为自然搜索排名提供站点审计、内容撰写与竞品分析。
设计与多媒体
security-threat-model
试用为任意代码仓库或路径生成基于实际架构的结构化威胁模型
它能做什么
分析代码仓库的架构、数据流和入口点,输出 AppSec 级别的威胁模型报告。识别信任边界、列出风险资产、将攻击者目标映射到滥用路径,并针对具体组件提出缓解建议。报告在定稿前会与用户确认关键假设。
什么时候用它
- 重大发布或部署前的安全态势评估
- 新集成或对外服务上线前的代码审计
- 应要求为特定项目编写 AppSec 文档
- 对特定路径或组件进行安全评审
技能文档
Threat Model Source Code Repo
Deliver an actionable AppSec-grade threat model that is specific to the repository or a project path, not a generic checklist. Anchor every architectural claim to evidence in the repo and keep assumptions explicit. Prioritizing realistic attacker goals and concrete impacts over generic checklists.
Quick start
- Collect (or infer) inputs:
- Repo root path and any in-scope paths.
- Intended usage, deployment model, internet exposure, and auth expectations (if known).
- Any existing repository summary or architecture spec.
- Use prompts in
references/prompt-template.mdto generate a repository summary. - Follow the required output contract in
references/prompt-template.md. Use it verbatim when possible.
Workflow
1) Scope and extract the system model
- Identify primary components, data stores, and external integrations from the repo summary.
- Identify how the system runs (server, CLI, library, worker) and its entrypoints.
- Separate runtime behavior from CI/build/dev tooling and from tests/examples.
- Map the in-scope locations to those components and exclude out-of-scope items explicitly.
- Do not claim components, flows, or controls without evidence.
2) Derive boundaries, assets, and entry points
- Enumerate trust boundaries as concrete edges between components, noting protocol, auth, encryption, validation, and rate limiting.
- List assets that drive risk (data, credentials, models, config, compute resources, audit logs).
- Identify entry points (endpoints, upload surfaces, parsers/decoders, job triggers, admin tooling, logging/error sinks).
3) Calibrate assets and attacker capabilities
- List the assets that drive risk (credentials, PII, integrity-critical state, availability-critical components, build artifacts).
- Describe realistic attacker capabilities based on exposure and intended usage.
- Explicitly note non-capabilities to avoid inflated severity.
4) Enumerate threats as abuse paths
- Prefer attacker goals that map to assets and boundaries (exfiltration, privilege escalation, integrity compromise, denial of service).
- Classify each threat and tie it to impacted assets.
- Keep the number of threats small but high quality.
5) Prioritize with explicit likelihood and impact reasoning
- Use qualitative likelihood and impact (low/medium/high) with short justifications.
- Set overall priority (critical/high/medium/low) using likelihood x impact, adjusted for existing controls.
- State which assumptions most influence the ranking.
6) Validate service context and assumptions with the user
- Summarize key assumptions that materially affect threat ranking or scope, then ask the user to confirm or correct them.
- Ask 1–3 targeted questions to resolve missing context (service owner and environment, scale/users, deployment model, authn/authz, internet exposure, data sensitivity, multi-tenancy).
- Pause and wait for user feedback before producing the final report.
- If the user declines or can’t answer, state which assumptions remain and how they influence priority.
7) Recommend mitigations and focus paths
- Distinguish existing mitigations (with evidence) from recommended mitigations.
- Tie mitigations to concrete locations (component, boundary, or entry point) and control types (authZ checks, input validation, schema enforcement, sandboxing, rate limits, secrets isolation, audit logging).
- Prefer specific implementation hints over generic advice (e.g., "enforce schema at gateway for upload payloads" vs "validate inputs").
- Base recommendations on validated user context; if assumptions remain unresolved, mark recommendations as conditional.
8) Run a quality check before finalizing
- Confirm all discovered entrypoints are covered.
- Confirm each trust boundary is represented in threats.
- Confirm runtime vs CI/dev separation.
- Confirm user clarifications (or explicit non-responses) are reflected.
- Confirm assumptions and open questions are explicit.
- Confirm that the format of the report matches closely the required output format defined in prompt template:
references/prompt-template.md - Write the final Markdown to a file named
-threat-model.md(use the basename of the repo root, or the in-scope directory if you were asked to model a subpath).
Risk prioritization guidance (illustrative, not exhaustive)
- High: pre-auth RCE, auth bypass, cross-tenant access, sensitive data exfiltration, key or token theft, model or config integrity compromise, sandbox escape.
- Medium: targeted DoS of critical components, partial data exposure, rate-limit bypass with measurable impact, log/metrics poisoning that affects detection.
- Low: low-sensitivity info leaks, noisy DoS with easy mitigation, issues requiring unlikely preconditions.
References
- Output contract and full prompt template:
references/prompt-template.md - Optional controls/asset list:
references/security-controls-and-assets.md
Only load the reference files you need. Keep the final result concise, grounded, and reviewable.
常见问题
- 这个 skill 具体做什么?
- 它读取代码仓库结构,生成一份 Markdown 格式的威胁模型报告,包含信任边界、风险资产、攻击者能力、滥用路径和缓解建议。
- 它会执行安全测试或漏洞扫描吗?
- 不会。它基于代码架构分析生成威胁模型,而非漏洞扫描或代码审查。
- 什么时候用这个而不是通用架构总结?
- 当你明确需要威胁建模或滥用路径枚举时使用。它不会在通用架构、代码审查或非安全设计工作时触发。
相关技能
以 AI 机器人身份加入视频会议,提供语音、虚拟形象与屏幕共享四种模式。
docx
官方生成、编辑和提取 Word .docx/.dotx 文件内容,完整控制页面排版、表格和目录。
处理 PDF 文件的实用工具集,支持读取、编辑、创建和转换操作。
基于官方文档生成可运行的 ChatGPT App 项目( MCP 服务器 + 组件 UI)。
从代码或描述构建完整的 Figma 页面屏幕
OpenAI 的更多技能
浏览全部技能基于官方文档生成可运行的 ChatGPT App 项目( MCP 服务器 + 组件 UI)。
从代码或描述构建完整的 Figma 页面屏幕
把代码同步为完整的 Figma 设计系统——按正确顺序生成 tokens、组件和文档。
通过 Plugin API 在 Figma 文件中直接执行 JavaScript——创建节点、设置变量、构建组件、修改布局。
从文本、图像或品牌线索生成可立即用于 Codex 的 8×9 动画宠物图集,含 QA 预览表和 pet.json 打包文件。
imagegen
官方根据文本描述生成或编辑位图图像——照片、插画、纹理、精灵图、模型图、背景抠图。