⚠️ Beta — not production ready.appsec-advisoris under active development. Interfaces, schemas, and output may change without notice.
appsec-advisor is a Claude Code plugin for code-derived threat modeling: it reads the code and configuration in a repository, builds an architecture model, and runs STRIDE against it. Each finding references repository evidence and includes remediation guidance.
Re-run the assessment when the code changes. The result complements workshops and scanners with an implementation-level model; it does not replace either. The plugin also includes requirements audits, change reviews, and CI gates.
Why appsec-advisor? · Security · Quick start · Threat Modeler · Documentation · Contributing
Traditional threat modeling brings teams together in workshops to map data flows, assets, trust boundaries, assumptions, and acceptable risks. This captures how the system is intended to work. Once code and configuration exist, appsec-advisor adds evidence from the implementation. It does not replace workshops, expert review, or developers thinking about threats themselves.
The plugin reads the repository and looks for missing controls at trust boundaries, implicit trust between services, unauthenticated paths, and other design risks. Run it again as the application changes to keep the threat model current. These repeatable checks help a small AppSec team cover a larger application portfolio and focus expert time on cases that need human judgment.
Organizations can add their own requirements and tools without maintaining a fork of the core analysis pipeline. See Enterprise rollout.
SAST analyzes implementation flaws in source code and traces untrusted data through concrete code paths. appsec-advisor works at the architecture level: it reconstructs components, data flows, and trust boundaries, then checks whether the expected controls exist across them.
The two approaches overlap in their use of code evidence, but answer different questions. SAST asks where an implementation is vulnerable. Code-derived threat modeling also asks whether the system design depends on trust or controls that the implementation does not provide.
The analysis is limited to the repository and any configured related repositories. It cannot verify runtime behavior, production-only controls, business processes, or user journeys. An AppSec engineer or security architect should validate findings before they drive remediation or risk acceptance.
Important
Treat scanned repositories as untrusted input. Repository content enters the LLM context and may attempt prompt injection. Untrusted mode is the default; keep it enabled and use a container or VM for third-party or vendor code. See Security: Untrusted repositories.
Data handling. Source, manifests, and configuration for analyzed components are sent to Anthropic. Surfaced secrets are masked. The plugin requires api.anthropic.com, cannot run air-gapped, and uses provider-side prompt caching.
Python renders reports from validated structured data. If a run artifact contains an unmasked secret, the run fails before its outputs are considered publishable.
Requires Claude Code, Python 3.10+, and git on PATH. Optional Mermaid dependencies provide stricter diagram validation; see the Threat Modeler reference.
For most repositories, run the Claude Code session on Sonnet 4.6. The orchestration session remains active for the full assessment and therefore has the largest effect on cost. Agent models are routed separately: a standard scan uses Sonnet 5 for judgment and report authoring, while STRIDE discovery remains on Sonnet 4.6. Very large repositories may require a Sonnet 5 session for the larger context window. See Model Selection.
Add the marketplace and install the plugin. This installs the current release and needs no checkout:
claude plugin marketplace add appsec-foundry/appsec-advisor
claude plugin install appsec-advisor@appsec-foundryLater releases arrive with claude plugin update appsec-advisor, which takes effect after a restart.
Then start Claude Code from the repository you want to assess:
cd /path/to/repository-to-assess
claudeTo run the development branch instead of a release, clone the repository and start Claude Code with the checkout:
git clone --branch dev https://github.com/appsec-foundry/appsec-advisor.git /path/to/appsec-advisor
cd /path/to/repository-to-assess
claude --plugin-dir /path/to/appsec-advisorRun the one-time permission setup:
/appsec-advisor:check-permissions --update
Restart or reload Claude Code, then create the model:
/appsec-advisor:create-threat-model
The assessment writes threat-model.md and threat-model.yaml to docs/security/.
# Reassess after code changes while preserving history
/appsec-advisor:create-threat-model --full
# Record fix, accept-risk, or defer decisions
/appsec-advisor:review-threat-model
# Publish a reviewed model to version control
/appsec-advisor:publish-threat-model
# Or ask a question directly
what are the most critical findings?
what should I fix first?
does it cover SSRF?
Updates preserve finding IDs. Review decisions are stored separately, and publishing remains optional. Run /appsec-advisor:help for the complete command list.
- Findings name the requirements they break, and mitigations quote the blueprint section that prescribes the fix.
- The Management Summary states compliance and lists the failed requirements.
/appsec-advisor:security-scorescores a repository from 0 to 100 using the scanners alone./appsec-advisor:statusreports the versions, skills, profile, and config in effect;--check-updateschecks whether they are current./appsec-advisor:authnz-reviewexports its findings as pentest tasks, with the discovered routes as the endpoint catalog.- Source scans flag LLM output that reaches rendering, interpreters, or privileged actions unchecked.
/appsec-advisor:update-baselinerefreshes an installed secure-coding baseline where it is loaded from; an organization profile can vendor its own source for it.
- Runs support only full, rebuild, and rerender; reassess a changed repository with
--full. - Threat analysis costs 39.8% less at quick depth and 26.8% less at thorough depth in reference runs.
- Trust boundaries are assessed, drawn in the architecture diagram, and linked to findings that cross them.
install-baselineandverify-baselineput the bundled AI Secure Coding Baseline into Claude Code's instruction files and let CI verify it.- Scans can take business context interactively or through
--context; named sensitive assets keep their component in scope, and the report says which file was read and how many findings it applied to. --formats threatdragonexports alpha Threat Dragon v2 JSON for Threat Dragon and OWASP ThreatAtlas.- Organization profiles can include custom skills and baselines, configure the session banner, and disable individual skills.
See the full changelog for all changes.
Run /appsec-advisor:create-threat-model to get:
- an architecture model with components, data flows, and trust boundaries;
- findings ordered by risk and tied to repository evidence;
- a Weakness Register for systemic and design patterns;
- mitigation guidance and generated diagrams;
threat-model.mdandthreat-model.yaml, with optional PDF, HTML, SARIF, Threat Dragon, and pentest-task exports.
The report links findings to the OWASP Top 10:2025. If the repository contains an LLM or agentic application, it also checks the relevant OWASP LLM and Agentic Applications categories.
Example: Read a thorough assessment of OWASP Juice Shop or browse more examples.
Assessments consume model tokens and usually take tens of minutes; thorough runs may exceed an hour. The Threat Modeler reference covers depth, focused scans, repository context, measured costs, and limits.
/appsec-advisor:audit-security-requirements checks the repository against an AppSec requirements catalog. It provides a faster control assessment for pull-request gates, compliance dashboards, and audit preparation.
# Use the configured catalog
/appsec-advisor:audit-security-requirements
# Use a catalog URL for this run
/appsec-advisor:audit-security-requirements --requirements https://appsec.int.example.com/appsec-requirements.yaml
If you do not have a catalog, adapt data/appsec-requirements-fallback.yaml or use the requirements harvester. See the Requirements Audit reference for setup and options.
| Tool | Use |
|---|---|
| Secure-coding baseline | Install, update, verify, or remove secure-coding instructions with install-baseline, update-baseline, verify-baseline, and remove-baseline. |
| Security Coach (experimental) | Add security guidance while writing security-sensitive code. |
| appsec-reviewer (experimental) | Embed change review in Claude Code or an Agent SDK workflow. |
| verify-requirements (experimental) | Review an interactive diff against the requirements catalog. |
| appsec-reviewer-cli (experimental) | Run the same change review in CI or other automation. |
See the developer tools guide for commands and configuration.
Create an anonymized diagnostic bundle with:
/appsec-advisor:report-error
Review the bundle before attaching it to a GitHub issue. The command excludes source code, findings, evidence, and report content, and sends nothing automatically.
AppSec and Platform teams can supply organization-specific requirements, defaults, guardrails, skills, hooks, and MCP servers. The organization packaging template keeps this configuration in a separate internal package built from a pinned upstream release. Core agent definitions remain upstream-owned.
See Internal Plugin Packaging and Organization Profiles.
| Goal | Start here |
|---|---|
| Run or configure a threat model | Threat Modeler |
| Add repository context or trust-boundary declarations | Repo-local context |
| Configure models, cost, logging, or organization settings | Configuration and Model Selection |
| Configure requirements audits | Requirements Audit |
| Run without interaction or integrate with CI | Non-interactive Mode |
| Package the plugin for an organization | Internal Plugin Packaging |
| Browse complete report examples | Threat Modeler Examples |
| Develop or contribute | Contributing and AGENTS.md |
| Report a vulnerability | Security Policy |
Agents inspect the repository and perform the security analysis. Deterministic Python validates structured artifacts, renders reports, generates exports, and enforces release gates. Schemas define the data exchanged between pipeline stages.
The main directories are agents/, skills/, scripts/, schemas/, templates/, and tests/. See the repository layout for the complete map and the tests required for each kind of change.
- appsec-advisor-packaging-template builds organization-specific plugin packages from pinned upstream releases.
- aiscb contains the secure-coding rules bundled by the plugin.
| Project | Primary scope | Relation to appsec-advisor |
|---|---|---|
| tachi | Multi-agent analysis of an architecture description. | Tachi treats the description as its primary input; appsec-advisor derives the model from code and configuration. |
| stride-gpt | Provider-independent STRIDE analysis from a description or codebase. | stride-gpt supports several model providers; appsec-advisor runs in Claude Code and adds schema validation and stable finding IDs. |
| OWASP pytm | Threat models authored and maintained as Python code. | pytm requires developers to declare the model; appsec-advisor derives it from the implementation. |
| OWASP Threat Dragon | Visual threat modeling and editable data-flow diagrams. | Threat Dragon starts from a modeler-authored diagram; appsec-advisor can generate and export an initial model from a repository. |
| OWASP ThreatAtlas | Collaborative threat-modeling workshops on shared diagrams. | ThreatAtlas records the workshop model; appsec-advisor maintains a code-derived model between sessions. |
| OWASP Precogly | Program-level threat modeling, libraries, and compliance traceability. | Precogly acts as a maintained system of record; appsec-advisor produces a model for an individual repository. |
| Claude Security | Enterprise scanning for exploitable codebase vulnerabilities. | Claude Security focuses on implementation flaws; appsec-advisor also identifies architectural gaps without a single vulnerable line. |
The Threat Dragon export can carry generated models into Threat Dragon and ThreatAtlas.
Development happens on dev. Branch from it and target it with your pull request; main contains tagged releases.
See CONTRIBUTING.md for setup and repository conventions. Read AGENTS.md before changing runtime behavior, schemas, prompts, permissions, cleanup behavior, or report output. Report vulnerabilities through SECURITY.md.