# Threat Model

> STRIDE/DREAD threat-model synthesis. Use when the user says "/vibe-sec:threat-model", "generate a threat model", "STRIDE analysis", "what could go wrong with my app", "model the attack surface", "threat modeling". Consumes all other concerns' findings plus Vibe Test covered-surfaces and emits a STRIDE/DREAD model as Mermaid-in-markdown with a Threat-Dragon-compatible JSON sidecar. The synthesis sink node — runs last.

## Facts
- Page: https://tashan.sh/capability/skill-estevanhernandez-stack-ed-threat-model
- tashan id: skill:estevanhernandez-stack-ed/threat-model
- Source: https://github.com/estevanhernandez-stack-ed/vibe-sec
- Type: skill
- Category: security
- tashan score: 43.0 / 100
- Adoption: 14.0
- Upkeep: 77.0
- Freshness: 88.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- Official: no

## Install

```sh
cp -r threat-model ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-14 by tashan (https://tashan.sh) from public evidence. Scorer s5.
