Agentic Research

Security Threat Model (OpenAI Codex)

27,820 stars

Official Codex threat-modeling skill: repository-grounded enumeration of trust boundaries, assets, attacker capabilities, abuse paths and mitigations, producing a concise Markdown threat model.

First published:2025-11-25
data as of:
2026-09-30
Licence:
None declared (see repository)

When to use it

When explicitly asked to threat-model a codebase or path, or enumerate threats and abuse paths.

Caution

No license file in the repo; triggers only on explicit request (by design). Output is an analysis document, not a penetration test.

Install prompt

請幫我安裝「Security Threat Model (OpenAI Codex)」技能:從 https://github.com/openai/skills/tree/main/skills/.curated/security-threat-model(技能路徑:skills/.curated/security-threat-model/) 取得完整的技能目錄,放進我的 Agent 的技能目錄(例如專案內的 skills/ 資料夾,或該 Agent 文件指明的全域技能位置),確認裡面的 SKILL.md 存在、frontmatter 的 name 與 description 完整,然後列出這個技能宣告的腳本、外部工具與 API 需求,先不要執行任何腳本。

Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.

Get it Official source Source(27,820 ★)
Compatible with
Related patterns