Use for tokens, permissions, AI tools, untrusted content, shell, webhooks, APIs, or remote mutation. Identify assets and abuse cases; require least privilege, authentication, replay protection, exact-head decisions, bounded repair, and independent validation.
Installs into .claude/skills of the current project.
Are you the author of Threat Model?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/the-vibey-project-threat-model)
# Threat modeling
Use for tokens, permissions, AI tools, untrusted content, shell, webhooks, APIs, or remote
mutation. Identify assets and abuse cases; require least privilege, authentication,
replay protection, exact-head decisions, bounded repair, and independent validation.