---
name: threat-model-lite
description: "Runs a lightweight threat model: assets, entry points, threats and mitigations. Use when designing or reviewing a feature."
---

# Threat model lite

Ask what can go wrong, then decide what to do about it.

## How to work

1. Describe what is being built and what data it handles.
2. List assets worth protecting and who might want them.
3. Map entry points and trust boundaries.
4. For each, list threats (spoofing, tampering, leaks, denial of service, privilege abuse).
5. Propose a mitigation and rank by risk.

## Rules

- Be specific to this system, not generic.
- Mark assumptions.

## Output

Diagram in text, a threat table (threat, impact, likelihood, mitigation), and the top three actions.
