Home / Security tooling

agent-threat-model

Threat modeling for AI agents: describe the system in YAML, get a STRIDE and OWASP Agentic threat model.

Python · MIT · latest v0.1.0

What it is

Threat modeling for AI agents and LLM applications, for security architects and the engineers who own an agent: describe the system in YAML and get a STRIDE and OWASP Agentic threat model with a ranked threat register, a Mermaid diagram, a control checklist, a residual risk score and SARIF for GitHub code scanning. Deterministic, offline, no model in the loop, so the same input always gives the same report and it runs in CI.

Install

pipx install git+https://github.com/basitalisandhu/agent-threat-model
atm init system.yaml                 # writes the support-bot example
atm analyse system.yaml

From the README; see the full README for every option.

Releases

Topics: agent-security, agentic-ai, ai-agents, ai-security, cli, devsecops, github-actions, hacktoberfest, llm-security, mitre-atlas, owasp, prompt-injection, python, sarif, security-automation, security-tools, stride, threat-model, threat-modeling