STRIDE threat identification with coverage checking (prose judgment) plus deterministic STRIDE coverage and DREAD severity scoring via executable script. Covers system architecture security review, trust boundaries across services, auth, payments, and PII feature pre-implementation review, and threat model refresh sessions. Use proactively when designing or reviewing a new system architecture or API, running pre-implementation security review for features touching auth, payments, or PII, conducting threat modeling sessions (initial or refresh), or reviewing another team's threat model for completeness. Run the coverage checker for deterministic STRIDE gap and DREAD scoring.
$npx -y skills add everyone-needs-a-copilot/claude-copilot --skill threat-modelingInstalls into the current project.
Run `npx skills use "https://github.com/everyone-needs-a-copilot/claude-copilot" --skill "everyone-needs-a-copilot/claude-copilot/threat-modeling"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/everyone-needs-a-copilot/claude-copilot" that are relevant to the current task. Run `npx skills add "https://github.com/everyone-needs-a-copilot/claude-copilot"` and select the relevant skills, then follow their instructions.