Skip to content
Development
Skill

/ca-threat-model

Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.

From plugin
codearbiter
14562 skills19 agents42 commands
Install
$ npx -y skills add arbiterForge/codeArbiter --skill ca-threat-model --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/ca-threat-model

Context preview

The summary Claude sees to decide when to auto-load this skill.

Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.

SKILL.md

ca-threat-model.SKILL.md
name: ca-threat-model
description: Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
argument-hint: "<scope description>"

$ca-threat-model — STRIDE pass (opt-in)

Optional, lightweight pre-implementation security review for a sensitive change — new external endpoints, new secrets-handling paths, new auth/authz flows. **Opt-in, not a routine gate**: nothing routes here automatically. Invoke it when a change warrants the thought; skip it otherwise. Read-only — modifies no file. Describe what the component does, what data it handles, and which actors interact with it.

Routes to

`security-architecture` ([routines/security-architecture/SKILL.md](../../routines/security-architecture/SKILL.md)). The skill reads:

  • `<project-root>/.codearbiter/security-controls.md` — compliance requirements.
  • `<project-root>/.codearbiter/decisions/` — existing security-relevant ADRs.

Output

## Scope
<what is being analyzed>

## STRIDE findings
| Threat | Category    | Likelihood | Impact | Control                      |
|--------|-------------|------------|--------|------------------------------|
| ...    | S/T/R/I/D/E | H/M/L      | H/M/L  | <control or NONE — needs one> |

## Recommended controls before implementation
- <control 1>

## Clearance
CLEAR TO IMPLEMENT | BLOCKED — resolve findings first

When NOT to use

  • Reviewing already-written code → `$ca-review`.
  • A full cross-cutting review → `$ca-checkpoint`.
  • A security question → `$ca-btw`.

Hard gate

Read-only — modifies no file. This is an advisory pass, not a routine gate; it never runs unless invoked.

Read more
Ships withcodearbiter

When you can't trust yourself with your code base, trust Arbiter.

Get the whole plugin

Other skills on codearbiter.