davidmatousek/tachi

Threat modeling and AI-reasoning vulnerability detection harness for Claude Code — STRIDE + AI + MAESTRO

This repository also configures its own agents. See what tachi tells them →

90Stars on the repository
106Mods indexed here, across every type
25d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

agent-autonomy

01

davidmatousek/tachi

Cursor rule Cursor needs its repo

AI agent autonomy threat agent — detects excessive autonomy, goal misalignment, unconstrained action scope, missing human-in-the-loop checkpoints, cascading multi-agent failures, and autonomous resource consumption against Processes.

not rated 90 25d ago A 37 tokens original Apache-2.0

data-poisoning

02

davidmatousek/tachi

Cursor rule Cursor needs its repo

AI/LLM data poisoning threat agent — detects training data manipulation, RAG index poisoning, knowledge base corruption, fine-tuning supply chain attacks, and context window contamination against Data Stores and Data Flows.

not rated 90 25d ago A 41 tokens original Apache-2.0

denial-of-service

03

davidmatousek/tachi

Cursor rule Cursor needs its repo

STRIDE denial of service threat agent — detects availability degradation threats including resource exhaustion, algorithmic complexity attacks, connection pool exhaustion, cascading dependency failures, and application-layer flooding against Processes, Data Stores, and Data Flows.

not rated 90 25d ago A 43 tokens original Apache-2.0

info-disclosure

04

davidmatousek/tachi

Cursor rule Cursor needs its repo

STRIDE information disclosure threat agent — detects confidentiality violations including error message exposure, excessive data in responses, data at rest and in transit exposure, side-channel leakage, and debug endpoint exposure against Processes, Data Stores, and Data Flows.

not rated 90 25d ago A 46 tokens original Apache-2.0

model-theft

05

davidmatousek/tachi

Cursor rule Cursor needs its repo

AI/LLM model theft threat agent — detects model weight exfiltration, API-based model extraction, artifact exposure, side-channel reconstruction, fine-tuned model theft, and supply chain compromise against Data Stores and Processes.

not rated 90 25d ago A 43 tokens original Apache-2.0

orchestrator

06

davidmatousek/tachi

Cursor rule Cursor needs its repo

Central coordinator for tachi OWASP threat modeling — parses architecture input, coordinates STRIDE and AI threat analysis, produces threats.md, SARIF output, and narrative threat report.

not rated 90 25d ago B 25,879 tokens original Apache-2.0

davidmatousek/tachi

Cursor rule Cursor needs its repo

STRIDE elevation of privilege threat agent — detects unauthorized privilege gain including broken access control, insecure direct object references, role escalation, multi-tenancy boundary violations, and lateral movement against Processes.

not rated 90 25d ago A 36 tokens original Apache-2.0

prompt-injection

08

davidmatousek/tachi

Cursor rule Cursor needs its repo

AI/LLM prompt injection threat agent — detects direct and indirect prompt injection, jailbreak, system prompt extraction, and cross-plugin injection threats against LLM-integrated Processes.

not rated 90 25d ago B 33 tokens original Apache-2.0

repudiation

09

davidmatousek/tachi

Cursor rule Cursor needs its repo

STRIDE repudiation threat agent — detects accountability failures including missing audit trails, insufficient log detail, log tampering vulnerabilities, timestamp manipulation, and deniable actions against External Entities and Processes.

not rated 90 25d ago A 36 tokens original Apache-2.0

spoofing

10

davidmatousek/tachi

Cursor rule Cursor needs its repo

STRIDE spoofing threat agent — detects identity impersonation, authentication bypass, credential theft, session hijacking, and federated identity attacks against External Entities and Processes.

not rated 90 25d ago A 32 tokens original Apache-2.0

tampering

11

davidmatousek/tachi

Cursor rule Cursor needs its repo

STRIDE tampering threat agent — detects unauthorized data modification threats including input injection, data flow manipulation, persistent data corruption, code and configuration tampering, and supply chain attacks against Processes, Data Stores, and Data Flows.

not rated 90 25d ago A 44 tokens original Apache-2.0

threat-infographic

12

davidmatousek/tachi

Cursor rule Cursor needs its repo

Threat infographic generator — transforms structured threat model output into visual infographic specifications and images via Gemini API. Supports multiple templates: Baseball Card (risk summary dashboard) and System Architecture (annotated architecture diagram with attack surface badges).

not rated 90 25d ago A 43 tokens original Apache-2.0

threat-report

13

davidmatousek/tachi

Cursor rule Cursor needs its repo

Threat report generator — produces narrative threat analysis with executive summary, Mermaid attack trees for Critical and High findings, prioritized remediation roadmap with effort estimates, cross-cutting theme detection, and complete finding traceability.

not rated 90 25d ago B 39 tokens original Apache-2.0

tool-abuse

14

davidmatousek/tachi

Cursor rule Cursor needs its repo

AI tool-use abuse threat agent — detects unauthorized tool invocation, capability escalation through tool composition, parameter injection, tool chain manipulation, and tool poisoning attacks against Processes with MCP servers, plugins, or function calling.

not rated 90 25d ago A 40 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: