Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

[Extension]: Add AttackTree (v0.1.0)

Aberta Para iniciantes
#4,842 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
1/5
Tempo estimado
Menos de uma hora
Facilidade para iniciantes
72/100
Tipo de issue
Funcionalidade
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
python
Domínio
tooling

Direção de pesquisa

Comece lendo o formato do catálogo de extensões e as entradas de extensões próximas; em seguida, encontre onde as submissões ao catálogo são adicionadas e validadas. Verifique se os metadados desta submissão correspondem ao esquema esperado. A tarefa estará concluída quando a entrada do AttackTree for adicionada com os detalhes fornecidos e a validação do catálogo passar.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

enhancement needs-triage
Extension ID

attacktree

Extension Name

AttackTree

Version

0.1.0

Description

Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability

Author

hupe1980

Repository URL

https://github.com/hupe1980/spec-kit-attacktree

Download URL

https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip

License

MIT

Homepage (optional)

https://hupe1980.github.io/spec-kit-attacktree/

Documentation URL (optional)

https://hupe1980.github.io/spec-kit-attacktree/docs/

Changelog URL (optional)

https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md

Required Spec Kit Version

=1.0.0

Required Tools (optional)
- python (>=3.11) with PyYAML - required, unless uv is available
- uv - optional; the wrappers use it to fetch PyYAML and jsonschema when no suitable Python is found
- jsonschema (Python package) - optional; enables full JSON Schema validation
Number of Commands

4

Number of Hooks (optional)

7

Tags

security, attack-trees, threat-modeling, risk-simulation, traceability

Key Features
  • Builds attack-tree.yaml from spec.md and plan.md: threat actors with capabilities, attacker goals with business impact, AND/OR paths, rated attack vectors, and security controls
  • Simulates the tree with Schneier's propagation rules and attacker-profile feasibility: most likely and cheapest path per actor, residual risk per goal, choke points, single points of failure, what-if per control, a cost-ranked roadmap, and a seeded Monte Carlo
  • Publishes controls as testable CR-### requirements with Given/When/Then acceptance into spec.md
  • 16 deterministic checks (A1–A16) plus semantic review, with Markdown, JSON, and SARIF output; a bundled GitHub Action uploads to code scanning
  • Evidence-based convergence: verdicts from tests, reviews, or micro attack simulations, measured bypass rates for probabilistic controls, residual risk from verified controls only, and remediation tasks appended to tasks.md
  • Agentic profile with five attack-surface zones and references to the OWASP Top 10 for LLM and Agentic Applications 2026 and MITRE ATLAS
  • Optional Open Threat Model (OTM) import; seven optional lifecycle hooks; a companion preset and workflow
  • The engine needs no LLM: a single Python script that runs in CI
Testing Checklist
  • Extension installs successfully via download URL
  • All commands execute without errors
  • Documentation is complete and accurate
  • No security vulnerabilities identified
  • Tested on at least one real project
Submission Requirements
  • Valid extension.yml manifest included
  • README.md with installation and usage instructions
  • LICENSE file included
  • GitHub release created with version tag
  • All command files exist and are properly formatted
  • Extension ID follows naming conventions (lowercase-with-hyphens)
Testing Details

Tested on:

  • macOS (Darwin 25) with Spec Kit 1.0.7, Python 3.11, 3.13, and 3.14
  • CI: Ubuntu and Windows, Python 3.11 and 3.13

Test project: scratch project from specify init --integration claude, plus the shipped example examples/agent-assistant

Test scenarios:

  1. Manifest validated with specify_cli.extensions.ExtensionManifest (4 commands, 7 hooks, no warnings)
  2. specify extension add --dev into the scratch project: the 4 skills were registered, the config was scaffolded, and the hooks were written to .specify/extensions.yml
  3. Companion preset and workflow installed with specify preset add and specify workflow add
  4. The engine run on the example: validate, render, check (md, json, sarif), simulate (all scenarios, what-if, Monte Carlo), converge-scan, converge-apply
  5. Test suite: 132 tests, including 40 seeded randomized property tests of the propagation rules
  6. The release workflow smoke-installs the built archive with specify extension add --from
Example Usage
# Install
specify extension add attacktree --from https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip

# In your agent, after /speckit-specify
/speckit.attacktree.model
# After /speckit-plan
/speckit.attacktree.model --from-plan
/speckit.attacktree.simulate
# After /speckit-tasks
/speckit.attacktree.check
# After /speckit-implement
/speckit.attacktree.converge

# Or without an agent, e.g. in CI
.specify/extensions/attacktree/scripts/bash/attacktree.sh check --format sarif --output attacktree.sarif
.specify/extensions/attacktree/scripts/bash/attacktree.sh simulate --scenario current
Proposed Catalog Entry
{
  "attacktree": {
    "name": "AttackTree — Attack Tree Modeling & Control Simulation",
    "id": "attacktree",
    "description": "Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability",
    "author": "hupe1980",
    "version": "0.1.0",
    "download_url": "https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip",
    "repository": "https://github.com/hupe1980/spec-kit-attacktree",
    "homepage": "https://hupe1980.github.io/spec-kit-attacktree/",
    "documentation": "https://hupe1980.github.io/spec-kit-attacktree/docs/",
    "changelog": "https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md",
    "license": "MIT",
    "requires": {
      "speckit_version": ">=1.0.0"
    },
    "provides": {
      "commands": 4,
      "hooks": 7
    },
    "tags": ["security", "attack-trees", "threat-modeling", "risk-simulation", "traceability"],
    "verified": false,
    "downloads": 0,
    "stars": 0,
    "created_at": "2026-10-05T00:00:00Z",
    "updated_at": "2026-10-05T00:00:00Z"
  }
}
Additional Context

AttackTree brings attack-tree threat modelling (Schneier 1999; Christian Schneider's scenario-driven practice at attacktree.online) into Spec-Driven Development. The agent builds the tree and judges evidence; a deterministic Python engine does all propagation, simulation, and checks, so results are reproducible and CI-ready. All hooks are optional, and core commands are unchanged unless the optional preset is installed. Interop is limited to open standards: OTM import, SARIF output, and a JSON Schema for the tree.

Linguagem predominante
Python
Estrelas
139k
Forks
12.5k
Merge médio
2d 5h
PRs com merge (30d)
182

Preparar o ambiente

Abrir no Codespaces

Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/spec-kit

Todas as issues de github/spec-kit

Issues semelhantes

Mais issues de Python

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.