More screenshots
Works with the AI tools you already use
STRIDE Web API Threat Model
Turn a web API architecture into a traceable STRIDE-per-element threat model.
$24.99
STRIDE Web API Threat Model
Example session with this skill installed
Threat-model this fictional multi-tenant SaaS API. A browser user sends HTTPS requests to an Express API, which queries PostgreSQL. The client supplies organization_id, and the API trusts it when loading tenant records. Reconstruct the DFD, mark trust boundaries, apply STRIDE per element, verify coverage and DREAD arithmetic, then return a prioritized mitigation roadmap.
- Read your context and instructions
- Compiled the stride web api
STRIDE Coverage Summary
Elements: browser_user (external entity), express_api (process), postgres (data store), https_request_flow and sql_query_flow (data flows). Three elements cross a trust boundary.
| ID | STRIDE | Element | DREAD | Tier | Evidence |
|---|---|---|---|---|---|
| WA-01 | Elevation of Privilege | express_api | 44 | CRITICAL | The client supplies organization_id and the process uses it as the tenant selector without server-side membership authorization. |
| WA-02 | Spoofing | browser_user | 31 | HIGH | The request identity and organization selector can be presented independently. |
| WA-04 | Denial of Service | express_api | 34 | HIGH | The boundary process has no supplied resource-control evidence. |
| WA-03 | Information Disclosure | https_request_flow | 29 | MEDIUM | Tenant-scoped response data crosses the public request boundary. |
Coverage gate: each entity, process, store, and flow received only valid STRIDE categories; DREAD totals reconcile with their five inputs.
Priority mitigation: derive organization scope from the authenticated server-side session, enforce object-level authorization before every tenant read, reject client attempts to override the organization context, and log denied cross-tenant access.
Verification test: authenticate as a user from organization A and request an object owned by organization B while supplying both organization IDs. Pass only if every route returns the same denial and no tenant-B data appears in the response or logs.
Scope: this model covers only the supplied architecture and controls.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Build a rigorous STRIDE-per-element threat model for a web app, REST or GraphQL API, backend service, or authentication flow. The Skill reconstructs the supplied architecture as external entities, processes, data stores, data flows, and trust boundaries; applies only valid STRIDE categories per element; checks boundary-crossing authorization; validates DREAD arithmetic; and maps each evidence-bounded finding to a concrete mitigation.
The package includes the full SKILL.md workflow, DFD method, STRIDE matrix, mitigation catalog, structured sample, coverage schema, deterministic coverage checker, tests, and a six-page PDF buyer guide.
It does not run penetration tests, generate exploit payloads, inspect live systems, certify security, or cover AI-agent, cloud-IAM, or IoT-specific threat models.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install