idea-analogist
想法群聊室 — 类比者角色。被 idea-team 主编排器调用,或用户单独说"类比一下"、"别的行业有没有"、"yes-and 扩展"、"X…
Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. Use when touching authentication, authorization, payments, secrets, user data, uploads, webhooks, admin tools,
$ npx -y skills add majiayu000/spellbook --skill security-threat-model --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-threat-modelContext preview
The summary Claude sees to decide when to auto-load this skill.
Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. Use when touching authentication, authorization, payments, secrets, user data, uploads, webhooks, admin tools,
name: security-threat-model description: Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. Use when touching authentication, authorization, payments, secrets, user data, uploads, webhooks, admin tools, innerHTML/eval/exec, dependency upgrades, or cross-tenant access.
Use this skill before implementing or approving security-sensitive changes. It complements `auth-security` and `server-security` by mapping assets, attackers, trust boundaries, and concrete controls.
Identify:
1. Assets: credentials, tokens, user data, tenant data, money movement, admin actions. 2. Actors: anonymous user, authenticated user, tenant admin, internal operator, compromised dependency. 3. Trust boundaries: browser/server, service/service, tenant/tenant, CI/runtime, third-party callbacks. 4. Entry points: API routes, CLI commands, jobs, webhooks, uploads, config files. 5. Existing controls: validation, authz, rate limits, audit logs, secret storage.
Check at least:
Every finding needs one of:
Do not accept "warn and continue" for authz, secrets, tenant isolation, injection, or payment/security-critical failures.
scope: assets: trust_boundaries: entry_points: threats: required_controls: tests_or_probes: residual_risks: review_gate:
For implementation work, include exact files and verification commands that prove the controls are active.
Cross-runtime skills for Claude Code, Codex, and multi-agent workflows.
Repo: majiayu000/claude-arsenal
想法群聊室 — 类比者角色。被 idea-team 主编排器调用,或用户单独说"类比一下"、"别的行业有没有"、"yes-and 扩展"、"X…
想法群聊室 — 反方角色。被 idea-team 主编排器调用,或用户单独说"反方意见"、"挑这个想法的刺"、"为什么会失败"、"找漏洞 / 反例"、"devil's…
想法群聊室 — 调研员角色。被 idea-team 主编排器调用,或用户单独说"调研一下 X"、"X 的现状/竞品/数据"、"找 2026 数据"、"事实底"时触发。**用…
端到端产品教练 — 把一句话想法走到 PRD + 可点击 HTML 原型。会顶嘴、强制砍功能、用 Nielsen + Norman 做友好性硬检。Use when user…
Mobile app UI design expert for iOS and Android. Use when designing app interfaces, creating…