/ca-threat-model
Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
$ npx -y skills add arbiterForge/codeArbiter --skill ca-threat-model --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/ca-threat-model
Context preview
The summary Claude sees to decide when to auto-load this skill.
Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
SKILL.md
ca-threat-model.SKILL.mdname: ca-threat-model
description: Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
argument-hint: "<scope description>"
$ca-threat-model — STRIDE pass (opt-in)
Optional, lightweight pre-implementation security review for a sensitive change — new external endpoints, new secrets-handling paths, new auth/authz flows. **Opt-in, not a routine gate**: nothing routes here automatically. Invoke it when a change warrants the thought; skip it otherwise. Read-only — modifies no file. Describe what the component does, what data it handles, and which actors interact with it.
Routes to
`security-architecture` (`${CLAUDE_PLUGIN_ROOT}/routines/security-architecture/SKILL.md`). The skill reads:
- `<project-root>/.codearbiter/security-controls.md` — compliance requirements.
- `<project-root>/.codearbiter/decisions/` — existing security-relevant ADRs.
Output
## Scope
<what is being analyzed>
## STRIDE findings
| Threat | Category | Likelihood | Impact | Control |
|--------|-------------|------------|--------|------------------------------|
| ... | S/T/R/I/D/E | H/M/L | H/M/L | <control or NONE — needs one> |
## Recommended controls before implementation
- <control 1>
## Clearance
CLEAR TO IMPLEMENT | BLOCKED — resolve findings first
When NOT to use
- Reviewing already-written code → `$ca-review`.
- A full cross-cutting review → `$ca-checkpoint`.
- A security question → `$ca-btw`.
Hard gate
Read-only — modifies no file. This is an advisory pass, not a routine gate; it never runs unless invoked.
Read more
name: ca-threat-model description: Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought. argument-hint: "<scope description>"
$ca-threat-model — STRIDE pass (opt-in)
Optional, lightweight pre-implementation security review for a sensitive change — new external endpoints, new secrets-handling paths, new auth/authz flows. **Opt-in, not a routine gate**: nothing routes here automatically. Invoke it when a change warrants the thought; skip it otherwise. Read-only — modifies no file. Describe what the component does, what data it handles, and which actors interact with it.
Routes to
`security-architecture` (`${CLAUDE_PLUGIN_ROOT}/routines/security-architecture/SKILL.md`). The skill reads:
- `<project-root>/.codearbiter/security-controls.md` — compliance requirements.
- `<project-root>/.codearbiter/decisions/` — existing security-relevant ADRs.
Output
## Scope <what is being analyzed> ## STRIDE findings | Threat | Category | Likelihood | Impact | Control | |--------|-------------|------------|--------|------------------------------| | ... | S/T/R/I/D/E | H/M/L | H/M/L | <control or NONE — needs one> | ## Recommended controls before implementation - <control 1> ## Clearance CLEAR TO IMPLEMENT | BLOCKED — resolve findings first
When NOT to use
- Reviewing already-written code → `$ca-review`.
- A full cross-cutting review → `$ca-checkpoint`.
- A security question → `$ca-btw`.
Hard gate
Read-only — modifies no file. This is an advisory pass, not a routine gate; it never runs unless invoked.
When you can't trust yourself with your code base, trust Arbiter.
Repo: arbiterForge/codeArbiter
Other skills on codearbiter.
- /brainstorming
The Socratic spec-refinement front of /feature, and the planning front of /sprint. Routed to BEFORE any code — it takes a one-line idea and drives it to an approved, concrete spec with testable acceptance criteria. Four gated phases — frame, refine, write, approve. No
Open skill - /commit-gate
The only path to a commit. Routed to when the user invokes /commit or otherwise instructs codeArbiter to persist staged changes. Nine gated phases — permission, branch, classification, verification (test/lint/secrets), behavioral proof, diff review, selective stage, message,
Open skill - /context-check
Optional manual drift audit — report stale provenance-tracked docs (via _provenancelib drift detection across .codearbiter/.provenance/), then per stale doc offer re-scout / re-baseline / defer. Not the daily loop; commit-gate auto-heal owns routine maintenance.
Open skill - /context-creation
The brownfield back-fill. Routed to by /create-context, and by startup when .codearbiter/CONTEXT.md lacks the <!--INITIALIZED--> body marker but source code exists. Six gated phases — pre-flight, scout dispatch, synthesis, gap interview, write, lock. Reads the existing codebase
Open skill - /crypto-compliance
The banned-primitive gate. Routed to when changed code hashes, signs, encrypts, derives keys, generates security-relevant randomness, configures TLS, or imports a crypto library. Rejects broken primitives, disabled TLS verification, and home-rolled crypto; the approved-primitive
Open skill - /debug
Investigate-then-decide root-cause analysis for a defect whose cause is unknown (distinct from /fix, which assumes a known bug). Five gated phases: capture, hypothesize, gather, decide, hand off. Investigation only, no code changes; exits to /fix, /adr, or a no-action close.
Open skill

