[Extension]: Add AttackTree (v0.1.0)
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 1/5
- Tempo estimado
- Menos de uma hora
- Facilidade para iniciantes
- 72/100
Direção de pesquisa
Comece lendo o formato do catálogo de extensões e as entradas de extensões próximas; em seguida, encontre onde as submissões ao catálogo são adicionadas e validadas. Verifique se os metadados desta submissão correspondem ao esquema esperado. A tarefa estará concluída quando a entrada do AttackTree for adicionada com os detalhes fornecidos e a validação do catálogo passar.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Extension ID
attacktree
Extension Name
AttackTree
Version
0.1.0
Description
Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability
Author
hupe1980
Repository URL
https://github.com/hupe1980/spec-kit-attacktree
Download URL
https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
License
MIT
Homepage (optional)
https://hupe1980.github.io/spec-kit-attacktree/
Documentation URL (optional)
https://hupe1980.github.io/spec-kit-attacktree/docs/
Changelog URL (optional)
https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md
Required Spec Kit Version
=1.0.0
Required Tools (optional)
- python (>=3.11) with PyYAML - required, unless uv is available
- uv - optional; the wrappers use it to fetch PyYAML and jsonschema when no suitable Python is found
- jsonschema (Python package) - optional; enables full JSON Schema validation
Number of Commands
4
Number of Hooks (optional)
7
Tags
security, attack-trees, threat-modeling, risk-simulation, traceability
Key Features
- Builds
attack-tree.yamlfromspec.mdandplan.md: threat actors with capabilities, attacker goals with business impact, AND/OR paths, rated attack vectors, and security controls - Simulates the tree with Schneier's propagation rules and attacker-profile feasibility: most likely and cheapest path per actor, residual risk per goal, choke points, single points of failure, what-if per control, a cost-ranked roadmap, and a seeded Monte Carlo
- Publishes controls as testable
CR-###requirements with Given/When/Then acceptance intospec.md - 16 deterministic checks (A1–A16) plus semantic review, with Markdown, JSON, and SARIF output; a bundled GitHub Action uploads to code scanning
- Evidence-based convergence: verdicts from tests, reviews, or micro attack simulations, measured bypass rates for probabilistic controls, residual risk from verified controls only, and remediation tasks appended to
tasks.md - Agentic profile with five attack-surface zones and references to the OWASP Top 10 for LLM and Agentic Applications 2026 and MITRE ATLAS
- Optional Open Threat Model (OTM) import; seven optional lifecycle hooks; a companion preset and workflow
- The engine needs no LLM: a single Python script that runs in CI
Testing Checklist
- Extension installs successfully via download URL
- All commands execute without errors
- Documentation is complete and accurate
- No security vulnerabilities identified
- Tested on at least one real project
Submission Requirements
- Valid
extension.ymlmanifest included - README.md with installation and usage instructions
- LICENSE file included
- GitHub release created with version tag
- All command files exist and are properly formatted
- Extension ID follows naming conventions (lowercase-with-hyphens)
Testing Details
Tested on:
- macOS (Darwin 25) with Spec Kit 1.0.7, Python 3.11, 3.13, and 3.14
- CI: Ubuntu and Windows, Python 3.11 and 3.13
Test project: scratch project from specify init --integration claude, plus the shipped example examples/agent-assistant
Test scenarios:
- Manifest validated with
specify_cli.extensions.ExtensionManifest(4 commands, 7 hooks, no warnings) specify extension add --devinto the scratch project: the 4 skills were registered, the config was scaffolded, and the hooks were written to.specify/extensions.yml- Companion preset and workflow installed with
specify preset addandspecify workflow add - The engine run on the example: validate, render, check (md, json, sarif), simulate (all scenarios, what-if, Monte Carlo), converge-scan, converge-apply
- Test suite: 132 tests, including 40 seeded randomized property tests of the propagation rules
- The release workflow smoke-installs the built archive with
specify extension add --from
Example Usage
# Install
specify extension add attacktree --from https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
# In your agent, after /speckit-specify
/speckit.attacktree.model
# After /speckit-plan
/speckit.attacktree.model --from-plan
/speckit.attacktree.simulate
# After /speckit-tasks
/speckit.attacktree.check
# After /speckit-implement
/speckit.attacktree.converge
# Or without an agent, e.g. in CI
.specify/extensions/attacktree/scripts/bash/attacktree.sh check --format sarif --output attacktree.sarif
.specify/extensions/attacktree/scripts/bash/attacktree.sh simulate --scenario current
Proposed Catalog Entry
{
"attacktree": {
"name": "AttackTree — Attack Tree Modeling & Control Simulation",
"id": "attacktree",
"description": "Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability",
"author": "hupe1980",
"version": "0.1.0",
"download_url": "https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip",
"repository": "https://github.com/hupe1980/spec-kit-attacktree",
"homepage": "https://hupe1980.github.io/spec-kit-attacktree/",
"documentation": "https://hupe1980.github.io/spec-kit-attacktree/docs/",
"changelog": "https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md",
"license": "MIT",
"requires": {
"speckit_version": ">=1.0.0"
},
"provides": {
"commands": 4,
"hooks": 7
},
"tags": ["security", "attack-trees", "threat-modeling", "risk-simulation", "traceability"],
"verified": false,
"downloads": 0,
"stars": 0,
"created_at": "2026-10-05T00:00:00Z",
"updated_at": "2026-10-05T00:00:00Z"
}
}
Additional Context
AttackTree brings attack-tree threat modelling (Schneier 1999; Christian Schneider's scenario-driven practice at attacktree.online) into Spec-Driven Development. The agent builds the tree and judges evidence; a deterministic Python engine does all propagation, simulation, and checks, so results are reproducible and CI-ready. All hooks are optional, and core commands are unchanged unless the optional preset is installed. Interop is limited to open standards: OTM import, SARIF output, and a JSON Schema for the tree.
- Docs and landing page: https://hupe1980.github.io/spec-kit-attacktree/
- Worked example: https://github.com/hupe1980/spec-kit-attacktree/tree/main/examples/agent-assistant
- Linguagem predominante
- Python
- Estrelas
- 139k
- Forks
- 12.5k
- Merge médio
- 2d 5h
- PRs com merge (30d)
- 182
Preparar o ambiente
Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.
- Sem Dockerfile nem arquivo Docker Compose
- Tem um modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/spec-kit
-
feature-assess feature-go triage-can-wait
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
github/spec-kit#4804 · 6 comentários ·
Mantenedores costumam responder em até 1 dia
-
needs-triage triage-nice-to-have
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
github/spec-kit#4527 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
[Bug]: specify init writes speckit.manifest.json without the speckit-converge skill it just installedTalvez livre de novo Um pull request para esta issue foi fechado sem ser mesclado. Abertabug-assess severity-medium
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
github/spec-kit#4273 · 3 comentários ·
Mantenedores costumam responder em até 1 dia
-
[Bug]: /speckit-implement counts checkbox markers inside fenced code blocks — example checkboxes can falsely block implementationTalvez já em andamento @ntdatt812 assumiu há 26 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
Mantenedores costumam responder em até 1 dia
-
[Extension]: Jira Integration (Sync Engine) v0.5.0 (version update of jira-sync)Talvez já em andamento @github-actions assumiu há 50 dias. Abertaextension-submission validation-passed
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
github/spec-kit#4099 · 3 comentários ·
Mantenedores costumam responder em até 1 dia
Todas as issues de github/spec-kit
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
Mantenedores costumam responder em até 3 dias
-
Negation with "not" and "no" is ignored during sentiment analysisTalvez já em andamento @vivek-3728 assumiu hoje. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
techcsispit/mess-mood#11 · 1 comentário ·
-
changelog investigate
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
ramnes/notion-sdk-py#408 ·
-
good first issue
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 83/100
btclib-org/btclib-wallet#267 ·
Mantenedores costumam responder em até 1 dia
-
good first issue tech-debt
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 85/100
knnmelprop/YAADO#111 ·