threat-modeling
This Claude Code plugin runs automated STRIDE threat modeling on features or designs, enumerating assets, trust boundaries, and threats across all six STRIDE categories (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) with concrete mitigations. It activates automatically when you mention threat modeling, security design reviews, or STRIDE concepts, and includes a read-only threat-modeler subagent that produces verbose threat models in an isolated context.
Install
Source: https://github.com/matthews-wong/claude-code-plugins/tree/HEAD/plugins/threat-modeling
What it's made of
1 agent · 1 skill
- Commands
- 0
- Agents
- 1
- Skills
- 1
- MCP servers
- 0
- Hooks
- 0
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
- none
- Talks to
- nothing external detected
Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (matthews-wong).