Documentation
AttackTree adds attack trees to Spec Kit’s Spec-Driven Development workflow. New here? Read What is AttackTree?, then follow the quickstart. The rest is organised by what you need: concepts explain how and why it works, guides solve a task, and the reference lists every command, field, and setting.
Get started
What is AttackTree?
AttackTree is an open-source Spec Kit extension that builds attack trees from your spec, simulates which security controls cut the attack paths, and verifies each control with evidence.
Installation
Install the AttackTree extension into a Spec Kit project from a release archive, a catalog, or a local checkout, plus the optional preset and workflow.
Quickstart
Run AttackTree on the shipped example in five minutes, then build your first attack tree for your own feature with a coding agent.
Concepts
Attack trees explained
What an attack tree is, where the method comes from, how AND and OR nodes and leaf values work, and why attack trees rank threats better than a list.
Risk model
How AttackTree computes likelihood, feasibility, control effects, actor occurrence, and residual risk, with a worked example and the full risk matrix.
Simulation
What the AttackTree simulation reports: most likely and cheapest paths, choke points, Achilles heels, single points of failure, what-if and defence in depth, the roadmap, and Monte Carlo.
Verification and convergence
How AttackTree verifies security controls with evidence: verdicts, evidence levels, micro attack simulations and bypass rates, status roll-up, and the definition of converged.
Guides
Workflow
Use AttackTree across the Spec Kit lifecycle: two modelling passes, simulation before tasks, checks before implementation, convergence after, plus hooks, the companion preset, and the workflow.
Continuous integration
Run AttackTree's checks and simulation in CI without an agent, upload findings to GitHub code scanning as SARIF, and gate pull requests on residual risk.
Open Threat Model interop
Seed AttackTree goals and assets from an Open Threat Model (OTM) file exported by other threat modelling tools, link goals back to threats, and track drift.
Agentic and LLM systems
Model attack trees for LLM applications and AI agents: the five attack-surface zones, prompt injection and tool-misuse paths, probabilistic guardrails, and bypass-rate measurement.
Troubleshooting
Fixes for common AttackTree problems: missing Python runtime, feature detection, YAML parse errors, rejected merges, infeasible or unknown goals, truncation, and drift.
Reference
Commands
Reference for the four AttackTree agent commands: model, simulate, check, and converge. Arguments, what each command reads and writes, and when to run it.
Engine CLI
Reference for attacktree.sh, the deterministic AttackTree engine: global options, feature resolution, every subcommand with its flags, and exit codes.
attack-tree.yaml format
Complete reference for attack-tree.yaml: actors, assets, goals, AND/OR nodes, attack vectors, controls, CR requirements, verification, decisions, reference rules, baselines, and drift hashes.
Checks
Reference for AttackTree's sixteen deterministic checks A1 to A16 with severities and fixes, and the ten semantic passes the check command adds.
Configuration
Every AttackTree configuration key with its default and effect: profiles, enforcement, risk scenario and blocking levels, simulation, risk acceptance, model rendering and OTM, and verification.
Profiles
AttackTree profiles supply the scales the engine computes with and libraries of actor archetypes, attack vectors, and controls: the default and agentic profiles, and how to write your own.
Glossary
Definitions of the terms used by AttackTree: attack tree, goal, node, leaf, AND and OR gates, path, choke point, control, bypass rate, residual risk, scenario, and more.
Project
Design and roadmap
Why AttackTree is built the way it is: positioning next to threat lists and attacktree.online, design decisions, what is out of scope, and the roadmap.
Security
AttackTree's own threat model: prompt injection through artifacts, overwriting human content, command execution, manipulated simulations, and how each is controlled.
Releasing
Maintainer checklist for releasing AttackTree: version bumps, the release workflow, install verification, and submission to the Spec Kit community catalog.