From threat-modeling
Run the PASTA (Process for Attack Simulation and Threat Analysis) seven-stage, risk-centric threat model that ties technical threats to business impact. Use for a deeper, attacker-simulation threat model where business risk alignment matters (vs. the faster STRIDE pass).
How this skill is triggered — by the user, by Claude, or both
Slash command
/threat-modeling:pastaThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A PASTA threat model: business objectives → technical scope → decomposition →
A PASTA threat model: business objectives → technical scope → decomposition → threat analysis → vulnerability mapping → attack modeling → risk & countermeasures.
security-diagramming:threat-model-dfd).security-diagramming:attack-tree); simulate the chains.Work the stages in order; each feeds the next. Capture outputs per stage so the model is auditable. Map threats to ATT&CK and weaknesses to CWE for traceability.
A staged PASTA document: objectives → scope/DFD → decomposition → threats (ATT&CK)
→ weaknesses (CWE) → attack trees → ranked risks & countermeasures. Use
security-reporting for the final deliverable.
PASTA's value is business alignment and attacker simulation — keep stage 1 and stage 7 tightly connected so technical findings map back to business risk. Use STRIDE instead when you need a faster, design-time pass.
Provides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.
npx claudepluginhub jassics/awesome-claude-security --plugin threat-modeling