Threat Lens
Paste a system or architecture description and get an AppSec threat model: a posture verdict, components and trust boundaries, an attacker model with explicit non-capabilities, entry points, multi-step abuse paths, a prioritized threat table with mitigations and detection ideas, and the focus areas to review first. A free client-side prescan flags attack surfaces, sensitive assets and exposure hints, and the model must reconcile every one. Derived from the @openai/security-threat-model skill.
Details
gpt-terra Every public app is built from a security-scanned skill and must pass a clean scan — skill and frontend — before it can be listed. Have a skill of your own? Turn it into an app — or read the step-by-step walkthrough.