基于先查文档的流程,把 ChatGPT Apps SDK 项目规划为 MCP 服务端 + 组件 UI 代码。
设计与多媒体
security-threat-model
试用针对代码仓库生成可直接落地的 AppSec 威胁模型,输出 Markdown 报告。
它能做什么
基于仓库代码(而非通用清单)产出威胁模型:识别组件、信任边界、资产、入口点与切合实际的攻击者能力,把每条威胁写成与资产绑定的攻击路径,并区分已有缓解措施与建议措施。影响、可能性与优先级都给出明确推断,未澄清的假设会在最终报告前向用户确认,最终写入 `-threat-model.md`。
什么时候用它
- 上线前对代码库做威胁建模
- 针对某个服务或模块枚举攻击路径
- 对子路径或新功能做 AppSec 评审
- 为安全审计整理信任边界与缓解措施清单
技能文档
Threat Model Source Code Repo
Deliver an actionable AppSec-grade threat model that is specific to the repository or a project path, not a generic checklist. Anchor every architectural claim to evidence in the repo and keep assumptions explicit. Prioritizing realistic attacker goals and concrete impacts over generic checklists.
Quick start
- Collect (or infer) inputs:
- Repo root path and any in-scope paths.
- Intended usage, deployment model, internet exposure, and auth expectations (if known).
- Any existing repository summary or architecture spec.
- Use prompts in
references/prompt-template.mdto generate a repository summary. - Follow the required output contract in
references/prompt-template.md. Use it verbatim when possible.
Workflow
1) Scope and extract the system model
- Identify primary components, data stores, and external integrations from the repo summary.
- Identify how the system runs (server, CLI, library, worker) and its entrypoints.
- Separate runtime behavior from CI/build/dev tooling and from tests/examples.
- Map the in-scope locations to those components and exclude out-of-scope items explicitly.
- Do not claim components, flows, or controls without evidence.
2) Derive boundaries, assets, and entry points
- Enumerate trust boundaries as concrete edges between components, noting protocol, auth, encryption, validation, and rate limiting.
- List assets that drive risk (data, credentials, models, config, compute resources, audit logs).
- Identify entry points (endpoints, upload surfaces, parsers/decoders, job triggers, admin tooling, logging/error sinks).
3) Calibrate assets and attacker capabilities
- List the assets that drive risk (credentials, PII, integrity-critical state, availability-critical components, build artifacts).
- Describe realistic attacker capabilities based on exposure and intended usage.
- Explicitly note non-capabilities to avoid inflated severity.
4) Enumerate threats as abuse paths
- Prefer attacker goals that map to assets and boundaries (exfiltration, privilege escalation, integrity compromise, denial of service).
- Classify each threat and tie it to impacted assets.
- Keep the number of threats small but high quality.
5) Prioritize with explicit likelihood and impact reasoning
- Use qualitative likelihood and impact (low/medium/high) with short justifications.
- Set overall priority (critical/high/medium/low) using likelihood x impact, adjusted for existing controls.
- State which assumptions most influence the ranking.
6) Validate service context and assumptions with the user
- Summarize key assumptions that materially affect threat ranking or scope, then ask the user to confirm or correct them.
- Ask 1–3 targeted questions to resolve missing context (service owner and environment, scale/users, deployment model, authn/authz, internet exposure, data sensitivity, multi-tenancy).
- Pause and wait for user feedback before producing the final report.
- If the user declines or can’t answer, state which assumptions remain and how they influence priority.
7) Recommend mitigations and focus paths
- Distinguish existing mitigations (with evidence) from recommended mitigations.
- Tie mitigations to concrete locations (component, boundary, or entry point) and control types (authZ checks, input validation, schema enforcement, sandboxing, rate limits, secrets isolation, audit logging).
- Prefer specific implementation hints over generic advice (e.g., "enforce schema at gateway for upload payloads" vs "validate inputs").
- Base recommendations on validated user context; if assumptions remain unresolved, mark recommendations as conditional.
8) Run a quality check before finalizing
- Confirm all discovered entrypoints are covered.
- Confirm each trust boundary is represented in threats.
- Confirm runtime vs CI/dev separation.
- Confirm user clarifications (or explicit non-responses) are reflected.
- Confirm assumptions and open questions are explicit.
- Confirm that the format of the report matches closely the required output format defined in prompt template:
references/prompt-template.md - Write the final Markdown to a file named
-threat-model.md(use the basename of the repo root, or the in-scope directory if you were asked to model a subpath).
Risk prioritization guidance (illustrative, not exhaustive)
- High: pre-auth RCE, auth bypass, cross-tenant access, sensitive data exfiltration, key or token theft, model or config integrity compromise, sandbox escape.
- Medium: targeted DoS of critical components, partial data exposure, rate-limit bypass with measurable impact, log/metrics poisoning that affects detection.
- Low: low-sensitivity info leaks, noisy DoS with easy mitigation, issues requiring unlikely preconditions.
References
- Output contract and full prompt template:
references/prompt-template.md - Optional controls/asset list:
references/security-controls-and-assets.md
Only load the reference files you need. Keep the final result concise, grounded, and reviewable.
常见问题
- 最终交付物是什么?
- 一份简洁的 Markdown 威胁模型文件,命名为 `-threat-model.md`(使用仓库根或范围内路径的 basename),包含组件、信任边界、资产、攻击者能力、按优先级排序的攻击路径,以及定位到具体位置的缓解措施。
- 会不会凭空捏造组件或控制?
- 不会。流程明确要求所有架构声明都要有仓库证据,并把运行时行为与 CI/构建/开发工具、测试明确区分,超出范围的项会被排除,假设也会被显式标出。
- 写报告前会问我什么?
- 会先汇总关键假设,并就服务归属与环境、规模与用户、部署模型、认证与授权、是否暴露公网、数据敏感度、多租户等提出 1–3 个针对性问题等待确认;若你无法回答,会明确列出剩余假设及其对优先级的影响。
相关技能
复用目标文件已发布的设计系统,把代码或描述转换为完整的 Figma 页面。
从概念、品牌或参考图生成 Codex 兼容的动画宠物与宠物精灵图集。
为 AI 编码代理生成针对你项目定制的 Figma 设计系统规则文件。
speech
官方基于 OpenAI gpt-4o-mini-tts 把文本转成语音,内置语音直接可用。
按照规划、实现、测试和评估四阶段,构建让大模型通过工具调用外部服务的 MCP 服务器。
OpenAI 的更多技能
浏览全部技能基于先查文档的流程,把 ChatGPT Apps SDK 项目规划为 MCP 服务端 + 组件 UI 代码。
复用目标文件已发布的设计系统,把代码或描述转换为完整的 Figma 页面。
通过 `use_figma` MCP 工具在 Figma 文件中执行 JavaScript 的参考技能,定义插件代码的 API 规则与写法。
从概念、品牌或参考图生成 Codex 兼容的动画宠物与宠物精灵图集。
imagegen
官方在 Codex 项目里直接生成或编辑位图图像,并把项目用到的素材放回项目内
基于 OpenAI 官方开发者文档,给出带引用的权威解答。