model-onboarding
Onboard a new model generation or sibling into oh-my-hermes: probe router recognition,…
[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Use when the user says: application-threat-model, application threat model,
$ npx -y skills add rlaope/oh-my-hermes --skill omh-application-threat-model --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/omh-application-threat-modelContext preview
The summary Claude sees to decide when to auto-load this skill.
[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Use when the user says: application-threat-model, application threat model,
name: "omh-application-threat-model"
description: "[omh] Attack paths into an operated system: turn a system's components and data flows into assets, trust boundaries, attack scenarios, controls, and the security test that proves each control holds. Use when the user says: application-threat-model, application threat model, threat model, threat modeling, threat modelling, threat modeling session, threat modeling workshop, security threat model."
metadata:
hermes:
tags: [workflow, oh-my-hermes, review]
category: review
phase: application-threat-model
role: reviewer
quality_tier: security-safety-gatedThis is a Hermes-native `application-threat-model` workflow skill.
`application-threat-model` exists because the nearest neighbour does not merely miss this request. `security-safety-review` maps the agent's own prompt, tool, credential, and dependency surface, so an application threat-model request came back as an agent tool inventory under a near-identical name — a confident wrong artifact rather than a miss, in the one domain where that costs most.
Good example:
Bad example:
Use when Hermes must model the security of an application, service, or deployed system the user operates: which assets are worth taking, where trust changes hands, how an attacker reaches each asset, which control stops them, and which security test fails when that control is removed. The subject is the modeled system, never the agent's own runtime.
Strong routing signals: `application-threat-model`, `application threat model`, `threat model`, `threat modeling`, `threat modelling`, `threat modeling session`, `threat modeling workshop`, `security threat model`, `build a threat model`, `model the threats`, `threat scenarios`, `stride analysis`, `stride model`, `trust boundary`, `trust boundaries`, `attack scenario`, `attack scenarios`, `attack tree`, `attack trees`, `abuse case`, `abuse cases`, `security design review`, `security architecture review`, `architecture security review`, `how would an attacker`, `how could an attacker`, `what could an attacker do`, `attacker perspective`
Category: `review` Phase: `application-threat-model` Hermes role: `reviewer` Quality tier: `security-safety-gated` Reasoning demand: `standard`
Quality bar:
English | 한국어 | 日本語 | 中文 Install once. Keep Hermes. Add a stronger operating layer. Planning, research, creation, coding handoffs, operations, and project memory with explicit evidence boundaries.
Repo: rlaope/oh-my-hermes
Onboard a new model generation or sibling into oh-my-hermes: probe router recognition,…
Review oh-my-hermes pull requests that have not been reviewed at their current head commit.…
Backfill labels across oh-my-hermes issues and pull requests. Run manually to sweep…
[omh] Screen-reader or keyboard accessibility gaps: prepare WCAG, keyboard, focus,…
[omh] Hermes badges unlocked and achievement progress: achievements observation: summarize…
[omh] Technical proposal facing adversarial scrutiny: independent perspectives attack a…