tmdd-threat-modeling
OfficialGround threat models in real code with TMDD.
Authorattasec
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Threat modeling often relies on generic templates. This skill grounds threat modeling in the actual codebase architecture, producing actionable YAML threat models that reflect real components, data flows, and technologies to guide secure development decisions.
Core Features & Use Cases
- Architecture-driven threat modeling grounded in real code paths (components, data flows, and technologies).
- Automated generation of threats and mitigations tied to specific files/endpoints, with support for incremental updates in existing threat models.
- Integration with tmdd commands for linting, initialization, and feature planning, enabling reproducible security reviews across deployments.
- Facilitates collaboration between developers and security analysts by generating machine-readable YAML artifacts under .tmdd/.
Quick Start
Invoke the tmdd threat-modeling workflow to analyze your repository and generate a code-grounded threat model.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: tmdd-threat-modeling Download link: https://github.com/attasec/tmdd/archive/main.zip#tmdd-threat-modeling Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.