Integration with tmdd commands for linting, initialization, and feature planning, enabling reproducible security reviews across deployments.
  • Facilitates collaboration between developers and security analysts by generating machine-readable YAML artifacts under .tmdd/.

Quick Start

Invoke the tmdd threat-modeling workflow to analyze your repository and generate a code-grounded threat model.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: tmdd-threat-modeling
Download link: https://github.com/attasec/tmdd/archive/main.zip#tmdd-threat-modeling

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.