Installation
Install the AttackTree extension into a Spec Kit project from a release archive, a catalog, or a local checkout, plus the optional preset and workflow.
# Requirements
- Spec Kit 1.0 or later, with a project initialised by
specify init. - Python 3.11 or later with PyYAML. If PyYAML is missing, the wrapper scripts fall back to uv, which fetches PyYAML and jsonschema on the fly.
- Any coding agent that Spec Kit supports: Claude Code, GitHub Copilot, Cursor, Gemini CLI, opencode, Codex, and others.
# Install the extension
Pick one of three sources. All three install the same files into .specify/extensions/attacktree/ and register the four commands with your agent.
From a release archive. The CLI asks you to confirm the URL because it is not in a catalog you trust yet.
specify extension add attacktree --from https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zipFrom this project’s catalog. Register the catalog once, then install and update by name.
specify extension catalog add https://raw.githubusercontent.com/hupe1980/spec-kit-attacktree/main/catalog.json \
--name attacktree --install-allowed
specify extension add attacktreeFrom a local checkout, for development:
git clone https://github.com/hupe1980/spec-kit-attacktree.git
specify extension add --dev ./spec-kit-attacktree# Verify
specify extension listThe list shows AttackTree — Attack Tree Modeling & Control Simulation with 4 commands and 7 hooks. If your agent was already running, restart it so it picks up the new commands. Depending on the agent, they appear as /speckit-attacktree-model (Claude Code, Copilot, Cursor, and most others) or /speckit.attacktree.model (opencode, Gemini, Qwen).
The install also scaffolds .specify/extensions/attacktree/attacktree-config.yml. The defaults work; see Configuration before you change them.
# Optional companions
The repository ships two optional add-ons. They are not part of the extension archive, so install them from a checkout.
| Add-on | What it does | Install |
|---|---|---|
Preset attacktree-sdd | Appends a short section to the core tasks, analyze, converge, and checklist commands so they tag, inventory, and check CR-### requirements natively | specify preset add --dev ./spec-kit-attacktree/preset/attacktree-sdd |
Workflow attacktree-sdd | Runs the whole cycle from specify to converge with review gates after the tree, the simulation, and the gap check | specify workflow add --dev ./spec-kit-attacktree/workflow/attacktree-sdd |
# Hooks
All seven hooks are optional: after /speckit-specify, /speckit-plan, /speckit-tasks, and the other core commands, the agent asks whether to run the matching AttackTree command. Nothing runs without your confirmation. To make a hook automatic, set optional: false for it in .specify/extensions.yml. The workflow guide lists every hook.
# Update and remove
specify extension update attacktree
specify extension remove attacktree # add --keep-config to keep your configurationRemoving the extension leaves your feature artifacts (attack-tree.yaml, the CR-### block in spec.md) untouched.