/speckit-threatspec-model
Builds or incrementally updates threat-model.yaml from spec.md (assets, actors, trust zones, threats, mitigations, SR-###) and, with --from-plan, from plan.md (components, data flows).
A Spec Kit extension
Threat Modeling & Security Traceability for Spec Kit
ThreatSpec is a Spec Kit extension that makes threat modeling and security traceability a first-class part of Spec-Driven Development.
It generates a machine-readable, Open Threat Model-compatible threat model from your Spec Kit artifacts, derives testable security requirements (SR-###) from it, feeds them into /speckit-plan and /speckit-tasks, checks the whole chain for gaps deterministically, and verifies after implementation that every threat has been mitigated, implemented, and tested.
Every ThreatSpec hook is optional by default โ nothing in the core workflow changes unless you opt in.
# From a release archive (the CLI asks you to confirm the untrusted URL)
specify extension add threatspec --from https://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/v0.2.0.zip
# Or register this repository's catalog once, then install by name
specify extension catalog add https://raw.githubusercontent.com/hupe1980/spec-kit-threatspec/main/catalog.json --name threatspec --install-allowed
specify extension add threatspec
Every threat resolves to a Security Requirement, and every requirement resolves to a task and a piece of evidence.
Asset โโถ Threat โโถ Mitigation โโถ Security Requirement (SR-###)
โโโโถ Task (T###) tasks.md
โโโโถ Verification test | review | scan | evidence
โโโโถ Convergence every link resolved, every SR verified/speckit-specify spec.md/speckit-threatspec-model threat-model.yaml + threat-model.md + SR-### block in spec.md/speckit-plan plan.md (sees the security requirements)/speckit-threatspec-model --from-plan components, data flows, trust zones/speckit-tasks tasks.md (security tasks tagged [SR-###])/speckit-threatspec-check gap report: threats โ mitigations โ SR-### โ tasks โ verification/speckit-implement code + tests/speckit-threatspec-converge evidence-based verification, convergence report, remediation tasks/speckit-converge core convergence completes the appended tasks/speckit-threatspec-modelBuilds or incrementally updates threat-model.yaml from spec.md (assets, actors, trust zones, threats, mitigations, SR-###) and, with --from-plan, from plan.md (components, data flows).
/speckit-threatspec-checkDeterministic checks C1โC12 and coverage tables from the engine, plus ten semantic passes; report in the /speckit-analyze shape; --format sarif for GitHub code scanning.
/speckit-threatspec-convergeCollects evidence per SR-###, has the agent judge only from that evidence, records append-only verification history, reports convergence, appends remediation tasks.
Techniques, applicability surfaces, and edition-pinned framework mappings, layered on top of STRIDE.
strideSTRIDE per element (default)
llmOWASP Top 10 for LLM Applications 2026, MITRE ATLAS
agentOWASP Top 10 for Agentic Applications 2026, MAESTRO layers
Install ThreatSpec as a Spec Kit extension and generate your first threat model from a spec alone.