Threat Modeling MCP Server is an MCP server that guides an AI coding agent through structured security threat modeling and code validation. It analyzes business context, architecture, assets, trust boundaries, and threat actors, then produces Markdown or JSON reports using a phased STRIDE-based process. The catalogue skills operate this workflow through compatible agent clients.
These files are awslabs/threat-modeling-mcp-server's own configuration. They tell Kiro how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.
.kiro/skills/phase-1-business-context/SKILL.md A 40 tok .kiro/skills/phase-2-architecture/SKILL.md A 32 tok .kiro/skills/phase-3-threat-actors/SKILL.md A 34 tok .kiro/skills/phase-4-trust-boundaries/SKILL.md A 32 tok .kiro/skills/phase-5-asset-flows/SKILL.md A 36 tok .kiro/skills/phase-6-threat-identification/SKILL.md A 41 tok .kiro/skills/phase-7-5-code-validation/SKILL.md A 32 tok .kiro/skills/phase-7-mitigation-planning/SKILL.md A 36 tok .kiro/skills/phase-8-residual-risk/SKILL.md A 30 tok .kiro/skills/phase-9-output-generation/SKILL.md A 37 tok