A Spec Kit extension

๐Ÿ›ก๏ธ ThreatSpec

Threat Modeling & Security Traceability for Spec Kit

ThreatSpec is a Spec Kit extension that makes threat modeling and security traceability a first-class part of Spec-Driven Development.

It generates a machine-readable, Open Threat Model-compatible threat model from your Spec Kit artifacts, derives testable security requirements (SR-###) from it, feeds them into /speckit-plan and /speckit-tasks, checks the whole chain for gaps deterministically, and verifies after implementation that every threat has been mitigated, implemented, and tested.

Every ThreatSpec hook is optional by default โ€” nothing in the core workflow changes unless you opt in.

# From a release archive (the CLI asks you to confirm the untrusted URL)
specify extension add threatspec --from https://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/v0.2.0.zip

# Or register this repository's catalog once, then install by name
specify extension catalog add https://raw.githubusercontent.com/hupe1980/spec-kit-threatspec/main/catalog.json --name threatspec --install-allowed
specify extension add threatspec

The lifecycle loop

Every threat resolves to a Security Requirement, and every requirement resolves to a task and a piece of evidence.

Asset โ”€โ–ถ Threat โ”€โ–ถ Mitigation โ”€โ–ถ Security Requirement (SR-###)
                                      โ”œโ”€โ”€โ–ถ Task (T###)      tasks.md
                                      โ”œโ”€โ”€โ–ถ Verification     test | review | scan | evidence
                                      โ””โ”€โ”€โ–ถ Convergence      every link resolved, every SR verified
  1. /speckit-specify spec.md
  2. /speckit-threatspec-model threat-model.yaml + threat-model.md + SR-### block in spec.md
  3. /speckit-plan plan.md (sees the security requirements)
  4. /speckit-threatspec-model --from-plan components, data flows, trust zones
  5. /speckit-tasks tasks.md (security tasks tagged [SR-###])
  6. /speckit-threatspec-check gap report: threats โ†’ mitigations โ†’ SR-### โ†’ tasks โ†’ verification
  7. /speckit-implement code + tests
  8. /speckit-threatspec-converge evidence-based verification, convergence report, remediation tasks
  9. /speckit-converge core convergence completes the appended tasks

Commands

/speckit-threatspec-model

Builds or incrementally updates threat-model.yaml from spec.md (assets, actors, trust zones, threats, mitigations, SR-###) and, with --from-plan, from plan.md (components, data flows).

Writes: threat-model.yaml, threat-model.md, the marked block in spec.md

/speckit-threatspec-check

Deterministic checks C1โ€“C12 and coverage tables from the engine, plus ten semantic passes; report in the /speckit-analyze shape; --format sarif for GitHub code scanning.

Writes: optional security/check-report.md

/speckit-threatspec-converge

Collects evidence per SR-###, has the agent judge only from that evidence, records append-only verification history, reports convergence, appends remediation tasks.

Writes: threat-model.yaml, security/convergence-report.{md,json}, appended phase in tasks.md

Profiles

Techniques, applicability surfaces, and edition-pinned framework mappings, layered on top of STRIDE.

stride

STRIDE per element (default)

llm

OWASP Top 10 for LLM Applications 2026, MITRE ATLAS

agent

OWASP Top 10 for Agentic Applications 2026, MAESTRO layers

Design principles

  • Reusable
  • Agent-agnostic
  • Traceable
  • Deterministic where possible
  • Non-intrusive
  • Incremental
  • Evidence over claims
  • Honest about uncertainty
  • Interoperable (OTM, SARIF)
  • Secure by construction

Ready to close the loop?

Install ThreatSpec as a Spec Kit extension and generate your first threat model from a spec alone.