Documentation

Everything you need to run ThreatSpec inside a Spec Kit project: how the model is built, what threat-model.yaml contains, how the lifecycle hooks fit together, and every configuration key.

For installation and a command overview, see the project home.

  • Methodology โ€” How ThreatSpec applies Shostack's four questions, STRIDE plus AI/ML profiles, and evidence-based verification to a Spec Kit feature.
  • threat-model.yaml reference โ€” Field-by-field reference for threat-model.yaml: the OTM-compatible schema, identifiers, threats, mitigations, requirements, verification, decisions, and reference rules.
  • Workflow integration โ€” How ThreatSpec's three commands and seven lifecycle hooks fit into the Spec Kit workflow, the companion preset and workflow, and CI integration.
  • Configuration reference โ€” Every threatspec-config.yml key, its default, what reads it, the four-layer precedence order, and the two known documentation inconsistencies.
  • Design: positioning, bets, roadmap โ€” ThreatSpec's positioning against other Spec Kit security extensions, its core design bets, decisions taken, the roadmap, and the landscape of related tools.
  • Threat model of ThreatSpec itself โ€” ThreatSpec's own threat model: what it protects, ten threats it accepts running as an agent with repository read/write access, and their mitigation status.
  • Publishing checklist โ€” Checklist mapped to Spec Kit's extension publishing guide: manifest requirements, the release process, and how to submit to the community catalog.