Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
Scanned 9/2/2026
Install to Claude Code
npx -y skills add arbiterForge/codeArbiter --skill ca-threat-model --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Ca Threat Model?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/arbiterforge-ca-threat-model-codearbiter)More formats (shields.io, HTML) on the badges page.
---
name: ca-threat-model
description: Opt-in lightweight STRIDE pass for a sensitive feature before implementation. Not a routine gate — invoke it when a change warrants security thought.
argument-hint: "<scope description>"
---
# /ca-threat-model — STRIDE pass (opt-in)
Optional, lightweight pre-implementation security review for a sensitive change — new external endpoints, new secrets-handling paths, new auth/authz flows. **Opt-in, not a routine gate**: nothing routes here automatically. Invoke it when a change warrants the thought; skip it otherwise. Read-only — modifies no file. Describe what the component does, what data it handles, and which actors interact with it.
## Routes to
`security-architecture` (`<plugin-root>/routines/security-architecture/SKILL.md`). The skill reads:
- `<project-root>/.codearbiter/security-controls.md` — compliance requirements.
- `<project-root>/.codearbiter/decisions/` — existing security-relevant ADRs.
## Output
```
## Scope
<what is being analyzed>
## STRIDE findings
| Threat | Category | Likelihood | Impact | Control |
|--------|-------------|------------|--------|------------------------------|
| ... | S/T/R/I/D/E | H/M/L | H/M/L | <control or NONE — needs one> |
## Recommended controls before implementation
- <control 1>
## Clearance
CLEAR TO IMPLEMENT | BLOCKED — resolve findings first
```
## When NOT to use
- Reviewing already-written code → `/ca-review`.
- A full cross-cutting review → `/ca-checkpoint`.
- A security question → `/ca-btw`.
## Hard gate
Read-only — modifies no file. This is an advisory pass, not a routine gate; it never runs unless
invoked.
Is this your skill, or is something wrong with this listing? . Author removals are honored within 72 hours.
No comments yet. Be the first to comment!