threat-modeling
4 resources across 2 kinds
Frameworks & agents
- Open ↗AppSec (florianbuetow)passive
MIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.
- Open ↗Phoenix Security Skillscloud cost
Six Claude Code plugins (27 skills, MIT) for pre-merge security review, STRIDE threat modelling, opengrep/semgrep rule generation, tiered CTI search across 595 curated domains, and security-first PRD writing.
References
- Open ↗
Slide deck from the SANS AI Cybersecurity Summit 2025 by Rob van der Veer of the Software Improvement Group, framing six ways AI security differs from standard security plus the AI-specific threats and controls it names.
- Open ↗
Preliminary-draft NIST Community Profile giving all 106 CSF 2.0 Subcategories a proposed priority under three focus areas — securing AI components, AI-enabled defense, thwarting AI attacks — and AI considerations where any exist.