Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Maestro

ASecurity

Run a MAESTRO threat model — the Cloud Security Alliance's layered framework for multi-agent / agentic AI systems — enumerating threats at each layer of the agent stack and across agent-to-agent and cross-layer trust boundaries. Use when threat modeling a multi-agent or agentic AI system where agent-to-agent trust, orchestration logic, and delegated tool use matter more than a single data flow.

8 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsrustgorailssecuritydocumentation

Works with

mcp

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add jassics/awesome-claude-security --skill maestro --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Maestro?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Maestro
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jassics-maestro/badge)](https://www.skillsdirectory.com/skills/jassics-maestro)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: maestro
description: >-
  Run a MAESTRO threat model — the Cloud Security Alliance's layered framework
  for multi-agent / agentic AI systems — enumerating threats at each layer of the
  agent stack and across agent-to-agent and cross-layer trust boundaries. Use when
  threat modeling a multi-agent or agentic AI system where agent-to-agent trust,
  orchestration logic, and delegated tool use matter more than a single data flow.
---

# Goal

A MAESTRO-layered threat analysis for a multi-agent/agentic system: the agent
stack decomposed into layers, cross-layer and cross-agent trust breaks enumerated,
and each mapped to a mitigation.

# Why MAESTRO, and when

STRIDE and PASTA are asset/data-flow-centric — excellent for a single system with a
clear DFD. Agentic systems add a different threat surface: autonomous agents
delegating to sub-agents, orchestrators trusting sub-agent output, tools/MCP
servers returning content that itself becomes an instruction, and emergent
behavior from agent-to-agent interaction that no single data flow captures.
MAESTRO (CSA, "Agentic AI Threat Modeling Framework: MAESTRO") decomposes the
agentic stack into layers and asks what can go wrong *at* each layer and *across*
layer/agent boundaries — complementary to, not a replacement for, STRIDE/PASTA.

- **Single-agent, simple system** → `stride` is enough.
- **Multi-agent, orchestrated, or tool/MCP-delegating system** → run MAESTRO
  alongside STRIDE; MAESTRO catches the cross-layer/cross-agent breaks STRIDE's
  per-element pass tends to miss.
- **GenAI feature generally** (RAG, single LLM call, etc.) → see
  `llm-security:ai-threat-model` for the OWASP LLM Top 10 overlay; that skill
  points back here for the multi-agent case.

# The layers (working model — see Notes)

1. **Foundation Models** — the model(s) themselves: training/fine-tune
   provenance, model-level vulnerabilities, jailbreak/alignment weaknesses.
2. **Data Operations** — data ingestion, RAG stores, embeddings, memory:
   provenance, poisoning, cross-tenant leakage.
3. **Agent Frameworks / Orchestration** — the orchestration logic, planning
   loops, inter-agent messaging: how one agent's output becomes another's input.
4. **Deployment & Infrastructure** — runtime, network exposure, secrets/identity
   the agents run under, sandboxing of tool execution.
5. **Evaluation & Observability** — monitoring, logging, eval harnesses: can an
   agent's misbehavior actually be detected, and can logs be trusted/tampered?
6. **Security & Compliance** — the controls layered on top (authz, guardrails,
   policy enforcement) and whether they apply consistently across agents.
7. **Agent Ecosystem** — the multi-agent system as a whole: agent-to-agent trust,
   delegation chains, third-party/external agents, and emergent behavior from
   their interaction.

# Steps

1. **Map the agents and their layer placement.** Identify every agent/sub-agent,
   what it's built on (layer 1), what data/memory it touches (layer 2), how it's
   orchestrated and what it messages to/from (layer 3), where it runs (layer 4).
2. **Per layer, enumerate trusted vs. untrusted.** What enters and leaves each
   layer, and is it treated as trusted instruction or untrusted content?
3. **Focus on cross-layer and cross-agent breaks.** The highest-value threats are
   boundary crossings: a compromised or manipulated sub-agent's output flowing
   untrusted into an orchestrator's decision layer; a tool/MCP result silently
   treated as trusted instruction; an eval/observability gap that lets layer-3
   misbehavior go undetected. Walk every agent-to-agent and agent-to-tool edge
   explicitly — don't stop at per-layer analysis alone.
4. **Rank** with `threat-modeling:risk-rank` (likelihood × impact).
5. **Map mitigations** per threat, noting existing controls vs. gaps — for
   tool/MCP-boundary specifics, hand off to `agentic-ai-security:mcp-security-review`
   and `agentic-ai-security:agent-security-review`.

# Output

A layer-by-layer threat table (layer · element/edge · threat · risk · mitigation ·
status) plus a short "top cross-layer/cross-agent risks" summary. Hand to
`security-reporting` if a formal document is needed.

# Notes

The 7-layer breakdown above is this skill's working model of MAESTRO based on
CSA's publicly described framework — cite CSA's published MAESTRO documentation
for the canonical, current layer names/count rather than treating the numbering
here as a fixed standard; the framework has evolved since its initial publication.
What matters operationally is the discipline: decompose the agent stack into
layers, then hunt specifically for trust breaks *between* layers and *between*
agents, which per-DFD STRIDE passes systematically under-weight. Use standalone
for a pure agentic-architecture review, or alongside `llm-security:ai-threat-model`
when the system is also GenAI/LLM-specific.

Attribution

jassicsjassics
View sourceSee grades on GitHubMore from jassics →
SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Your tool, in front of Claude Code builders.

3 founder slots · $299/mo · GSC-verified traffic · sponsors can never buy grades.

See placements

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

696481 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes
View all in ai-agents →