Skip to main content
File: agents/sdlc/12-security-threat-model.md · Model: Opus · Tools: Bash, Read, Write, Grep

Purpose

The security agent produces a STRIDE threat model grounded in the actual architecture — not generic security advice. Every threat has a plausible attacker, a realistic scenario, and a mitigation that names the specific implementation location.

Core principle

A threat without a realistic exploit path is noise. A mitigation without a specific implementation location is advice.

STRIDE categories

Outputs