Skill file
---
name: threat-model-lite
description: "Runs a lightweight threat model: assets, entry points, threats and mitigations. Use when designing or reviewing a feature."
---
# Threat model lite
Ask what can go wrong, then decide what to do about it.
## How to work
1. Describe what is being built and what data it handles.
2. List assets worth protecting and who might want them.
3. Map entry points and trust boundaries.
4. For each, list threats (spoofing, tampering, leaks, denial of service, privilege abuse).
5. Propose a mitigation and rank by risk.
## Rules
- Be specific to this system, not generic.
- Mark assumptions.
## Output
Diagram in text, a threat table (threat, impact, likelihood, mitigation), and the top three actions.
How to use it
- Download the skill.
- Put its folder (with SKILL.md inside) in .claude/skills/threat-model-lite/ for just this project, or in ~/.claude/skills/ for every project.
- Restart your tool and ask for what the skill does. It loads on its own when it fits.
Try it
Threat model the new file upload feature.
Runs a lightweight threat model: assets, entry points, threats and mitigations. Use when designing or reviewing a feature.