Documentation
Everything you need to run ThreatSpec inside a Spec Kit project: how the model is built, what threat-model.yaml contains, how the lifecycle hooks fit together, and every configuration key.
For installation and a command overview, see the project home.
- Methodology โ How ThreatSpec applies Shostack's four questions, STRIDE plus AI/ML profiles, and evidence-based verification to a Spec Kit feature.
- threat-model.yaml reference โ Field-by-field reference for threat-model.yaml: the OTM-compatible schema, identifiers, threats, mitigations, requirements, verification, decisions, and reference rules.
- Workflow integration โ How ThreatSpec's three commands and seven lifecycle hooks fit into the Spec Kit workflow, the companion preset and workflow, and CI integration.
- Configuration reference โ Every threatspec-config.yml key, its default, what reads it, the four-layer precedence order, and the two known documentation inconsistencies.
- Design: positioning, bets, roadmap โ ThreatSpec's positioning against other Spec Kit security extensions, its core design bets, decisions taken, the roadmap, and the landscape of related tools.
- Threat model of ThreatSpec itself โ ThreatSpec's own threat model: what it protects, ten threats it accepts running as an agent with repository read/write access, and their mitigation status.
- Publishing checklist โ Checklist mapped to Spec Kit's extension publishing guide: manifest requirements, the release process, and how to submit to the community catalog.