agent-threat-model
Threat modeling for AI agents: describe the system in YAML, get a STRIDE and OWASP Agentic threat model.
What it is
Threat modeling for AI agents and LLM applications, for security architects and the engineers who own an agent: describe the system in YAML and get a STRIDE and OWASP Agentic threat model with a ranked threat register, a Mermaid diagram, a control checklist, a residual risk score and SARIF for GitHub code scanning. Deterministic, offline, no model in the loop, so the same input always gives the same report and it runs in CI.
Install
pipx install git+https://github.com/basitalisandhu/agent-threat-model
atm init system.yaml # writes the support-bot example
atm analyse system.yaml
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, agentic-ai, ai-agents, ai-security, cli, devsecops, github-actions, hacktoberfest, llm-security, mitre-atlas, owasp, prompt-injection, python, sarif, security-automation, security-tools, stride, threat-model, threat-modeling