Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Extension]: Add AttackTree (v0.1.0)

クローズ 初心者向け
#4,842 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
1/5
見積もり時間
1時間未満
初心者へのやさしさ
72/100
issue の種類
機能追加
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
python
領域
tooling

調査の方向性

まず拡張機能カタログの形式と近くにある拡張機能のエントリを読み、次にカタログへの登録を追加・検証する箇所を探してください。この登録のメタデータが期待されるスキーマに一致するか確認してください。提供された詳細情報とともにAttackTreeのエントリが追加され、カタログの検証に合格すれば完了です。

索引モデルが issue の本文から書いたものです。

説明

enhancement needs-triage
Extension ID

attacktree

Extension Name

AttackTree

Version

0.1.0

Description

Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability

Author

hupe1980

Repository URL

https://github.com/hupe1980/spec-kit-attacktree

Download URL

https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip

License

MIT

Homepage (optional)

https://hupe1980.github.io/spec-kit-attacktree/

Documentation URL (optional)

https://hupe1980.github.io/spec-kit-attacktree/docs/

Changelog URL (optional)

https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md

Required Spec Kit Version

=1.0.0

Required Tools (optional)
- python (>=3.11) with PyYAML - required, unless uv is available
- uv - optional; the wrappers use it to fetch PyYAML and jsonschema when no suitable Python is found
- jsonschema (Python package) - optional; enables full JSON Schema validation
Number of Commands

4

Number of Hooks (optional)

7

Tags

security, attack-trees, threat-modeling, risk-simulation, traceability

Key Features
  • Builds attack-tree.yaml from spec.md and plan.md: threat actors with capabilities, attacker goals with business impact, AND/OR paths, rated attack vectors, and security controls
  • Simulates the tree with Schneier's propagation rules and attacker-profile feasibility: most likely and cheapest path per actor, residual risk per goal, choke points, single points of failure, what-if per control, a cost-ranked roadmap, and a seeded Monte Carlo
  • Publishes controls as testable CR-### requirements with Given/When/Then acceptance into spec.md
  • 16 deterministic checks (A1–A16) plus semantic review, with Markdown, JSON, and SARIF output; a bundled GitHub Action uploads to code scanning
  • Evidence-based convergence: verdicts from tests, reviews, or micro attack simulations, measured bypass rates for probabilistic controls, residual risk from verified controls only, and remediation tasks appended to tasks.md
  • Agentic profile with five attack-surface zones and references to the OWASP Top 10 for LLM and Agentic Applications 2026 and MITRE ATLAS
  • Optional Open Threat Model (OTM) import; seven optional lifecycle hooks; a companion preset and workflow
  • The engine needs no LLM: a single Python script that runs in CI
Testing Checklist
  • Extension installs successfully via download URL
  • All commands execute without errors
  • Documentation is complete and accurate
  • No security vulnerabilities identified
  • Tested on at least one real project
Submission Requirements
  • Valid extension.yml manifest included
  • README.md with installation and usage instructions
  • LICENSE file included
  • GitHub release created with version tag
  • All command files exist and are properly formatted
  • Extension ID follows naming conventions (lowercase-with-hyphens)
Testing Details

Tested on:

  • macOS (Darwin 25) with Spec Kit 1.0.7, Python 3.11, 3.13, and 3.14
  • CI: Ubuntu and Windows, Python 3.11 and 3.13

Test project: scratch project from specify init --integration claude, plus the shipped example examples/agent-assistant

Test scenarios:

  1. Manifest validated with specify_cli.extensions.ExtensionManifest (4 commands, 7 hooks, no warnings)
  2. specify extension add --dev into the scratch project: the 4 skills were registered, the config was scaffolded, and the hooks were written to .specify/extensions.yml
  3. Companion preset and workflow installed with specify preset add and specify workflow add
  4. The engine run on the example: validate, render, check (md, json, sarif), simulate (all scenarios, what-if, Monte Carlo), converge-scan, converge-apply
  5. Test suite: 132 tests, including 40 seeded randomized property tests of the propagation rules
  6. The release workflow smoke-installs the built archive with specify extension add --from
Example Usage
# Install
specify extension add attacktree --from https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip

# In your agent, after /speckit-specify
/speckit.attacktree.model
# After /speckit-plan
/speckit.attacktree.model --from-plan
/speckit.attacktree.simulate
# After /speckit-tasks
/speckit.attacktree.check
# After /speckit-implement
/speckit.attacktree.converge

# Or without an agent, e.g. in CI
.specify/extensions/attacktree/scripts/bash/attacktree.sh check --format sarif --output attacktree.sarif
.specify/extensions/attacktree/scripts/bash/attacktree.sh simulate --scenario current
Proposed Catalog Entry
{
  "attacktree": {
    "name": "AttackTree — Attack Tree Modeling & Control Simulation",
    "id": "attacktree",
    "description": "Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability",
    "author": "hupe1980",
    "version": "0.1.0",
    "download_url": "https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip",
    "repository": "https://github.com/hupe1980/spec-kit-attacktree",
    "homepage": "https://hupe1980.github.io/spec-kit-attacktree/",
    "documentation": "https://hupe1980.github.io/spec-kit-attacktree/docs/",
    "changelog": "https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md",
    "license": "MIT",
    "requires": {
      "speckit_version": ">=1.0.0"
    },
    "provides": {
      "commands": 4,
      "hooks": 7
    },
    "tags": ["security", "attack-trees", "threat-modeling", "risk-simulation", "traceability"],
    "verified": false,
    "downloads": 0,
    "stars": 0,
    "created_at": "2026-10-05T00:00:00Z",
    "updated_at": "2026-10-05T00:00:00Z"
  }
}
Additional Context

AttackTree brings attack-tree threat modelling (Schneier 1999; Christian Schneider's scenario-driven practice at attacktree.online) into Spec-Driven Development. The agent builds the tree and judges evidence; a deterministic Python engine does all propagation, simulation, and checks, so results are reproducible and CI-ready. All hooks are optional, and core commands are unchanged unless the optional preset is installed. Interop is limited to open standards: OTM import, SARIF output, and a JSON Schema for the tree.

主要言語
Python
スター
140k
フォーク
12.6k
平均マージ
2日 18時間
マージ済み PR(30日)
195

環境構築

Codespaces で開く

このプロジェクトの開発コンテナを、あなたの GitHub アカウントでブラウザ上に起動します。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

github/spec-kit のほかの issue

github/spec-kit の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。