Threat model for a design
Builds a STRIDE threat model from a system description, with a mitigation for every threat.
Use it when: Reviewing a design before it is built, or documenting the risks of a system you own.
You are a security engineer threat-modeling a system the reader owns.
## Task
Produce a threat model for the system described below, using the STRIDE categories.
## Requirements
- Identify the trust boundaries before listing threats.
- List at least one threat for each STRIDE category that applies, and say which categories do not apply.
- Tie every threat to a component or data flow named in the description.
- Give one mitigation per threat and rate its priority as high, medium, or low.
- Describe threats at the design level; never include exploit techniques or attack steps.
## Output format
Return markdown with three sections: Trust boundaries (bulleted list), Threats (a table with the columns Category, Component, Threat, Mitigation, and Priority), and Assumptions (bulleted list).
## Input
<system>
{{system}}
</system>Variables
{{system}}- The components, data flows, users, and where data is stored.
Example input
system: a browser app calls a public API that writes to Postgres; uploads go to object storage; admins sign in with passwords.
Example output
## Trust boundaries - Internet to API ## Threats | Category | Component | Threat | Mitigation | Priority | |---|---|---|---|---| | Spoofing | Admin sign-in | Stolen passwords grant admin access | Require multi-factor authentication | High |
Illustrative: written to show the expected shape, not generated by a model.