Security Threat Model Codex Skill
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a...
What it adds
Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.
security
Get set up
- Ask Codex to install the skill with the built-in skill installer, pointing it at the source below.
- Start a new thread so Codex picks up the skill.
$skill-installer security-threat-modelReview before running
Before you install
Compatibility & limitations
Documented for ChatGPT desktop app, Codex CLI, Codex IDE extension
Cursor: Not confirmed for Cursor.
This listing is based on source documentation. We have not installed or runtime-tested this asset.
How it fits together
Security Best Practices · SkillPerform language and framework specific security best-practice reviews and suggest improvements.Security Ownership Map · SkillAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export...Codex Security · PluginSecurity scanning for your codebase.SonarQube · MCP serverOfficial SonarQube MCP Server for code quality and security in AI agents.Sources & provenance
Reviewed 2026-09-20. Source revision: main (mutable; commit not pinned).