SkillAgentSearch skills...

stride-analysis-patterns

Apply STRIDE methodology to systematically identify threats

Install / Use

npx skills add wshobson/agents --skill stride-analysis-patterns

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

79/100

Category

Security

Supported Platforms

Universal

Our assessment of stride-analysis-patterns

stride-analysis-patterns scores 79/100 on our quality scale, 543rd of 653 Security skills we index.

Its SKILL.md is 2.4 KB long, well organised into 9 sections with 1 code example: moderately detailed.

With 39,920 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
20/30
Structure
17/20
Description
8/15
Adoption
20/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 5 days ago, so stride-analysis-patterns is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

stride-analysis-patterns compared with similar skills

All 4 of these similar skills score higher than stride-analysis-patterns; compare them before choosing.

SkillScoreStarsUpdatedFormat
stride-analysis-patterns (this skill)by wshobson7939.9k5d agoSKILL.md
algorithmic-artby anthropics100177.9k4d agoSKILL.md
pptxby anthropics100177.9k4d agoSKILL.md
designby nextlevelbuilder100130.2k5d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k5d agoSKILL.md

Frequently asked questions

How do I install stride-analysis-patterns?
Run npx skills add wshobson/agents --skill stride-analysis-patterns. The install tabs above show the steps for each supported agent.
Which AI agents does stride-analysis-patterns work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is stride-analysis-patterns safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is stride-analysis-patterns still maintained?
The repository was last updated 5 days ago, so stride-analysis-patterns is actively maintained.

name: stride-analysis-patterns description: Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation.

STRIDE Analysis Patterns

Systematic threat identification using the STRIDE methodology.

When to Use This Skill

  • Starting new threat modeling sessions
  • Analyzing existing system architecture
  • Reviewing security design decisions
  • Creating threat documentation
  • Training teams on threat identification
  • Compliance and audit preparation

Core Concepts

1. STRIDE Categories

S - Spoofing       → Authentication threats
T - Tampering      → Integrity threats
R - Repudiation    → Non-repudiation threats
I - Information    → Confidentiality threats
    Disclosure
D - Denial of      → Availability threats
    Service
E - Elevation of   → Authorization threats
    Privilege

2. Threat Analysis Matrix

| Category | Question | Control Family | | ------------------- | ----------------------------------------- | -------------- | | Spoofing | Can attacker pretend to be someone else? | Authentication | | Tampering | Can attacker modify data in transit/rest? | Integrity | | Repudiation | Can attacker deny actions? | Logging/Audit | | Info Disclosure | Can attacker access unauthorized data? | Encryption | | DoS | Can attacker disrupt availability? | Rate limiting | | Elevation | Can attacker gain higher privileges? | Authorization |

Templates and detailed worked examples

Full template library lives in references/details.md. Read that file when you need concrete templates for this skill.

Best Practices

Do's

  • Involve stakeholders - Security, dev, and ops perspectives
  • Be systematic - Cover all STRIDE categories
  • Prioritize realistically - Focus on high-impact threats
  • Update regularly - Threat models are living documents
  • Use visual aids - DFDs help communication

Don'ts

  • Don't skip categories - Each reveals different threats
  • Don't assume security - Question every component
  • Don't work in isolation - Collaborative modeling is better
  • Don't ignore low-probability - High-impact threats matter
  • Don't stop at identification - Follow through with mitigations

Related Skills

View on GitHub
GitHub Stars39.9k
CategorySecurity
Updated5d ago
Forks4.3k

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions