c/security › command
0votes

Threat model a new featurePrompt

submitted by u/client to c/security · 0 copies

STRIDE-style review that ends with concrete mitigations.

Prompt · 3 variables
Threat model this feature before we build it:

Feature: {{feature_description}}
Data involved: {{data_types}}
Users and roles: {{roles}}

1. Draw the data flow in text (actors → components → data stores).
2. For each step, list threats using STRIDE (spoofing, tampering, repudiation, info disclosure, DoS, elevation).
3. Rate each threat Low/Medium/High by likelihood and impact.
4. Give a concrete mitigation for every Medium and High.
5. List the security tests we should add.
0 commentsreport
0 comments

Log in to join the discussion.