OpenAI · Agent Skill

security-threat-model

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform…

Published by OpenAI81 lines in SKILL.md
Source
openai/skills/skills/.curated/security-threat-model
Repository owner
openai

Install

Read the SKILL.md and any scripts before installing: a skill runs with your agent's permissions. This copies just this skill into Claude Code's user skills folder; other agents read skills from their own folder.

Claude Code (user-level)

git clone --depth 1 --filter=blob:none --sparse https://github.com/openai/skills.git /tmp/skills
cd /tmp/skills && git sparse-checkout set "skills/.curated/security-threat-model"
mkdir -p ~/.claude/skills && cp -r "skills/.curated/security-threat-model" ~/.claude/skills/security-threat-model

Skills folder docs:

Works with

Agent Skills is an open format, so this skill loads in any harness that supports it, including Claude Code, Codex, Gemini CLI, OpenCode, Cursor, GitHub Copilot, goose, OpenHands. Some skills are written for one product and say so in their description.

More skills from OpenAI

Reviewed Oct 5, 2026. Name and description are the skill's own frontmatter.