KS
Killer-Skills

ctm — how to use ctm how to use ctm, what is ctm, ctm vs threat modeling, ctm install guide, ctm setup for developers, continuous threat modeling tutorial, ctm alternative solutions, ctm security notable events

v1.0.0
GitHub

About this Skill

Perfect for Security Analysis Agents needing advanced threat modeling capabilities for Continuous Threat Modeling (CTM) ctm is a skill that enables Continuous Threat Modeling by examining business cases and user stories to identify security notable events according to a baseline threat model.

Features

Uses a security notable event checklist to track progress
Enriches development requests with relevant threat model data
Utilizes the CTM Developer Checklist for comprehensive analysis
Examines business cases in the context of project baselines
Identifies security notable events according to a baseline threat model
Supports copying and tracking of the security notable event checklist

# Core Topics

izar izar
[0]
[0]
Updated: 3/6/2026

Quality Score

Top 5%
30
Excellent
Based on code quality & docs
Installation
SYS Universal Install (Auto-Detect)
Cursor IDE Windsurf IDE VS Code IDE
> npx killer-skills add izar/tm_skills/ctm

Agent Capability Analysis

The ctm MCP Server by izar is an open-source Categories.community integration for Claude and other AI agents, enabling seamless task automation and capability expansion. Optimized for how to use ctm, what is ctm, ctm vs threat modeling.

Ideal Agent Persona

Perfect for Security Analysis Agents needing advanced threat modeling capabilities for Continuous Threat Modeling (CTM)

Core Value

Empowers agents to examine business cases and user stories in the context of project baselines and existing threat models, identifying security notable events using CTM Developer Checklists and baseline threat models

Capabilities Granted for ctm MCP Server

Automating security notable event detection
Enriching development requests with threat model context
Validating user stories against project baselines

! Prerequisites & Limits

  • Requires existing baseline threat model
  • Limited to Continuous Threat Modeling (CTM) framework
Project
SKILL.md
1.6 KB
.cursorrules
1.2 KB
package.json
240 B
Ready
UTF-8

# Tags

[No tags]
SKILL.md
Readonly

Overview

Given a business case, a user-story, a development request or similar, examine it in the context of the project and the existing baseline threat model and decide if it is a "security notable event" according to Continuous Threat Modeling.

Method

Copy this checklist and track your progress:

Security notable event checklist

- [ ] Find a baseline threat model
- [ ] Enrich the request
- [ ] Use the CTM Developer Checklist

**Step 1: Find a baseline threat model

Examine the project's directory for documentation that resembles a threat model. If one is found, use that as the baseline threat model. If one is not found, ask the user if they would like to use the pytm skill to create one, or if they can provide a baseline threat model. Give the user the option to not have a baseline threat model but point out the quality of the analysis will be diminished.

**Step 2: Enrich the request

If a baseline threat model is available, use it to enrich the corpus of the request. Feel free to ask the user as many elucidative questions about the request as you consider necessary. Use the answers to enrich the request.

**Step 3: Use the CTM Developer Checklist

Using the content of ./Secure_Developer_Checklist.md try to identify in the user request instances that match the "If you did THIS ..." side of the reference table. If matches are found, use the "... then do THAT" respective field to suggest mitigations to the issue identified.

There can be many matches in any given request. Return all those matches.

If there are notable events, suggest to the user that a ticket be created reflecting this change so the threat model can be updated.

Related Skills

Looking for an alternative to ctm or building a Categories.community AI Agent? Explore these related open-source MCP Servers.

View All

widget-generator

Logo of f
f

widget-generator is an open-source AI agent skill for creating widget plugins that are injected into prompt feeds on prompts.chat. It supports two rendering modes: standard prompt widgets using default PromptCard styling and custom render widgets built as full React components.

149.6k
0
Design

chat-sdk

Logo of lobehub
lobehub

chat-sdk is a unified TypeScript SDK for building chat bots across multiple platforms, providing a single interface for deploying bot logic.

73.0k
0
Communication

zustand

Logo of lobehub
lobehub

The ultimate space for work and life — to find, build, and collaborate with agent teammates that grow with you. We are taking agent harness to the next level — enabling multi-agent collaboration, effortless agent team design, and introducing agents as the unit of work interaction.

72.8k
0
Communication

data-fetching

Logo of lobehub
lobehub

The ultimate space for work and life — to find, build, and collaborate with agent teammates that grow with you. We are taking agent harness to the next level — enabling multi-agent collaboration, effortless agent team design, and introducing agents as the unit of work interaction.

72.8k
0
Communication