[Extension]: Add OWASP LLM Threat Model v2.1.2 (version update)
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 70/100
Rechercherichtung
Finden Sie den vorhandenen threatmodel-Katalogeintrag, der in Issue #2369 hinzugefügt wurde, und vergleichen Sie ihn mit dem in diesem Issue vorgeschlagenen Eintrag. Aktualisieren Sie die Katalogmetadaten so, dass sie Version 2.1.2 und die bereitgestellten Release-Details widerspiegeln; der Quellcode der Erweiterung ist ausdrücklich nicht Gegenstand dieses Issues. Erledigt, wenn der Katalog auf das v2.1.2-Archiv verweist und seine Metadaten dem Vorschlag entsprechen.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Extension ID
threatmodel
Extension Name
OWASP LLM Threat Model
Version
2.1.2
Description
OWASP Top 10 for LLM Applications 2026 threat analysis on skill files
Author
NaviaSamal
Repository URL
https://github.com/NaviaSamal/spec-kit-threatmodel
Download URL
https://github.com/NaviaSamal/spec-kit-threatmodel/archive/refs/tags/v2.1.2.zip
License
MIT
Homepage (optional)
https://github.com/NaviaSamal/spec-kit-threatmodel
Documentation URL (optional)
https://github.com/NaviaSamal/spec-kit-threatmodel/blob/main/README.md
Changelog URL (optional)
https://github.com/NaviaSamal/spec-kit-threatmodel/blob/main/CHANGELOG.md
Required Spec Kit Version
=0.6.0
Required Tools (optional)
None — the extension bundles its own check-prerequisites.sh; no external tools required.
Number of Commands
1
Number of Hooks (optional)
1
Tags
security, owasp, threat-model, llm, analysis
Key Features
- OWASP Top 10 for LLM Applications 2026 methodology applied to agent artifacts (skills, prompts, templates, hooks, memory files).
- Single command
/speckit.threatmodel.analyze— read-only, producesFEATURE_DIR/threat-model-{YYYY-MM-DD}-{NNN}.md. - Categorized findings LLM01–LLM10 with a Likelihood × Impact risk matrix and mitigations.
- Flags blocking (Critical) threats that should be resolved before deployment.
Testing Checklist
- Extension installs successfully via download URL
- All commands execute without errors
- Documentation is complete and accurate
- No security vulnerabilities identified
- Tested on at least one real project
Submission Requirements
- Valid
extension.ymlmanifest included - README.md with installation and usage instructions
- LICENSE file included
- GitHub release created with version tag
- All command files exist and are properly formatted
- Extension ID follows naming conventions (lowercase-with-hyphens)
Testing Details
**Version update:** bumps the existing `threatmodel` catalog entry from v1.0.0 (added in #2369) to v2.1.2.
**Verified release baseline:**
- Spec Kit (`specify-cli`) 1.0.13.dev0
- Extension `threatmodel` v2.1.2 (release published 2026-09-10)
- Agents: GitHub Copilot in VS Code, and Claude Code
- OS/Shell: macOS (Darwin 25.6.0) / zsh
**Installation method:** Dev mode per the Extension Development Guide. In this environment the CLI's Python URL download fails with SSL CERTIFICATE_VERIFY_FAILED (corporate proxy), so the release archive was fetched with `curl`, unzipped, and installed with `--dev`:
curl -L -o /tmp/tm.zip 'https://github.com/NaviaSamal/spec-kit-threatmodel/archive/refs/tags/v2.1.2.zip'
unzip -q /tmp/tm.zip -d /tmp/tm
specify extension add --dev /tmp/tm/spec-kit-threatmodel-2.1.2
**Install — successful (both agent integrations):**
- Copilot project (`specify init helloworld-copilot --integration copilot --non-interactive`) — skill auto-registered into `.github/skills/speckit-threatmodel-analyze/`.
- Claude project (`specify init helloworld-springboot --integration claude --non-interactive`) — skill auto-registered into `.claude/skills/speckit-threatmodel-analyze/`.
**Extension list verification — successful:**
Installed Extensions:
✓ OWASP LLM Threat Model (v2.1.2)
threatmodel
OWASP Top 10 for LLM Applications 2026 threat analysis on agent artifacts
Commands: 1 | Hooks: 1 | Priority: 10 | Status: Enabled
**Analysis against a real spec-kit skill — successful:** ran `/speckit-threatmodel-analyze speckit-specify` in Copilot Chat and in Claude Code. Pass in both — the threat-model-{YYYY-MM-DD}-{NNN}.md artifact was generated under the feature directory; 5 threats, 3 blocking (Critical). Template fully rendered (no leftover {{handlebars}}); read-only confirmed (only the new artifact appeared).
**Detection discrimination — true-positive / true-negative — successful:** two skill files were created fresh for this test, each with a known-expected outcome.
1. True positive — `vuln-deploy-helper`, authored with deliberate OWASP LLM anti-patterns (raw $ARGUMENTS→shell, `curl … | bash`, hardcoded AWS keys + ghp_ token, unbounded retry, model output→/etc/…→bash, no autonomy gate). Result: 10 threats, all Critical/blocking across LLM01/02/03/04/05/06/08/10.
2. True negative — `safe-status-reporter`, authored to be safe ($ARGUMENTS validated against an allowlist and used only as a scope selector; explicit read-only / no-shell / no-fetch / no-secrets / no-autonomy). Result: 0 threats, 0 blocking (LLM05/06/09/10 N/A, LLM08 Informational).
Flagging the dangerous skill while clearing the safe one confirms the extension discriminates rather than always firing.
**Support matrix:**
| Target | Result | Evidence |
|---|---|---|
| GitHub Copilot in VS Code | PASS | skill auto-registered into `.github/skills/`; analysis run in Copilot Chat produced the artifact |
| Claude Code | PASS | skill auto-registered into `.claude/skills/`; analysis run produced the artifact |
| Install from release tag (v2.1.2) | PASS | `specify extension list` shows OWASP LLM Threat Model (v2.1.2), 1 cmd + 1 hook, Enabled |
| Detection — true positive (vuln skill) | PASS | 10 threats, all Critical/blocking |
| Detection — true negative (safe skill) | PASS | 0 threats, 0 blocking |
Example Usage
`
# Install extension (from release tag)
specify extension add threatmodel --from https://github.com/NaviaSamal/spec-kit-threatmodel/archive/refs/tags/v2.1.2.zip
# Run OWASP LLM Top 10 (2026) analysis against a skill
/speckit.threatmodel.analyze <skill-name>
# → writes threat-model-{YYYY-MM-DD}-{NNN}.md under the feature directory
`
Proposed Catalog Entry
{
"threatmodel": {
"name": "OWASP LLM Threat Model",
"id": "threatmodel",
"description": "OWASP Top 10 for LLM Applications 2026 threat analysis on agent artifacts",
"author": "NaviaSamal",
"version": "2.1.2",
"download_url": "https://github.com/NaviaSamal/spec-kit-threatmodel/archive/refs/tags/v2.1.2.zip",
"repository": "https://github.com/NaviaSamal/spec-kit-threatmodel",
"homepage": "https://github.com/NaviaSamal/spec-kit-threatmodel",
"documentation": "https://github.com/NaviaSamal/spec-kit-threatmodel/blob/main/README.md",
"changelog": "https://github.com/NaviaSamal/spec-kit-threatmodel/blob/main/CHANGELOG.md",
"license": "MIT",
"category": "code",
"effect": "read-only",
"requires": {
"speckit_version": ">=0.6.0"
},
"provides": {
"commands": 1,
"hooks": 1
},
"tags": ["security", "owasp", "threat-model", "llm", "analysis"],
"verified": false,
"downloads": 0,
"stars": 0,
"created_at": "2026-04-25T00:00:00Z",
"updated_at": "2026-09-27T00:00:00Z"
}
}
Additional Context
This is a **version update**, not a new submission — it bumps the existing `threatmodel` catalog entry from v1.0.0 (added in #2369) to the latest release v2.1.2.
**What changed since v1.0.0 (per the extension CHANGELOG / release notes):**
- v2.0.0 (breaking): migrated the methodology from OWASP LLM Top 10 2025 → 2026; category IDs renumbered/renamed (Excessive Agency→LLM03, Supply Chain→LLM04, Data & Model Poisoning→LLM05, Unbounded Consumption→LLM06, Misinformation→LLM07, Improper Output Handling→LLM10); old LLM07 System Prompt Leakage folded into severity-graded LLM08 Hidden Context Exposure; added LLM06/LLM07 detection guidance. (This is why the description changes 2025 → 2026.)
- v2.1.0: applicability gating — LLM05/06/09/10 report N/A when structurally absent (three-state disposition).
- v2.1.1: LLM01 $ARGUMENTS usage-pattern grading (instruction-interpolation → High, API/tool parameter → Medium, scope-selector-only → No threat); analyzer no longer trusts a skill's own "trusted"/"attacker-controlled" claims.
- v2.1.2 (latest): LLM08 Informational disposition (kills false positives on benign workflow skills); LLM04 scope correction (stops flagging the CLI-managed `.specify/extensions.yml`); LLM03 impact calibration (High when an auto-executing hook combines with a confirmed LLM01 finding).
Net effect: reports now use the OWASP LLM Top 10 2026 categories, produce fewer false positives on benign skills, and grade real risks more precisely — confirmed by the true-positive/true-negative test above.
**AI-assistance disclosure (voluntary):** catalog-submission issue forms are exempt from the disclosure requirement, but disclosed here for transparency (as accepted update issue #4763 also did): this submission was prepared with Claude Code (model: Claude Opus 4.8, human-supervised) — used to research spec-kit's submission process, verify the release/manifest values, run the end-to-end testing, and draft this issue. The maintainer reviewed the content before filing. The extension's own source is authored and released separately by NaviaSamal and is not modified here.
- Vorherrschende Sprache
- Python
- Sterne
- 138k
- Forks
- 12.4k
- Ø Merge
- 2 T. 12 Std.
- Gemergte PRs (30 T.)
- 161
Entwicklungsumgebung
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/spec-kit
-
triage-nice-to-have
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
Maintainer antworten meist innerhalb von 1 Tag
-
Windows: Copilot integration hardcodes `copilot.cmd`, breaking installs that ship `copilot.exe`Offenbug-assess severity-medium triage-nice-to-have
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
github/spec-kit#4755 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
triage-nice-to-have
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
[Feature]: 给 slug 添加默认值Offenenhancement needs-triage triage-can-wait
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
github/spec-kit#4627 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
needs-triage triage-nice-to-have
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
github/spec-kit#4527 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in github/spec-kit
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 86/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-2 Tage Anfängerfreundlichkeit 70/100
-
FingerprintSplitter raises ZeroDivisionError when int(frac_train * len(dataset)) floors to zeroOffen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 7 Tagen
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
lmstudio-ai/mlx-engine#376 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
pyiron/bagofholding#166 ·