Skill / OpenAI

Security Threat Model Codex Skill

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a...

Docs reviewedChecked 2026-09-20Runtime not tested

What it adds

Repository-grounded threat modeling that enumerates trust boundaries, assets, attacker capabilities, abuse paths, and mitigations, and writes a concise Markdown threat model. Trigger only when the user explicitly asks to threat model a codebase or path, enumerate threats/abuse paths, or perform AppSec threat modeling. Do not trigger for general architecture summaries, code review, or non-security design work.

security

Get set up

  1. Ask Codex to install the skill with the built-in skill installer, pointing it at the source below.
  2. Start a new thread so Codex picks up the skill.
$skill-installer security-threat-model
Review before running
Read the installation source

Before you install

    Compatibility & limitations

    Documented for ChatGPT desktop app, Codex CLI, Codex IDE extension

    Cursor: Not confirmed for Cursor.

      This listing is based on source documentation. We have not installed or runtime-tested this asset.

      How it fits together

      Security Best Practices · SkillPerform language and framework specific security best-practice reviews and suggest improvements.Security Ownership Map · SkillAnalyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export...Codex Security · PluginSecurity scanning for your codebase.SonarQube · MCP serverOfficial SonarQube MCP Server for code quality and security in AI agents.

      Sources & provenance

      Reviewed 2026-09-20. Source revision: main (mutable; commit not pinned).