Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.
Systematic threat identification using the STRIDE methodology.
S - Spoofing → Authentication threats
T - Tampering → Integrity threats
R - Repudiation → Non-repudiation threats
I - Information → Confidentiality threats
Disclosure
D - Denial of → Availability threats
Service
E - Elevation of → Authorization threats
Privilege
| Category | Question | Control Family | | ------------------- | ----------------------------------------- | -------------- | | Spoofing | Can attacker pretend to be someone else? | Authentication | | Tampering | Can attacker modify data in transit/rest? | Integrity | | Repudiation | Can attacker deny actions? | Logging/Audit | | Info Disclosure | Can attacker access unauthorized data? | Encryption | | DoS | Can attacker disrupt availability? | Rate limiting | | Elevation | Can attacker gain higher privileges? | Authorization |
Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.
Copy a source-pinned command for your client. You run it yourself.
Destination: .claude/skills/stride-analysis-patterns · pinned to the source commit
# Run from your project root
git clone https://github.com/wshobson/agents.git .skillboard-tmp
git -C .skillboard-tmp checkout 38e19c20d2b154510b0e624a2e3e186b19b5c527
mkdir -p ".claude/skills"
cp -r ".skillboard-tmp/plugins/security-scanning/skills/stride-analysis-patterns" ".claude/skills/"
rm -rf .skillboard-tmpReview the source before running. This copies files into your project; it is not a one-click install and does not verify runtime safety.
sudo apt update && sudo apt install -y gitnpm install -g @anthropic-ai/claude-code# Run from your project root
git clone https://github.com/wshobson/agents.git .skillboard-tmp
git -C .skillboard-tmp checkout 38e19c20d2b154510b0e624a2e3e186b19b5c527
mkdir -p ".claude/skills"
cp -r ".skillboard-tmp/plugins/security-scanning/skills/stride-analysis-patterns" ".claude/skills/"
rm -rf .skillboard-tmpDestination: .claude/skills/stride-analysis-patterns
Scanner static-checks@0.1.0 · commit 38e19c20d2b1. Static checks cannot prove runtime safety – review the source and the exact diff before installing. How checks work.
No static rules matched. This is not a safety guarantee.