BigHugger
sk Skill · majiayu000

security-threat-model

Threat-model product features, APIs, data flows, secrets, permissions, supply-chain changes, auth boundaries, and risky code paths before or during implementation. Use when touching authentication, authorization, payments, secrets, user data, uploads, webhooks, admin tools, innerHTML/eval/exec, dependency upgrades, or cross-tenant access.

installs 8w
0
30-day movement
starts with the next reading
Related entries
5
Connections
0
Python
Host repository
majiayu000/spellbook
Host stars
280
Host language
Python