Microsoft TM7 威胁模型
原名:tm7-threat-model
生成可在 Microsoft Threat Modeling Tool 中打开的 TM7 文件并整理 STRIDE 风险。
中文 Skills 技能说明
适合系统设计或上线前建立数据流、信任边界与威胁清单。内容仅用于已授权的防御性建模,架构信息需受控保存;生成文件后必须在工具中打开验证并由安全负责人复核。
上游能力依据
上游原始适用说明:Creates valid Microsoft Threat Modeling Tool (.tm7) files compatible with the Microsoft Threat Modeling Tool v7.3+. Use this skill whenever asked to create, generate, or modify a .tm7 threat model file, or when performing STRIDE threat modeling that should output a .tm7 file that opens cleanly in the Microsoft Threat Modeling Tool.
上游 SKILL.md 主要章节(保留原文标题):
- Workflow
- CRITICAL: Serialization format
- Required namespace prefixes
- File structure (correct order)
- Stencil elements
- Stencil shape types
- Common TypeId values (SDL TM knowledge base)
- Data flow lines
- Property attribute types
- Threat instances
使用边界
先确认授权范围、资产边界和证据来源。输出用于防御性检查与人工决策,不自动执行攻击、绕过或破坏性操作。
作者、翻译与许可证
- 原作者
- GitHub, Inc. 与 awesome-copilot contributors
- 中文翻译
- CEOFans翻译
- 许可证
- MIT
- 上游来源
- https://github.com/github/awesome-copilot/tree/83561bd7d8a46fcda0581aedabdf8eac7cb196b6/skills/tm7-threat-model
适用范围
平台:linux、macos、windows;标签:安全与合规、Microsoft TM7 威胁模型
安全提示
基础静态扫描不等于绝对安全。技能可能调用命令、浏览器、云服务或本地文件,请在最小权限环境中使用,高风险操作必须人工确认。
如发现侵权、许可证或安全问题,可在本页前台提交投诉,管理员复核后可立即下架。