| name | threat-model-producer |
|---|---|
| description | Produce an open-source project's threat model — the implicit contract between the project and downstream users (what's in scope, what's out, what's claimed, what's disclaimed). Use when a project needs a threat model for an automated security scan (e.g. Glasswing), to anchor vulnerability-report triage, or when a maintainer asks "what's our security model?". Source — Michael Scovetta's gist `https://gist.github.com/scovetta/2dc9a0695c7cbcc32e23799e00d2ced3`, imported verbatim and bound here as a reusable SKILL. |
This document is an instruction set for whoever is producing a threat model for an open-source project — a human reviewer, a coding assistant, an automated tooling pipeline, or any combination. It is deliberately