[Extension]: Add AttackTree (v0.1.0)
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 1/5
- Temps estimé
- Moins d'une heure
- Accessibilité débutants
- 72/100
Piste de recherche
Commencez par lire le format du catalogue d’extensions et les entrées d’extensions voisines, puis cherchez où les soumissions au catalogue sont ajoutées et validées. Vérifiez si les métadonnées de cette soumission correspondent au schéma attendu. Le travail est terminé lorsque l’entrée AttackTree est ajoutée avec les détails fournis et que la validation du catalogue réussit.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Extension ID
attacktree
Extension Name
AttackTree
Version
0.1.0
Description
Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability
Author
hupe1980
Repository URL
https://github.com/hupe1980/spec-kit-attacktree
Download URL
https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
License
MIT
Homepage (optional)
https://hupe1980.github.io/spec-kit-attacktree/
Documentation URL (optional)
https://hupe1980.github.io/spec-kit-attacktree/docs/
Changelog URL (optional)
https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md
Required Spec Kit Version
=1.0.0
Required Tools (optional)
- python (>=3.11) with PyYAML - required, unless uv is available
- uv - optional; the wrappers use it to fetch PyYAML and jsonschema when no suitable Python is found
- jsonschema (Python package) - optional; enables full JSON Schema validation
Number of Commands
4
Number of Hooks (optional)
7
Tags
security, attack-trees, threat-modeling, risk-simulation, traceability
Key Features
- Builds
attack-tree.yamlfromspec.mdandplan.md: threat actors with capabilities, attacker goals with business impact, AND/OR paths, rated attack vectors, and security controls - Simulates the tree with Schneier's propagation rules and attacker-profile feasibility: most likely and cheapest path per actor, residual risk per goal, choke points, single points of failure, what-if per control, a cost-ranked roadmap, and a seeded Monte Carlo
- Publishes controls as testable
CR-###requirements with Given/When/Then acceptance intospec.md - 16 deterministic checks (A1–A16) plus semantic review, with Markdown, JSON, and SARIF output; a bundled GitHub Action uploads to code scanning
- Evidence-based convergence: verdicts from tests, reviews, or micro attack simulations, measured bypass rates for probabilistic controls, residual risk from verified controls only, and remediation tasks appended to
tasks.md - Agentic profile with five attack-surface zones and references to the OWASP Top 10 for LLM and Agentic Applications 2026 and MITRE ATLAS
- Optional Open Threat Model (OTM) import; seven optional lifecycle hooks; a companion preset and workflow
- The engine needs no LLM: a single Python script that runs in CI
Testing Checklist
- Extension installs successfully via download URL
- All commands execute without errors
- Documentation is complete and accurate
- No security vulnerabilities identified
- Tested on at least one real project
Submission Requirements
- Valid
extension.ymlmanifest included - README.md with installation and usage instructions
- LICENSE file included
- GitHub release created with version tag
- All command files exist and are properly formatted
- Extension ID follows naming conventions (lowercase-with-hyphens)
Testing Details
Tested on:
- macOS (Darwin 25) with Spec Kit 1.0.7, Python 3.11, 3.13, and 3.14
- CI: Ubuntu and Windows, Python 3.11 and 3.13
Test project: scratch project from specify init --integration claude, plus the shipped example examples/agent-assistant
Test scenarios:
- Manifest validated with
specify_cli.extensions.ExtensionManifest(4 commands, 7 hooks, no warnings) specify extension add --devinto the scratch project: the 4 skills were registered, the config was scaffolded, and the hooks were written to.specify/extensions.yml- Companion preset and workflow installed with
specify preset addandspecify workflow add - The engine run on the example: validate, render, check (md, json, sarif), simulate (all scenarios, what-if, Monte Carlo), converge-scan, converge-apply
- Test suite: 132 tests, including 40 seeded randomized property tests of the propagation rules
- The release workflow smoke-installs the built archive with
specify extension add --from
Example Usage
# Install
specify extension add attacktree --from https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
# In your agent, after /speckit-specify
/speckit.attacktree.model
# After /speckit-plan
/speckit.attacktree.model --from-plan
/speckit.attacktree.simulate
# After /speckit-tasks
/speckit.attacktree.check
# After /speckit-implement
/speckit.attacktree.converge
# Or without an agent, e.g. in CI
.specify/extensions/attacktree/scripts/bash/attacktree.sh check --format sarif --output attacktree.sarif
.specify/extensions/attacktree/scripts/bash/attacktree.sh simulate --scenario current
Proposed Catalog Entry
{
"attacktree": {
"name": "AttackTree — Attack Tree Modeling & Control Simulation",
"id": "attacktree",
"description": "Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability",
"author": "hupe1980",
"version": "0.1.0",
"download_url": "https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip",
"repository": "https://github.com/hupe1980/spec-kit-attacktree",
"homepage": "https://hupe1980.github.io/spec-kit-attacktree/",
"documentation": "https://hupe1980.github.io/spec-kit-attacktree/docs/",
"changelog": "https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md",
"license": "MIT",
"requires": {
"speckit_version": ">=1.0.0"
},
"provides": {
"commands": 4,
"hooks": 7
},
"tags": ["security", "attack-trees", "threat-modeling", "risk-simulation", "traceability"],
"verified": false,
"downloads": 0,
"stars": 0,
"created_at": "2026-10-05T00:00:00Z",
"updated_at": "2026-10-05T00:00:00Z"
}
}
Additional Context
AttackTree brings attack-tree threat modelling (Schneier 1999; Christian Schneider's scenario-driven practice at attacktree.online) into Spec-Driven Development. The agent builds the tree and judges evidence; a deterministic Python engine does all propagation, simulation, and checks, so results are reproducible and CI-ready. All hooks are optional, and core commands are unchanged unless the optional preset is installed. Interop is limited to open standards: OTM import, SARIF output, and a JSON Schema for the tree.
- Docs and landing page: https://hupe1980.github.io/spec-kit-attacktree/
- Worked example: https://github.com/hupe1980/spec-kit-attacktree/tree/main/examples/agent-assistant
- Langage dominant
- Python
- Étoiles
- 139k
- Forks
- 12.5k
- Merge moyen
- 2 j 4 h
- PR mergées (30 j)
- 167
Préparer son environnement
Lance le conteneur de développement du projet dans votre navigateur, avec votre propre compte GitHub.
- Aucun Dockerfile ni fichier Docker Compose
- Propose un modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de github/spec-kit
-
feature-assess feature-go triage-can-wait
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
github/spec-kit#4804 · 6 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
needs-triage triage-nice-to-have
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/spec-kit#4527 · 1 commentaire ·
Les mainteneurs répondent en général sous 1 jour
-
[Bug]: specify init writes speckit.manifest.json without the speckit-converge skill it just installedPeut-être à nouveau libre Une pull request pour cette issue a été fermée sans être fusionnée. Ouvertebug-assess severity-medium
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/spec-kit#4273 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
-
[Bug]: /speckit-implement counts checkbox markers inside fenced code blocks — example checkboxes can falsely block implementationPeut-être pris @ntdatt812 l’a pris il y a 25 jours. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 84/100
Les mainteneurs répondent en général sous 1 jour
-
[Extension]: Jira Integration (Sync Engine) v0.5.0 (version update of jira-sync)Peut-être pris @github-actions l’a pris il y a 50 jours. Ouverteextension-submission validation-passed
Difficulté 2/5 1-3 heures Accessibilité débutants 72/100
github/spec-kit#4099 · 3 commentaires ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de github/spec-kit
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 83/100
Les mainteneurs répondent en général sous 1 jour
-
Difficulté 2/5 1-3 heures Accessibilité débutants 86/100
FuRongJun-1999/dsh-memory#65 ·
Les mainteneurs répondent en général sous 1 jour
-
ci needs-ac
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
Ikalus1988/MisakaNet#2930 ·
Les mainteneurs répondent en général sous 1 jour
-
`FakeBackendV2.run` fails with `NoiseError` on circuits with delays on qubits where T2 > 2·T1Ouvertebug
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100
Qiskit/qiskit-aer#2466 ·
-
area/cli
Difficulté 2/5 1-3 heures Accessibilité débutants 82/100