ca-threat-model
Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
Install
npx skills add https://github.com/arbiterForge/codeArbiter/tree/main/plugins/ca-codex/skills/ca-threat-model
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install arbiterforge-codearbiter@llmmart
git clone https://github.com/arbiterForge/codeArbiter.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole arbiterforge/codearbiter collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
$ca-threat-model — STRIDE pass (opt-in)
Optional, lightweight pre-implementation security review for a sensitive change — new external endpoints, new secrets-handling paths, new auth/authz flows. Opt-in, not a routine gate: nothing routes here automatically. Invoke it when a change warrants the thought; skip it otherwise. Read-only — modifies no file. Describe what the component does, what data it handles, and which actors interact with it.
Routes to
security-architecture (routines/security-architecture/SKILL.md). The skill reads:
<project-root>/.codearbiter/security-controls.md— compliance requirements.<project-root>/.codearbiter/decisions/— existing security-relevant ADRs.
Output
## Scope
<what is being analyzed>
## STRIDE findings
| Threat | Category | Likelihood | Impact | Control |
|--------|-------------|------------|--------|------------------------------|
| ... | S/T/R/I/D/E | H/M/L | H/M/L | <control or NONE — needs one> |
## Recommended controls before implementation
- <control 1>
## Clearance
CLEAR TO IMPLEMENT | BLOCKED — resolve findings first
When NOT to use
- Reviewing already-written code →
$ca-review. - A full cross-cutting review →
$ca-checkpoint. - A security question →
$ca-btw.
Hard gate
Read-only — modifies no file. This is an advisory pass, not a routine gate; it never runs unless invoked.
Files (codearbiter)
-
SKILL.md 1.7 KB
--- name: ca-threat-model description: Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought. argument-hint: "<scope description>" --- # $ca-threat-model — STRIDE pass (opt-in) Optional, lightweight pre-implementation security review for a sensitive change — new external endpoints, new secrets-handling paths, new auth/authz flows. **Opt-in, not a routine gate**: nothing routes here automatically. Invoke it when a change warrants the thought; skip it otherwise. Read-only — modifies no file. Describe what the component does, what data it handles, and which actors interact with it. ## Routes to `security-architecture` ([routines/security-architecture/SKILL.md](../../routines/security-architecture/SKILL.md)). The skill reads: - `<project-root>/.codearbiter/security-controls.md` — compliance requirements. - `<project-root>/.codearbiter/decisions/` — existing security-relevant ADRs. ## Output ``` ## Scope <what is being analyzed> ## STRIDE findings | Threat | Category | Likelihood | Impact | Control | |--------|-------------|------------|--------|------------------------------| | ... | S/T/R/I/D/E | H/M/L | H/M/L | <control or NONE — needs one> | ## Recommended controls before implementation - <control 1> ## Clearance CLEAR TO IMPLEMENT | BLOCKED — resolve findings first ``` ## When NOT to use - Reviewing already-written code → `$ca-review`. - A full cross-cutting review → `$ca-checkpoint`. - A security question → `$ca-btw`. ## Hard gate Read-only — modifies no file. This is an advisory pass, not a routine gate; it never runs unless invoked.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.