On this page
- Start here (Track A, Track B, Track C)
- Run one prompt at a time
- Track A: Four Questions
- Track B (optional)
- Track C (optional)
- Export the report, JSON, CSV, and diagram
- Evaluation baselines
Start here: one chat
- Attach the representation and set
representation_kindtoimage,mermaid, orsvg. - Copy the Track A shortcut. Send it once with the representation.
- Save the four export replies as
.md,.json,.csv, and.mmd.
The model loads prompts.json and runs Track A through the four exports. Omitted fields stay empty. Catalog, SRF, and vertical mapping without injected data are not applicable. Optional JSON stays on this page; it is not in the copied shortcut. If the chat cannot load that file, use Run one prompt at a time.
Track A
Default path. Representation and representation_kind are
enough. Default role is experienced-threat-modeler. Default
if_no_ai_nodes is continue_without_llm.
Attach this system representation. Load https://aisharedresponsibility.com/tools/prompts/threat-model/prompts.json.
Use pack version 3.0, runtime_defaults, chain_execution, and operator_initial_inputs. Run required Track A from P-context through P-report, then P-export-md, P-export-json, P-export-csv, and P-export-diagram. Fill every later template slot from accumulated JSON. Keep the representation attached when a template includes {{representation}}. Set representation_kind to image, mermaid, or svg. Role: experienced-threat-modeler unless this message names another role.
Treat omitted operator fields as empty and continue. Do not ask for review context, source records, SRF data, or continue. If this message already contains review_context_input, source_manifest, source_records, srf_inputs, or vertical_source_rows, use those values.
Do not skip a step. If a stop_condition fails, record the gap in that step's JSON and continue later steps that can run. When a chain object has repeat_until, rerun that same step with its cumulative prior output until the condition is true, in this same reply.
Do not fetch catalog or SRF data. Use data/threat-sources.json as the named source registry only. An omitted or empty source_manifest makes catalog coverage not_applicable. Track B runs only when this message includes srf_inputs. Track C runs only after Track B when this message includes vertical_ids and vertical_source_rows.
Leave report.reviewer empty.
Do not rephrase Shostack's four questions. Do not put mitigations in P-phantom.
Add review context (optional JSON)
Paste this JSON in the same first message when you have claims the
diagram does not show. Omit keys you do not know. Rewrite names and
labels to match the attached diagram. Role values:
experienced-threat-modeler (default),
application-security, llm-caller.
Profile values: full-system,
bounded-subsystem, artifact-only.
A catalog overlay is a source_manifest object with
pinned entries; omit it to leave catalog coverage not applicable.
{
"role": "application-security",
"if_no_ai_nodes": "continue_without_llm",
"review_context_input": {
"profile": "full-system",
"profile_confirmation": {
"operator_confirmed": false,
"evidence_ref": null
},
"perspective": "Healthcare application team that owns intake, triage workflow, model integration, and clinician review.",
"vertical_ids": [],
"jurisdictions": [],
"operating_model": null,
"critical_assets": [
{
"id": "asset-patient-record",
"name": "patient record",
"diagram_referents": [
"Patient record"
],
"evidence_refs": [
"operator-review-context"
]
},
{
"id": "asset-triage-priority",
"name": "triage priority",
"diagram_referents": [
"Triage queue"
],
"evidence_refs": [
"operator-review-context"
]
}
],
"prohibited_outcomes": [
{
"id": "outcome-no-clinician",
"statement": "Model output must not suppress an urgent case without clinician review.",
"evidence_refs": [
"operator-review-context"
]
}
],
"continuity_safety_constraints": [
{
"id": "constraint-fallback",
"statement": "Urgent intake must route to a clinician when the model path is unavailable.",
"evidence_refs": [
"operator-review-context"
]
}
],
"supplied_severity": null,
"scope": {
"included_labels": [],
"excluded_labels": [
"model-provider training pipeline"
],
"boundary_statement": "Review the drawn clinical application, data stores, and model API call. Do not review provider training."
}
}
}
Artifact-only confirmation. Traditional-phase
not_applicable is allowed only when
profile_confirmation.operator_confirmed is true and
evidence_ref states that integration is out of scope.
{
"review_context_input": {
"profile": "artifact-only",
"profile_confirmation": {
"operator_confirmed": true,
"evidence_ref": "This review covers the model package and model card only. Integration, inference, deployment, identity, retrieval, and tools are out of scope."
},
"perspective": "Assurance team reviewing a model package without a runtime claim.",
"vertical_ids": [],
"jurisdictions": [],
"operating_model": null,
"critical_assets": [],
"prohibited_outcomes": [],
"continuity_safety_constraints": [],
"supplied_severity": null,
"scope": {
"included_labels": [
"model package",
"model card"
],
"excluded_labels": [
"runtime",
"deployment",
"identity",
"retrieval",
"tools"
],
"boundary_statement": "Static artifact inspection only."
}
}
}
Track B: assign SRF accountability
Use this when the first message already includes an operating model
plus the full personas,
matrix, and
threat_crosswalk objects.
Operating model values: AI-SaaS, AI-PaaS,
Agent-PaaS, IaaS.
- Copy the Track B shortcut.
- Open the three files. Copy each file's full JSON object.
- Copy the example below. Replace the three
REPLACE_WITH_FULL_OBJECTstrings with those objects. Keepoperating_modelthe same inreview_context_inputandsrf_inputs. - Paste the shortcut, the representation, and the filled JSON in the same first message.
Attach this system representation. Load https://aisharedresponsibility.com/tools/prompts/threat-model/prompts.json.
Use pack version 3.0, runtime_defaults, chain_execution, and operator_initial_inputs. Run required Track A from P-context through P-qa, then Track B from P-srf-join through P-srf-coverage, then P-report, then P-export-md, P-export-json, P-export-csv, and P-export-diagram. Fill every later template slot from accumulated JSON. Keep the representation attached when a template includes {{representation}}. Set representation_kind to image, mermaid, or svg. Role: experienced-threat-modeler unless this message names another role.
Treat omitted operator fields as empty and continue. Do not ask for review context, source records, SRF data, or continue. Use srf_inputs already in this message. If srf_inputs or operating_model is missing, mark Track B incomplete and continue to P-report. Do not ask.
Do not skip a step. If a stop_condition fails, record the gap in that step's JSON and continue later steps that can run. When a chain object has repeat_until, rerun that same step with its cumulative prior output until the condition is true, in this same reply.
Do not fetch catalog or SRF data. Use data/threat-sources.json as the named source registry only. An omitted or empty source_manifest makes catalog coverage not_applicable. Track C runs only after Track B when this message also includes vertical_ids and vertical_source_rows.
Leave report.reviewer empty.
Do not rephrase Shostack's four questions. Do not put mitigations in P-phantom.
{
"role": "application-security",
"if_no_ai_nodes": "continue_without_llm",
"review_context_input": {
"profile": "full-system",
"profile_confirmation": {
"operator_confirmed": false,
"evidence_ref": null
},
"perspective": "Healthcare application team that owns intake, triage workflow, model integration, and clinician review.",
"vertical_ids": [],
"jurisdictions": [],
"operating_model": "AI-PaaS",
"critical_assets": [
{
"id": "asset-patient-record",
"name": "patient record",
"diagram_referents": [
"Patient record"
],
"evidence_refs": [
"operator-review-context"
]
},
{
"id": "asset-triage-priority",
"name": "triage priority",
"diagram_referents": [
"Triage queue"
],
"evidence_refs": [
"operator-review-context"
]
}
],
"prohibited_outcomes": [
{
"id": "outcome-no-clinician",
"statement": "Model output must not suppress an urgent case without clinician review.",
"evidence_refs": [
"operator-review-context"
]
}
],
"continuity_safety_constraints": [
{
"id": "constraint-fallback",
"statement": "Urgent intake must route to a clinician when the model path is unavailable.",
"evidence_refs": [
"operator-review-context"
]
}
],
"supplied_severity": null,
"scope": {
"included_labels": [],
"excluded_labels": [
"model-provider training pipeline"
],
"boundary_statement": "Review the drawn clinical application, data stores, and model API call. Do not review provider training."
}
},
"srf_inputs": {
"operating_model": "AI-PaaS",
"personas": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/personas.json",
"matrix": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/matrix.json",
"threat_crosswalk": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/threats.json"
}
}
Track C: join vertical obligations
Use this after Track B inputs are in the first message, plus
vertical_ids and vertical_source_rows.
The two rows in the example are reshaped from
healthcare-controls.json.
Copy more rows from that file or the matching vertical file and keep
this object shape. A control candidate is a proposed control.
Vertical ids on this site: healthcare,
finance, public-sector,
insurance, defense,
manufacturing. Jurisdiction ids include
us-federal and eu from
jurisdictions.json.
- Complete the Track B packing steps.
- Set
vertical_idsandjurisdictionsonreview_context_input. - Add obligation and control-candidate rows. Paste shortcut, representation, and the filled JSON in the same first message.
Attach this system representation. Load https://aisharedresponsibility.com/tools/prompts/threat-model/prompts.json.
Use pack version 3.0, runtime_defaults, chain_execution, and operator_initial_inputs. Run required Track A from P-context through P-qa, then Track B from P-srf-join through P-srf-coverage, then Track C from P-vertical-join through P-vertical-route, then P-report, then P-export-md, P-export-json, P-export-csv, and P-export-diagram. Fill every later template slot from accumulated JSON. Keep the representation attached when a template includes {{representation}}. Set representation_kind to image, mermaid, or svg. Role: experienced-threat-modeler unless this message names another role.
Treat omitted operator fields as empty and continue. Do not ask for review context, source records, SRF data, or continue. Use srf_inputs, vertical_ids, and vertical_source_rows already in this message. If Track B cannot close, skip Track C, record the gap, and continue to P-report. Do not ask.
Do not skip a step. If a stop_condition fails, record the gap in that step's JSON and continue later steps that can run. When a chain object has repeat_until, rerun that same step with its cumulative prior output until the condition is true, in this same reply.
Do not fetch catalog or SRF data. Use data/threat-sources.json as the named source registry only. An omitted or empty source_manifest makes catalog coverage not_applicable.
Leave report.reviewer empty.
Do not rephrase Shostack's four questions. Do not put mitigations in P-phantom.
{
"role": "application-security",
"if_no_ai_nodes": "continue_without_llm",
"review_context_input": {
"profile": "full-system",
"profile_confirmation": {
"operator_confirmed": false,
"evidence_ref": null
},
"perspective": "Healthcare application team that owns intake, triage workflow, model integration, and clinician review.",
"vertical_ids": [
"healthcare"
],
"jurisdictions": [
"us-federal"
],
"operating_model": "AI-PaaS",
"critical_assets": [
{
"id": "asset-patient-record",
"name": "patient record",
"diagram_referents": [
"Patient record"
],
"evidence_refs": [
"operator-review-context"
]
},
{
"id": "asset-triage-priority",
"name": "triage priority",
"diagram_referents": [
"Triage queue"
],
"evidence_refs": [
"operator-review-context"
]
}
],
"prohibited_outcomes": [
{
"id": "outcome-no-clinician",
"statement": "Model output must not suppress an urgent case without clinician review.",
"evidence_refs": [
"operator-review-context"
]
}
],
"continuity_safety_constraints": [
{
"id": "constraint-fallback",
"statement": "Urgent intake must route to a clinician when the model path is unavailable.",
"evidence_refs": [
"operator-review-context"
]
}
],
"supplied_severity": null,
"scope": {
"included_labels": [],
"excluded_labels": [
"model-provider training pipeline"
],
"boundary_statement": "Review the drawn clinical application, data stores, and model API call. Do not review provider training."
}
},
"srf_inputs": {
"operating_model": "AI-PaaS",
"personas": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/personas.json",
"matrix": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/matrix.json",
"threat_crosswalk": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/threats.json"
},
"vertical_source_rows": [
{
"source_id": "srf-healthcare-controls",
"vertical_id": "healthcare",
"kind": "obligation",
"id": "SRF-L3-DEV-001",
"title": "Human-in-the-Loop Gate for High-Stakes Outputs",
"statement": "Clinical AI outputs classified as high-risk (diagnosis, treatment selection, medication dosing, procedure recommendation) must be surfaced as advisory only and require explicit clinician confirmation before any downstream action is taken.",
"mandatory": true,
"layer": "L3",
"accountable_persona": "clinical-application-developer",
"canonical_url": "https://aisharedresponsibility.com/data/healthcare-controls.json"
},
{
"source_id": "srf-healthcare-controls",
"vertical_id": "healthcare",
"kind": "control_candidate",
"id": "SRF-L3-VV-002",
"title": "Prompt Injection and Input Manipulation Defense",
"statement": "LLM-based clinical AI tools must implement and validate defenses against prompt injection, jailbreak, and adversarial input manipulation before clinical deployment.",
"mandatory": false,
"layer": "L3",
"accountable_persona": "clinical-application-developer",
"canonical_url": "https://aisharedresponsibility.com/data/healthcare-controls.json"
}
]
}
Run one prompt at a time
Use this when the chat cannot load
prompts.json.
Copy P-context first, then use Copy next. Optional review context, SRF
data, and vertical rows still belong in the first message.
Role values: experienced-threat-modeler, application-security, llm-caller. Default is experienced-threat-modeler.
Copy-one-block text starts with a [chain] line. A chain
run of P-stride repeats in the same reply until its typed denominator
closes. P-importance is required before P-act. After P-report, run the
export steps.
Last copied: none. Next: P-context (Establish review context).
Shostack's Four Questions
- What are we working on?
- What can go wrong?
- What are we going to do about it?
- Did we do a good job?
Wording is from the Four Question Framework (CC-BY). Use those four sentences as written. State the team view and what we are working on right now.
PHANTOM-B questions (LLM subset)
- P Prompt injection: How could someone prompt inject (direct, indirect, multi-stage) through this component?
- H Hallucination: What if hallucinations exceed our hopes in this use of the component?
- A Anthropomorphization: Are we anthropomorphizing this component (treating a token generator as if it had intent, guilt, or a model of user versus attacker)?
- N Non-explainability: When must we explain or justify this component's output, and to whom? The model's own story is not an explanation.
- T Training issues: What if training data is bad by accident or on purpose, and how does that show up at this call site?
- O Over-reliance: What decisions does this LLM make, what control does it have, and does that expand the attack surface?
- M Missing security engineering: Did we skip the rest of security engineering and the SDL around this LLM (authn, authz, logging, isolation, least privilege)?
- B Biases: What biases does this model carry into this use case, and are they acceptable here?
Ask these eight questions for each eligible AI node after traditional applicability closes. Write mitigations in P-act.
Roles
- Experienced threat modeler (experienced-threat-modeler). Enumerate concrete scenarios a builder could act on this sprint. Prefer data-flow and trust-boundary analysis over catalogs. When a STRIDE letter does not apply to an element, say so and give a reason. Notices first: entry points, trust-boundary crossings, high-value stores, and controls whose shown coverage is uncertain; low-prerequisite attack paths available from an adversary position already recorded in the matrix. Declines to infer: provider capacity, undocumented controls, or business impact that the diagram and prior matrix do not show; likelihood or residual-risk scores when the input supplies no evidence for them.
- Application security (application-security). Focus on entry points, authn/authz, input mediation, session handling, and control points the application team can change. Keep a provider-owned infrastructure threat in scope only when the diagram shows it and the application team must demand evidence. Notices first: public inputs that can bypass, disable, or choose whether a drawn filter runs; authorization decisions, session boundaries, parser transitions, and application-owned control points. Declines to infer: provider DDoS capacity, datacenter controls, or model-training controls that are not shown; a provider-owned remediation when the application team can only require an attestation.
- LLM caller (llm-caller). Focus on prompt construction, tool and retrieval inputs, over-reliance, and what the model is allowed to decide. Do not assume you can retrain the base model. Notices first: where untrusted content enters prompt assembly, retrieval, tools, memory, or model output handling; decisions or actions delegated to model output without a drawn approval or policy control. Declines to infer: base-model retraining, provider internals, or training-data facts that are not shown; model intent, consciousness, guilt, or a provider guarantee not present in the diagram.
Sources
- Adam Shostack, The Four Question Framework for Threat Modeling (CC-BY).
- Adam Shostack, PHANTOM-B: A STRIDE Analog for LLMs (CC-BY).
- Crossman et al., Auspex (arXiv:2503.09586). Two-stage chain, cumulative prompt fill, threat matrix, SME evaluation. The prompts here are rebuilt from the paper's published figures. JPMC's withheld tradecraft text is not in this pack.
- IETF RFC 6819. Attack assumptions and existing features are stated before new threats. Do not copy its OAuth threat list onto an unrelated diagram.
- CoSAI SRF accountability data: threats.json, personas.json, matrix.json.
- External source registry: threat-sources.json. A run records the exact source versions and hashes in
source_manifest.
What each track records
Track A records review context, the full inventory, traditional and AI applicability, composition paths, threats, actions, and source provenance. Track B assigns one SRF layer, persona, and party. Track C adds source-bound obligations, control candidates, and acceptance authority. A catalog entry needs an inventory referent and evidence before it can attach to a threat.
Q1. What are we working on?
Set the review profile and claim boundary, then read the whole representation into a structured inventory.
[chain] This prompt is P-context (Establish review context). Next prompt: P-norm (Normalize representation). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-context. Establish the claim boundary before normalizing the representation.
Representation kind: {{representation_kind}}
Representation:
{{representation}}
Operator-supplied review context from the first message (empty object if omitted; do not ask):
{{review_context_input}}
Use the representation and explicit operator statements only. Do not derive jurisdictions, operating model, severity, business criticality, or obligations from a product name. For every claim, record evidence with kind diagram or operator, a concrete reference, and the supported claim. A diagram reference should use its visible label until P-norm supplies stable ids; an operator reference should quote or identify the supplied field. Set unknown nullable values to null and unknown arrays to [].
Profiles:
- full-system: the whole represented AI-enabled system is the review subject.
- bounded-subsystem: named represented elements and interfaces are the review subject; record the operator's boundary.
- artifact-only: only a supplied artifact is reviewed, not its integration. This profile requires explicit operator confirmation. Later traditional-analysis not_applicable decisions are allowed only for this confirmed profile; missing integration evidence is incomplete, not not_applicable.
Return JSON:
{
"review_context": {
"profile": "full-system|bounded-subsystem|artifact-only",
"profile_confirmation": {"operator_confirmed": false, "evidence_ref": "operator evidence ref or null"},
"perspective": "team and review subject",
"vertical_ids": ["operator-supplied vertical or sector ids"],
"jurisdictions": ["operator-supplied jurisdiction ids or names"],
"operating_model": "AI-SaaS|AI-PaaS|Agent-PaaS|IaaS|null",
"critical_assets": [{"id": "asset-...", "name": "", "diagram_referents": ["visible labels until normalized"], "evidence_refs": ["claim id"]}],
"prohibited_outcomes": [{"id": "outcome-...", "statement": "concrete outcome the operator prohibits", "evidence_refs": ["claim id"]}],
"continuity_safety_constraints": [{"id": "constraint-...", "statement": "availability, physical-safety, OT, or continuity constraint", "evidence_refs": ["claim id"]}],
"supplied_severity": {"value": "operator value", "scale": "operator scale", "source": "operator evidence ref"},
"scope": {"included_labels": [], "excluded_labels": [], "boundary_statement": ""},
"claim_evidence": [{"id": "claim-...", "kind": "diagram|operator", "reference": "visible label or supplied field", "supports": "one review-context claim"}]
}
}
Set operating_model and supplied_severity to null when absent. Do not infer severity, likelihood, impact, or residual risk.
[chain] This prompt is P-norm (Normalize representation). Next prompt: P-diag (Decompose diagram). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-norm. Normalize the system representation into a canonical inventory and bind review-context labels to stable ids.
Review context:
{{review_context}}
Representation kind: {{representation_kind}}
Representation follows this line. If kind is mermaid, parse nodes, edges, and subgraphs as candidate trust zones. If kind is svg, parse groups, labels, and connectors. If kind is image, read the image.
{{representation}}
Return a JSON object with this shape:
{
"system_name": "string",
"perspective": "review_context.perspective",
"review_context": "same context with diagram_referents resolved to stable ids and claim evidence retained",
"representation": { "kind": "image|mermaid|svg", "source_id": "filename or unknown", "version": "drawn or labeled version, or unknown", "commit": "commit if labeled, or unknown" },
"inventory": {
"components": [{"id": "kebab-id", "name": "", "type": "process", "replica_of": "canonical component id or null", "replica_evidence": "drawn scaling-group or managed-pair evidence, or empty"}],
"external_actors": [{"id": "", "name": "", "type": "actor"}],
"data_stores": [{"id": "", "name": "", "type": "store"}],
"data_flows": [{"id": "", "from": "id", "to": "id", "label": "", "crosses_boundary": "boundary-id or null"}],
"trust_boundaries": [{"id": "", "name": "", "contains": ["id"]}],
"llm_components": [],
"missing_trust_boundaries": false
}
}
Id rules: lowercase kebab-case, derived from the diagram label. Reuse the same id if the label is the same. Do not merge distinct boxes. Set replica_of only when the representation explicitly groups boxes as configuration copies in one scaling group or managed pair; otherwise use null. A repeated icon or similar name is not enough. Preserve unresolved context references with a claim-evidence gap; do not fabricate a binding.
[chain] This prompt is P-diag (Decompose diagram). Next prompt: P-app (Application details). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-diag. Write a long-form architecture description of the system in the diagram.
Inventory from P-norm:
{{inventory}}
Original representation (kind={{representation_kind}}):
{{representation}}
Write architecture_description that covers:
- every component and how it relates to the others
- system entry points
- data flow
- security boundaries (drawn ones only)
- public vs private resources
- system availability or fault-tolerance properties only if the diagram shows them
- external dependencies
- storage and data security properties only if the diagram shows them
Return JSON:
{
"architecture_description": "prose",
"inventory": <echo the inventory; correct ids only if the diagram contradicts P-norm, and list corrections in a "corrections" array>
}
[chain] This prompt is P-app (Application details). Next prompt: P-feat (Key features). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-app. Condense the architecture description into application details.
Architecture description:
{{architecture_description}}
Return JSON:
{
"application_details": "short prose: function, actors, data the system handles, and the team perspective"
}
[chain] This prompt is P-feat (Key features). Next prompt: P-scope (In-scope components). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-feat. List key features that matter more for threat modeling than the rest of the architecture.
Architecture description:
{{architecture_description}}
Application details:
{{application_details}}
Return JSON:
{
"key_features": ["each item names a diagram element and why it changes the threat surface"]
}
[chain] This prompt is P-scope (In-scope components). Next prompt: P-sol (Solution description). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-scope. Mark which architectural components must be included in threat modeling.
Perspective remains what we are working on right now. Do not pull in an unshown enterprise.
Architecture description:
{{architecture_description}}
Application details:
{{application_details}}
Key features:
{{key_features}}
Inventory:
{{inventory}}
Replica rule:
- Keep every distinct box in inventory.
- Inherit threat coverage only when P-norm set replica_of from explicit scaling-group or managed-pair evidence.
- Map each inherited component, flow, or trust-boundary id to the representative id whose considerations it inherits.
- Require one configuration-divergence scenario for every representative/replica pair. P-dedup later records its threat id.
Return JSON:
{
"in_scope": [{"id": "inventory-id", "rationale": "why this must be modeled"}],
"out_of_scope": [{"id": "inventory-id", "rationale": "why this stays out for this perspective"}],
"replica_coverage": [{
"representative_id": "canonical component id",
"replica_id": "replica component id",
"evidence": "what the diagram shows",
"inherited_element_pairs": [{"representative_id": "component, flow, or boundary id", "replica_id": "matching id"}],
"divergence_gap": "configuration or policy drift scenario that P-stride must consider",
"divergence_threat_id": null
}]
}
[chain] This prompt is P-sol (Solution description). Next prompt: P-adv (Attacker capabilities and claim boundary). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-sol. Combine prior Q1 outputs into a solution description (solS) plus a structured DFD.
Architecture description:
{{architecture_description}}
Application details:
{{application_details}}
Key features:
{{key_features}}
In scope:
{{in_scope}}
Out of scope:
{{out_of_scope}}
Replica coverage:
{{replica_coverage}}
Inventory:
{{inventory}}
Return JSON:
{
"solution_description": "prose of how the architecture functions as a whole",
"inventory": <canonical inventory for all later steps>,
"in_scope": [...],
"out_of_scope": [...],
"replica_coverage": [...]
}
[chain] This prompt is P-adv (Attacker capabilities and claim boundary). Next prompt: P-controls (Existing security features). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-adv. State attacker capabilities and the claim boundary before eliciting threats. This is the RFC 6819 §2.2 shape: assumptions first, then positions. Do not copy OAuth threats.
Inventory:
{{inventory}}
In scope:
{{in_scope}}
Out of scope:
{{out_of_scope}}
Solution description:
{{solution_description}}
Write adversary.assumptions as capabilities someone already has (network position, credentials, ability to send prompts, physical access). Do not invent an attacker who can already do everything.
Write adversary.positions: one row per drawn trust boundary or in-scope zone. Each row needs id, zone (boundary or component id), actor (who is there), and already_can (what they can do from that zone without a new exploit).
Write claim_boundary.does_not_claim: attacks this review will not treat as in play. Tie each item to a reason from the diagram or the named perspective (for example a global passive observer if the diagram is one application, or physical theft of a provider datacenter that is not drawn).
Write claim_boundary.box: the time, access, or component limit of this review (what we are working on right now).
Return JSON:
{
"adversary": {
"assumptions": ["..."],
"positions": [{"id": "pos-internet", "zone": "internet", "actor": "unauthenticated user", "already_can": "send HTTP to the drawn entry point"}]
},
"claim_boundary": {
"does_not_claim": ["..."],
"box": "..."
}
}
[chain] This prompt is P-controls (Existing security features). Next prompt: P-llm-cut (Mark the LLM subset). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-controls. Record security features already visible on the diagram and diagram-visible control gaps before writing threats. This is the RFC 6819 §3 shape: existing features first. Do not invent a control that is not drawn or named.
Solution description:
{{solution_description}}
Inventory:
{{inventory}}
Adversary:
{{adversary}}
Existing-control rules:
- Include authn, TLS, filters, isolation, logging, human approval, network policy, or identity providers only if a label, component, boundary, badge, or flow shows them.
- coverage_referents contains only inventory ids the diagram visibly connects, contains, or labels as protected.
- coverage_basis is connected, contained, label_only, badge_only, or unknown. A badge with no connecting line is badge_only and does not justify broader coverage.
- If no controls are drawn, return an empty existing_controls array and set none_drawn true.
Control-absence rules:
- A control_absence says only that the representation does not show the control at expected_referent. It does not claim the deployed system lacks it.
- expected_referent must be a component, store, flow, or trust-boundary id.
- Use a stable gap-ctl-* id so threat evidence_refs can cite the observation.
Return JSON:
{
"existing_controls": [{
"id": "ctl-...",
"name": "",
"diagram_referent": "inventory id where the control is drawn",
"kind": "authn|tls|filter|isolation|logging|approval|network|identity|other",
"coverage_referents": ["inventory ids visibly protected"],
"coverage_basis": "connected|contained|label_only|badge_only|unknown"
}],
"control_absences": [{
"id": "gap-ctl-...",
"kind": "authn|tls|filter|isolation|logging|approval|network|identity|other",
"expected_referent": "component, store, flow, or trust-boundary id",
"observation": "what the diagram does not show and where"
}],
"none_drawn": false
}
[chain] This prompt is P-llm-cut (Mark the LLM subset). Repeat this prompt until llm_subset_decision.status is ready, continue_without_llm, or needs_operator_confirmation. Only then continue. Next prompt: P-stride (STRIDE elicitation). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we working on?
Step: P-llm-cut. Mark which nodes receive PHANTOM-B. Per Shostack, PHANTOM-B applies to the front end and model runtime, not every box.
Solution description:
{{solution_description}}
Inventory:
{{inventory}}
First-message if_no_ai_nodes (default continue_without_llm):
{{if_no_ai_nodes}}
Include a node if it: assembles or receives prompts, hosts a chatbot, runs an LLM, or calls an LLM endpoint.
Exclude a node if it only stores weights, serves as a generic database, or is a third-party hub that is not executing inference in this diagram.
Empty-subset rule:
- Set llm_subset_empty to true when llm_subset is empty.
- If inventory.llm_components or the diagram shows a prompt, chatbot, model caller, or model runtime, set status possible_miss and correct the subset in this same reply.
- If no AI node is drawn, read if_no_ai_nodes from the first message. Default is continue_without_llm. Do not ask. Do not stop the chain.
- continue_without_llm: status continue_without_llm. PHANTOM-B is not_applicable.
- incomplete: status needs_operator_confirmation with reason citing if_no_ai_nodes from the first message. Continue the chain. PHANTOM-B stays incomplete.
- A non-empty valid subset has status ready.
Return JSON:
{
"llm_subset": ["component-id", "..."],
"llm_subset_empty": false,
"llm_subset_rationale": [{"id": "", "include": true, "reason": ""}],
"llm_subset_decision": {
"status": "ready|possible_miss|needs_operator_confirmation|continue_without_llm",
"reason": ""
}
}
Q2. What can go wrong?
Complete typed STRIDE and conditional abuse and operational passes before PHANTOM-B. Then test AI-to-traditional paths and pinned source mappings.
[chain] This prompt is P-stride (STRIDE elicitation). Repeat this prompt until stride_coverage.complete is true or traditional_coverage.status is not_applicable. Only then continue. Next prompt: P-abuse (Abuse-case analysis). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
{{role_guidance}}
Cyber role: {{cyber_role}}
Shostack question: What can go wrong?
Step: P-stride. Apply typed STRIDE to all applicable in-scope elements in cumulative, auditable batches.
Typed applicability:
- process: S, T, R, I, D, E
- actor: S, R
- store: T, R, I, D
- flow: T, I, D
- trust boundary: no direct letter rows; cover it through every crossing flow and drawn control reaching that crossing.
Root traditional_coverage is the reusable traditional-phase gate. It always has status, expected_referents, considered_referents, exclusions, operator_confirmation, and gaps. status is incomplete after STRIDE while later traditional phases remain, unless the entire traditional phase is operator-confirmed not_applicable for artifact-only. Missing architecture, integration, typing, crossing-flow, or control evidence creates gaps and incomplete status.
Expected scope includes every in-scope applicable process, actor, store, and flow, not only crossings. Exclude an inherited replica only with valid drawn replica evidence and id pairs. traditional_coverage.expected_referents contains the full traditional-analysis denominator; considered_referents records only referents completed so far; exclusions records referent and reason.
Cumulative budget:
- Add at most 72 new rows per P-stride pass. On a chain run, immediately rerun this step in the same reply with the cumulative prior output until stride_coverage.complete is true or traditional_coverage.status is not_applicable. Do not wait for another operator message. Copy-one-block runs one pass per pasted prompt.
- stride_coverage.expected_considerations is an array of {element_id, element_type, letters}; rows_expected is the sum of its letters plus required divergence rows.
- expected_elements, considered_elements, and remaining_elements are id arrays. rows_written_total counts cumulative unique element_id/letter pairs plus divergence rows. Never reduce scope for budget.
For each letter, record scenario or not_applicable with reason. Use inventory referents, adversary position ids, and claim or visible-gap evidence. Preserve one configuration-divergence scenario per replica pair.
Review context:
{{review_context}}
Solution description:
{{solution_description}}
Inventory:
{{inventory}}
In scope:
{{in_scope}}
Replica coverage:
{{replica_coverage}}
Adversary:
{{adversary}}
Existing controls:
{{existing_controls}}
Control absences:
{{control_absences}}
Claim boundary:
{{claim_boundary}}
Prior cumulative STRIDE considerations:
{{prior_stride_considerations}}
Return JSON:
{
"stride_considerations": [{"element_id": "inventory id", "element_type": "process|actor|store|flow", "letter": "S|T|R|I|D|E", "status": "scenario|not_applicable", "scenario": "concrete scenario or empty", "reason": "required for not_applicable", "diagram_referent": "inventory id", "preconditions": "evidence-bound conditions", "evidence_refs": ["claim or gap ids"], "attacker_position": "pos-id", "asset": "asset id or concrete asset"}],
"stride_coverage": {
"budget_rows": 72,
"expected_considerations": [{"element_id": "inventory id", "element_type": "process|actor|store|flow", "letters": ["S"]}],
"expected_elements": ["inventory ids"],
"considered_elements": ["completed ids"],
"remaining_elements": ["ids"],
"rows_expected": 0,
"rows_written_total": 0,
"complete": false,
"boundary_coverage": [{"boundary_id": "", "crossing_flow_ids": [], "control_ids": [], "status": "covered|incomplete"}]
},
"traditional_coverage": {"status": "complete|incomplete|not_applicable", "expected_referents": [], "considered_referents": [], "exclusions": [{"referent": "inventory id", "reason": ""}], "operator_confirmation": null, "gaps": []},
"traditional_analysis": {"stride": {"status": "complete|incomplete|not_applicable", "reason": ""}}
}
[chain] This prompt is P-abuse (Abuse-case analysis). Next prompt: P-operational (Operational and continuity analysis). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What can go wrong?
Step: P-abuse. Examine business and authorization behavior that typed STRIDE does not fully express. Do not proceed until stride_coverage.complete is true or root traditional_coverage is operator-confirmed not_applicable.
Identify diagram- or operator-evidenced high-value transactions, authorization decisions, and delegated actions. For each, consider permitted-actor misuse, decision bypass, transaction replay or alteration, confused-deputy behavior, and action beyond delegated scope. Keep concrete scenarios only.
abuse_coverage uses the reusable phase fields status, expected_referents, considered_referents, exclusions, operator_confirmation, and gaps. Extra expected_subjects is allowed. Set complete when every expected referent is considered; not_applicable only with grounded evidence and any required artifact-only operator confirmation; missing integration is incomplete. Preserve and update root traditional_coverage but do not mark it complete before operational analysis finishes.
Review context:
{{review_context}}
Inventory:
{{inventory}}
Solution description:
{{solution_description}}
Adversary:
{{adversary}}
Existing controls:
{{existing_controls}}
Control absences:
{{control_absences}}
STRIDE coverage:
{{stride_coverage}}
Root traditional coverage:
{{traditional_coverage}}
Traditional detail:
{{traditional_analysis}}
Return JSON:
{
"abuse_considerations": [{"id": "abuse-...", "kind": "high-value-transaction|authorization-decision|delegated-action", "referents": ["inventory ids"], "diagram_referent": "inventory id", "status": "scenario|not_applicable", "scenario": "concrete misuse or empty", "reason": "required when not_applicable", "attacker_position": "pos-id", "preconditions": "", "asset": "", "evidence_refs": ["claim or gap ids"]}],
"abuse_coverage": {"status": "complete|incomplete|not_applicable", "expected_referents": [], "considered_referents": [], "exclusions": [{"referent": "inventory id", "reason": ""}], "operator_confirmation": null, "gaps": [], "expected_subjects": [{"id": "abuse-...", "kind": "high-value-transaction|authorization-decision|delegated-action", "referents": []}]},
"traditional_coverage": {"status": "incomplete|not_applicable", "expected_referents": [], "considered_referents": [], "exclusions": [], "operator_confirmation": null, "gaps": []},
"traditional_analysis": {"stride": "preserve prior object", "abuse_case": {"status": "complete|incomplete|not_applicable", "reason": ""}}
}
[chain] This prompt is P-operational (Operational and continuity analysis). Next prompt: P-phantom (PHANTOM-B elicitation). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What can go wrong?
Step: P-operational. Consider operational sources when availability, physical safety, operational technology, or continuity is relevant.
Use NIST source classes as prompts, not claims: adversarial, accidental, structural, environmental. Tie each relevant class to represented processes, stores, flows, dependencies, and continuity_safety_constraints. Do not invent exposure, safety effects, OT links, capacity, recovery objectives, or provider behavior.
operational_coverage uses status, expected_referents, considered_referents, exclusions, operator_confirmation, and gaps. Extra source-class fields are allowed. complete requires every expected referent and relevant class; not_applicable requires grounded evidence, with operator confirmation when the artifact-only rule applies; missing dependencies or integration means incomplete.
Every scenario uses an id from adversary.positions. For accidental, structural, or environmental events, use the recorded position for the initiating actor or affected system zone and explain the non-adversarial precondition. If no existing position can represent it, record a gap and status incomplete rather than inventing an id.
This step finalizes root traditional_coverage by merging typed STRIDE, abuse, and operational denominators. All downstream gates use traditional_coverage, not traditional_analysis. traditional_coverage.status is complete when required phases are complete or locally justified not_applicable; it is not_applicable only for an operator-confirmed artifact-only review in which traditional integration analysis is confirmed unnecessary. Any unresolved integration is incomplete.
Review context:
{{review_context}}
Inventory:
{{inventory}}
Solution description:
{{solution_description}}
Adversary:
{{adversary}}
Existing controls:
{{existing_controls}}
Control absences:
{{control_absences}}
Incoming traditional coverage:
{{traditional_coverage}}
Abuse coverage:
{{abuse_coverage}}
Traditional detail:
{{traditional_analysis}}
Return JSON:
{
"operational_considerations": [{"id": "operational-...", "source_class": "adversarial|accidental|structural|environmental", "status": "scenario|not_applicable", "scenario": "concrete operational failure or empty", "reason": "required when not_applicable", "diagram_referent": "inventory id", "referents": ["inventory ids"], "attacker_position": "existing pos-id for initiating actor or affected zone", "preconditions": "", "asset": "", "constraint_ids": [], "evidence_refs": ["claim or gap ids"]}],
"operational_coverage": {"status": "complete|incomplete|not_applicable", "expected_referents": [], "considered_referents": [], "exclusions": [{"referent": "inventory id", "reason": ""}], "operator_confirmation": null, "gaps": [], "triggered_by": ["availability|physical-safety|ot|continuity"], "expected_source_classes": [], "considered_source_classes": [], "remaining_source_classes": []},
"traditional_coverage": {"status": "complete|incomplete|not_applicable", "expected_referents": [], "considered_referents": [], "exclusions": [{"referent": "inventory id", "reason": ""}], "operator_confirmation": null, "gaps": []},
"traditional_analysis": {"stride": "preserve prior object", "abuse_case": "preserve prior object", "operational": {"status": "complete|incomplete|not_applicable", "reason": ""}}
}
[chain] This prompt is P-phantom (PHANTOM-B elicitation). Next prompt: P-compose (Analyze AI and traditional composition). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
{{role_guidance}}
Cyber role: {{cyber_role}}
Shostack question: What can go wrong?
Step: P-phantom. Run PHANTOM-B only after root traditional_coverage.status is complete or not_applicable. If it is incomplete, return phantom_coverage.status incomplete with a gate gap and do not elicit AI scenarios. traditional_analysis is detail only and never controls this gate.
For each LLM or chatbot component, ask all eight questions and leave defenses for P-act. If llm_subset_empty is true and llm_subset_decision.status is continue_without_llm, return no considerations and status not_applicable. If the empty subset was recorded as a first-message incomplete gap, return no considerations and status incomplete. Do not ask for confirmation.
Ask, for each id in llm_subset:
1. P Prompt injection: How could someone prompt inject (direct, indirect, multi-stage) through this component?
2. H Hallucination: What if hallucinations exceed our hopes?
3. A Anthropomorphization: Are we anthropomorphizing?
4. N Non-explainability: When must we explain or justify the output, and to whom?
5. T Training issues: What if training data is bad by accident or on purpose?
6. O Over-reliance: What decisions is the LLM making, and does that expand the attack surface?
7. M Missing security engineering: Did we skip the rest of the SDL around this component?
8. B Biases: What biases does the model have, and are they acceptable in this use case?
Use adversary position ids and claim, diagram, or control-gap evidence. Do not infer training facts or model internals.
Review context:
{{review_context}}
Solution description:
{{solution_description}}
Inventory:
{{inventory}}
LLM subset and decision:
{{llm_subset}}
{{llm_subset_decision}}
Adversary:
{{adversary}}
Existing controls and visible gaps:
{{existing_controls}}
{{control_absences}}
Root traditional gate:
{{traditional_coverage}}
Traditional detail:
{{traditional_analysis}}
Abuse and operational phase coverage:
{{abuse_coverage}}
{{operational_coverage}}
Return JSON:
{
"phantom_considerations": [{"element_id": "llm component id", "letter": "P|H|A|N|T|O|M|B", "status": "scenario|not_applicable", "scenario": "concrete instance or empty", "reason": "required when not_applicable", "diagram_referent": "element_id", "preconditions": "", "evidence_refs": ["claim or gap ids"], "attacker_position": "pos-id", "asset": ""}],
"phantom_coverage": {"status": "complete|incomplete|not_applicable", "expected_elements": ["llm_subset ids"], "complete_elements": ["ids with all eight letters"], "missing": [{"element_id": "", "letters": ["P"]}], "gate_status": "passed|blocked", "reason": ""}
}
[chain] This prompt is P-compose (Analyze AI and traditional composition). Next prompt: P-catalog (Map evidence-bound external sources). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What can go wrong?
Step: P-compose. Analyze failures where AI behavior meets traditional software, people, data, identity, and actuation. Root traditional_coverage must be complete or not_applicable; traditional_analysis is detail only.
Build expected_paths from represented AI-to-traditional flows, retrieval, identity delegation, tool actuation, output consumption, feedback loops, and shared stores. Each path object is exactly {id, kind, referents}; referents contains at least two inventory ids. For each path, consider identity changes, lost provenance, content becoming instruction, output treated as authorization, excessive side effects, stale feedback, and cross-layer control bypass. Do not repeat isolated STRIDE or PHANTOM-B rows.
composition_coverage uses expected_paths, considered_paths, remaining_paths, and status. considered_paths and remaining_paths contain path ids. complete means every expected path id is considered; not_applicable means the representation and operator scope show no AI/traditional integration path; indicated but underspecified integration is incomplete.
Review context:
{{review_context}}
Inventory:
{{inventory}}
Solution description:
{{solution_description}}
Adversary:
{{adversary}}
Existing controls and visible gaps:
{{existing_controls}}
{{control_absences}}
Root traditional coverage:
{{traditional_coverage}}
Traditional detail:
{{traditional_analysis}}
AI coverage:
{{phantom_coverage}}
Return JSON:
{
"composition_considerations": [{"path_id": "comp-...", "referents": ["inventory-id-a", "inventory-id-b"], "diagram_referent": "primary inventory id", "status": "scenario|not_applicable", "scenario": "cross-layer failure or empty", "reason": "required when not_applicable", "evidence_refs": ["claim or gap ids"]}],
"composition_coverage": {"expected_paths": [{"id": "comp-...", "kind": "ai-traditional-flow|retrieval|identity-delegation|tool-actuation|output-consumption|feedback-loop|shared-store", "referents": ["inventory-id-a", "inventory-id-b"]}], "considered_paths": ["comp-..."], "remaining_paths": [], "status": "complete|incomplete|not_applicable"}
}
[chain] This prompt is P-catalog (Map evidence-bound external sources). Next prompt: P-dedup (Deduplicate and compose threat list). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What can go wrong?
Step: P-catalog. Consume injected source data only; do not fetch URLs. Map an external entry or propose an external-source candidate only when supplied content, system evidence, and a represented failure align.
Injected source manifest:
{{source_manifest}}
Preserve source_manifest exactly as {source_set_id, entries:[{source_id, source_kind, canonical_url, license_id, integration_mode, catalog_version, retrieved_at, content_sha256}]}. Optional source documents may be injected separately and do not change this shape. Never invent metadata or content.
Inputs to compare:
Review context: {{review_context}}
Inventory: {{inventory}}
STRIDE: {{stride_scenarios}}
Abuse cases: {{abuse_scenarios}}
Operational: {{operational_scenarios}}
PHANTOM-B: {{phantom_scenarios}}
Composition: {{composition_scenarios}}
Every external_ref retains source_id, external_id, catalog_version, relation exact|narrower|broader|related|supporting, affected_referents, evidence_refs, confidence, and status. status is exactly candidate, mapped, affected, not_affected, or unknown:
- candidate: supplied entry is worth review but is not yet mapped to this system.
- mapped: entry is evidence-bound to represented referents, but applicability or effect is not established.
- affected: supplied evidence establishes that the represented component is affected.
- not_affected: supplied evidence establishes non-applicability, such as a verified non-affected version.
- unknown: evidence is missing, conflicting, or cannot resolve applicability.
For source_id cve or nvd, affected requires applicability_evidence with non-empty, non-unknown supplier, product, version, component_referent, and evidence_refs. component_referent must be in inventory, occur in affected_referents, and be backed by at least one resolving evidence_ref. Product-name similarity, an unknown or ranged-without-resolution version, and CISA KEV presence do not establish affected. Use mapped or unknown until exact applicability is evidenced. A KEV entry may be mapped to an already supplied CVE, but it cannot by itself make the CVE or component affected.
Reject word-only matches. Proposed scenarios require a diagram_referent, preconditions, asset, claim evidence, and a complete external_ref. State only which injected sources were examined.
Return JSON:
{
"source_manifest": {"source_set_id": "preserve supplied id", "entries": [{"source_id": "", "source_kind": "", "canonical_url": "", "license_id": "", "integration_mode": "", "catalog_version": "", "retrieved_at": "", "content_sha256": ""}]},
"catalog_mappings": [{"candidate_ref": "method and row id", "diagram_referent": "inventory id", "external_refs": [{"source_id": "manifest source id", "external_id": "supplied external id", "catalog_version": "manifest catalog version", "relation": "exact", "affected_referents": ["inventory id"], "evidence_refs": ["claim id"], "confidence": 0.0, "status": "mapped"}], "match_evidence": "specific source and system alignment"}],
"catalog_considerations": [{"catalog_candidate_id": "external-...", "source": "external-source", "scenario": "evidence-bound proposed scenario", "diagram_referent": "inventory id", "attacker_position": "pos-id", "preconditions": "", "asset": "", "evidence_refs": ["claim id"], "external_refs": [{"source_id": "manifest source id", "external_id": "supplied external id", "catalog_version": "manifest catalog version", "relation": "supporting", "affected_referents": ["inventory id"], "evidence_refs": ["claim id"], "confidence": 0.0, "status": "candidate"}]}],
"catalog_coverage": {"status": "complete|incomplete|not_applicable", "examined_source_ids": [], "reason": "coverage of injected inputs only; never a completeness claim"}
}
When source_manifest is omitted or entries is empty, set catalog_coverage.status to not_applicable, examined_source_ids to [], reason to no injected sources in the first message, and source_manifest.source_set_id to the supplied id or none-injected. Do not ask for a manifest. When a supplied CVE or NVD record meets the affected contract, include applicability_evidence as {"supplier": "non-unknown supplier", "product": "non-unknown product", "version": "non-unknown exact applicable version", "component_referent": "inventory id", "evidence_refs": ["resolving evidence id"]} and set status affected. Otherwise do not claim affected.
[chain] This prompt is P-dedup (Deduplicate and compose threat list). Next prompt: P-cia (CIA mapping). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What can go wrong?
Step: P-dedup. Consume every scenario set and form one threat list TSS.
If root traditional_coverage, phantom_coverage, composition_coverage, or injected-source coverage is incomplete, omit unbound rows from those sets, keep the gaps for QA, and still form TSS from completed scenario sets. Do not ask for more input. traditional_analysis is detail only.
Inputs:
Perspective: {{perspective}}
Inventory: {{inventory}}
Replica coverage: {{replica_coverage}}
Adversary: {{adversary}}
Root traditional coverage: {{traditional_coverage}}
Traditional detail: {{traditional_analysis}}
STRIDE: {{stride_scenarios}}
{{stride_coverage}}
Abuse cases: {{abuse_scenarios}}
{{abuse_coverage}}
Operational: {{operational_scenarios}}
{{operational_coverage}}
PHANTOM-B: {{phantom_scenarios}}
{{phantom_coverage}}
Composition: {{composition_scenarios}}
{{composition_coverage}}
External-source proposals and mappings: {{catalog_scenarios}}
{{catalog_mappings}}
{{catalog_coverage}}
Source manifest: {{source_manifest}}
Drop not_applicable consideration rows, not coverage records. source and method_sources use only traditional, stride, phantom-b, abuse-case, operational, composition, external-source, vertical, srf, both, kill-chain. External catalog candidates use external-source. Merge only the same failure, referent, preconditions, and asset. Preserve the union of evidence_refs and complete external_refs.
For each external_ref preserve source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status, and applicability_evidence when present. status is candidate, mapped, affected, not_affected, or unknown. Deduplication cannot promote status. If a CVE or NVD ref says affected without non-unknown applicability_evidence supplier, product, version, component_referent, and evidence_refs, change it to unknown, retain the deficient evidence, and add a gap; do not silently preserve affected. Product-name similarity, unknown version, or KEV membership is insufficient. A KEV ref remains separate and cannot establish CVE applicability.
Assign T ids in diagram order, bind replica divergence ids, and initialize required importance without inference; P-importance replaces provisional positions.
Return JSON:
{
"threats": [{"id": "T1", "scenario": "actor or failure, referent, preconditions, asset, and system-specific path", "diagram_referent": "inventory id", "preconditions": "", "evidence_refs": ["claim or gap id"], "external_refs": [{"source_id": "manifest source id", "external_id": "supplied external id", "catalog_version": "manifest catalog version", "relation": "exact", "affected_referents": ["inventory id"], "evidence_refs": ["claim id"], "confidence": 0.0, "status": "mapped"}], "attacker_position": "pos-id", "asset": "", "source": "external-source", "method_sources": ["external-source"], "importance": {"factors": [], "needs_input": ["pending P-importance"], "review_position": 1}, "stride": [], "phantom_b": [], "cia": [], "action": {"type": "accept", "detail": "pending P-act"}}],
"source_manifest": {"source_set_id": "preserved id", "entries": []},
"replica_coverage": ["same rows with divergence_threat_id filled"]
}
A valid affected CVE or NVD external_ref keeps applicability_evidence {"supplier": "non-unknown", "product": "non-unknown", "version": "non-unknown", "component_referent": "inventory id", "evidence_refs": ["resolving evidence id"]}.
Q3. What are we going to do about it?
Map method labels, record evidence-backed importance, and choose one action with a testable control point.
[chain] This prompt is P-cia (CIA mapping). Next prompt: P-stride-map (STRIDE mapping). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we going to do about it?
Step: P-cia. Map each threat scenario to CIA. Multi-label is allowed.
C Confidentiality, I Integrity, A Availability.
Solution description:
{{solution_description}}
Threats:
{{threats}}
Return the same threats array with cia filled. Do not add or drop threats. Do not fill action.
Return JSON:
{ "threats": [ ... ] }
[chain] This prompt is P-stride-map (STRIDE mapping). Next prompt: P-phantom-map (PHANTOM-B mapping). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we going to do about it?
Step: P-stride-map. Map each threat scenario to STRIDE letters. Multi-label is allowed.
Solution description:
{{solution_description}}
Threats:
{{threats}}
Return the same threats array with stride filled. Do not add or drop threats.
Return JSON:
{ "threats": [ ... ] }
[chain] This prompt is P-phantom-map (PHANTOM-B mapping). Next prompt: P-importance (Order threats by evidence-backed importance). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we going to do about it?
Step: P-phantom-map. Attach PHANTOM-B letters only when the scenario was elicited from the LLM subset. Do not force every STRIDE threat into PHANTOM-B.
Letters: P prompt injection, H hallucination, A anthropomorphization, N non-explainability, T training issues, O over-reliance, M missing security engineering, B biases.
LLM subset:
{{llm_subset}}
Threats:
{{threats}}
Return the same threats array with phantom_b filled per the rule above.
Return JSON:
{ "threats": [ ... ] }
[chain] This prompt is P-importance (Order threats by evidence-backed importance). Next prompt: P-act (Choose an action). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we going to do about it?
Step: P-importance. Produce the required builder review order immediately before P-act. This is an evidence index, not a risk score. Root traditional_coverage must not be incomplete.
Review context:
{{review_context}}
Adversary:
{{adversary}}
Traditional, AI, and composition coverage:
{{traditional_coverage}}
{{phantom_coverage}}
{{composition_coverage}}
Threats:
{{threats}}
Allowed factor kinds are attacker_access, critical_asset, prohibited_outcome, control_gap, cross_layer_propagation, mandatory_obligation, active_exploitation, uncertainty. For each threat write importance.factors as {kind, evidence, source}; evidence identifies the supporting claim, gap, coverage row, or external ref, and source identifies its resolvable origin. importance.needs_input lists missing evidence. importance.review_position is unique and 1-based.
External applicability rule:
- Respect external_ref.status candidate, mapped, affected, not_affected, or unknown; do not promote it here.
- A CVE or NVD ref counts as applicable only when status is affected and applicability_evidence has non-unknown supplier, product, version, component_referent, and evidence_refs resolving to the same represented component.
- Product-name similarity, unknown version, or KEV presence cannot establish applicability.
- Add active_exploitation from CISA KEV only when the threat has both a KEV reference for the vulnerability and an applicable CVE or NVD reference for the same component. The factor evidence and source must identify both external refs and the applicability evidence. KEV without that CVE/NVD proof adds no active_exploitation factor; put the missing applicability proof in needs_input instead.
Return review_order rows exactly as {position, threat_id, attacker_position, prerequisite_summary, reason}; position equals importance.review_position. Keep ids, scenarios, refs, methods, and array order unchanged. Never infer likelihood, impact, severity, exploitability, or residual risk.
Return JSON:
{
"threats": [{"id": "T1", "importance": {"factors": [{"kind": "active_exploitation", "evidence": "KEV entry plus affected CVE applicability evidence for this component", "source": "KEV external-ref id and affected CVE/NVD external-ref id"}], "needs_input": [], "review_position": 1}}],
"review_order": [{"position": 1, "threat_id": "T1", "attacker_position": "pos-id", "prerequisite_summary": "recorded access and remaining condition", "reason": "evidence-backed review reason without a risk claim"}]
}
[chain] This prompt is P-act (Choose an action). Next prompt: P-qa (Self-check). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: What are we going to do about it?
Step: P-act. Choose one action per threat after threats[].importance and review_order are complete: mitigate, eliminate, transfer, or accept.
- mitigate: make the scenario harder at a named control point in the representation.
- eliminate: remove the feature or interface creating the scenario.
- transfer: name the represented party better placed to handle it.
- accept: keep the scenario and state the decision basis; do not claim residual risk.
A control_point is an inventory component, store, flow, or trust-boundary id, never a control-gap id. For mitigate or eliminate, validation.kind is test, log, or fail_condition and validation.detail is executable or observable. Transfer and accept may use null validation. External citations may only come from complete threats[].external_refs or source_manifest.
Solution description:
{{solution_description}}
Inventory:
{{inventory}}
Existing controls and visible gaps:
{{existing_controls}}
{{control_absences}}
Review order:
{{review_order}}
Threats with embedded importance:
{{threats}}
Return the same threats and review_order. Preserve each threats[].importance exactly; fill action and validation only:
{"threats": [...], "review_order": [...]}
Q4. Did we do a good job?
Check phase gates, denominators, evidence, and actions. Optional accountability and vertical joins run here before the report.
[chain] This prompt is P-qa (Self-check). Next prompt: P-report (Write the readable report). Optional route before that step: P-srf-join (Join AI Exchange slugs). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: Did we do a good job?
Step: P-qa. Check the combined workflow before human review.
Full threat matrix so far:
{{full_matrix}}
Checks:
1. review_context_grounded: valid profile and confirmation; structured claim objects and claim_evidence remain grounded.
2. traditional_phase_complete: root traditional_coverage is schema-shaped; not_applicable is confirmed artifact-only and missing integration is incomplete. traditional_analysis never gates.
3. stride_considered: recompute typed letters, row counts, cumulative budget, and boundary crossings.
4. abuse_cases_complete and operational_events_complete: reusable phase fields and denominators are accounted for.
5. phantom_b_complete and composition_complete: phase gates, AI letters, composition paths, and nullable completion states are consistent.
6. source_refs_bound: source_manifest is schema-shaped; method_sources uses its enum; every external_ref resolves to the manifest and retains source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is only candidate, mapped, affected, not_affected, unknown.
7. external applicability: every CVE/NVD ref with status affected has applicability_evidence whose supplier, product, version, and component_referent are non-empty and not unknown, whose component is an affected inventory referent, and whose evidence_refs are non-empty and resolve. Product-name similarity, unknown version, or KEV presence never passes this check. Invalid affected refs fail source_refs_bound and are listed in gaps.
8. importance_complete: every threat embeds importance and positions match review_order. Each active_exploitation factor attributed to CISA KEV identifies a KEV ref plus a CVE/NVD ref with valid affected applicability for the same component; KEV alone fails the check.
9. referents, controls, replica inheritance, classifications, attacker positions, action validation, and control points are bound.
10. optional Track B and Track C coverage is valid or null when skipped.
11. report_present is false.
Completion fields are null for a not_applicable phase or skipped optional track, except stride_considered remains boolean. Put every failure in gaps and unresolved claims in open_assumptions.
Return the full matrix unchanged except qa. Required excerpt:
{
"traditional_coverage": {"status": "complete", "expected_referents": [], "considered_referents": [], "exclusions": [], "operator_confirmation": null, "gaps": []},
"stride_coverage": {"budget_rows": 72, "expected_considerations": [], "expected_elements": [], "considered_elements": [], "remaining_elements": [], "rows_expected": 0, "rows_written_total": 0, "complete": true},
"abuse_coverage": {"status": "complete", "expected_referents": [], "considered_referents": [], "exclusions": [], "operator_confirmation": null, "gaps": []},
"operational_coverage": {"status": "complete", "expected_referents": [], "considered_referents": [], "exclusions": [], "operator_confirmation": null, "gaps": []},
"composition_coverage": {"expected_paths": [], "considered_paths": [], "remaining_paths": [], "status": "complete"},
"source_manifest": {"source_set_id": "injected-set-id", "entries": []},
"qa": {"llm_subset_empty": false, "phantom_b_complete": true, "stride_considered": true, "traditional_phase_complete": true, "abuse_cases_complete": true, "operational_events_complete": true, "composition_complete": true, "source_refs_bound": true, "importance_complete": true, "srf_layer_coverage_complete": null, "vertical_join_valid": null, "control_points_bound": true, "report_present": false, "inventory_components_in_solS": true, "boundary_crossings_covered": true, "actions_complete": true, "adversary_stated": true, "existing_controls_listed": true, "control_absences_grounded": true, "claim_boundary_stated": true, "actions_have_validation": true, "attacker_positions_bound": true, "evidence_refs_bound": true, "replica_coverage_complete": true, "review_order_complete": true, "open_assumptions": [], "gaps": []}
}
Preserve optional layer_coverage and vertical_context only when present.
[chain] This prompt is P-report (Write the readable report). Next prompt: P-export-md (Write the downloadable markdown report). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Shostack question: Did we do a good job?
Step: P-report. Finalize after P-qa, P-srf-coverage when Track B ran, or P-vertical-route when Track C ran. Only this step authors report.markdown. P-export-md later copies this string; do not leave a digest for the export to expand.
Full final matrix:
{{full_matrix}}
report.markdown is a readable projection of this matrix, not a summary. A reviewer who never opens the JSON must still see every threat, position, control, and coverage count that the matrix stores.
Echo the incoming matrix. Fill report, chain_meta, and qa.report_present. Do not drop threats, stride_findings, adversary, existing_controls, coverage objects, source_manifest, review_order, or other filled fields. Do not change threat text, classifications, actions, or external applicability status.
Write report.markdown in this order:
1. Title heading. Metadata table: date, method, role, pack version, representation (kind, source_id, version), perspective, empty reviewer.
2. Claim boundary: the box sentence, then a list from claim_boundary.does_not_claim.
3. Attacker: adversary.assumptions as prose, then a table with one row per adversary.positions[] (id, zone or trust boundary, capability).
4. Architecture: the full architecture_description if present, otherwise the full solution_description. Do not compress this to a one-line pipeline. Then trust boundaries, in_scope, and out_of_scope.
5. Existing controls table: one row per existing_controls[] (id, feature, diagram_referent). Then list control_absences[] as diagram limitations, not as proof that a deployed control is missing.
6. Review order table from review_order. This is an evidence index, not a risk score. Include threat id, attacker_position, prerequisite summary, and reason. Do not assign likelihood, impact, severity, or residual risk.
7. Threats grouped by diagram_referent. One heading and one markdown table per referent. One row per threats[] item. Every later row keeps the same columns as the first row. Required columns: ID, Scenario (full stored text), Attacker position, Preconditions, STRIDE, PHANTOM-B, CIA, Method sources, Action (type plus control_point), Validation (kind plus detail), Review position. Add SRF, vertical, and external_ref columns only when those fields are populated on at least one threat. Do not switch later threats to bullet lists. Do not omit STRIDE, CIA, position, or validation on later rows. The number of threat table rows must equal len(threats).
8. External-reference applicability table when any threats[].external_refs exist: source_id, external_id, relation, status, affected_referents, confidence, evidence_refs, applicability_evidence. If none exist, write that catalog mapping is not_applicable and name source_manifest.source_set_id. Call a CVE/NVD affected only when supplier, product, version, component_referent, and evidence_refs are non-unknown and resolve to this system. Product-name-only, unknown-version, and KEV-only matches stay mapped or unknown, never affected.
9. For each active_exploitation factor based on CISA KEV, show both the KEV ref and the valid affected CVE/NVD ref for the same component. If that pair is absent, report the QA gap rather than active exploitation.
10. Coverage using matrix counts, not a checklist of method names: traditional status, STRIDE rows_expected and rows_written_total, abuse and operational status, PHANTOM-B status with complete versus expected AI elements, composition considered_paths versus remaining_paths, optional layer_coverage, optional vertical_context.
11. source_manifest as a table (source_id, source_kind, canonical_url, license_id, integration_mode, catalog_version, retrieved_at, content_sha256). Do not dump the JSON object in a fence. State that injected-source coverage is not a completeness claim.
12. Non-claims from claim_boundary, qa.gaps, qa.open_assumptions, and an empty reviewer line.
Do not shorten later threats to keep the JSON reply short. This step is allowed to be long. Truncating report.markdown so later threat ids disappear fails the stop_condition.
Set qa.report_present true. Preserve source_manifest. Set chain_meta version and null reviewer. Track B requires complete layer_coverage; Track C requires Track B and vertical_context. Omit skipped optional objects.
Return the full incoming matrix plus:
{"report": {"title": "", "markdown": "full document with every threat id", "reviewer": null}, "qa": {"report_present": true}, "chain_meta": {"prompt_pack_version": "3.0", "role": "{{cyber_role}}", "method": "", "date": "", "reviewer": null, "track_b_applied": false, "track_c_applied": false}}
What Track A has filled
P-qa produces the checked Track A matrix. Run optional
Track B and Track C
before P-report, or run P-report
immediately. Then run the export steps and save the
.md, .json, .csv, and
.mmd replies.
Schema:
eval/threat-model/schema.json.
Eval path: <system-id>/image.json (or
mermaid.json / svg.json).
review_context,inventory,solution_description,replica_coverage, andllm_subset_empty.adversary: assumptions and positions (who already sits in which zone).existing_controlswith shown coverage, pluscontrol_absencesfor expected controls not shown at a named referent.claim_boundary: what this review does not claim, plus the time or component box.traditional_coverage, typedstride_coverage,phantom_coverage, andcomposition_coveragerecord method denominators and gaps.source_manifestpins every external source used by a mapping.threats: stable ids with referents, method sources, evidence, external references, importance factors, one action, and validation on mitigate or eliminate.review_orderrecords the review sequence without claiming likelihood, impact, or residual risk.qarecords failed checks. P-report later fillsreport.markdownas a full projection of the matrix: grouped threat tables, every threat/position/control id, architecture prose, and coverage counts. Leavereport.reviewerempty.
Track B and Track C are optional. After the selected tracks, return to
P-report. Then run the export steps and save the
.md, .json, .csv, and
.mmd replies.
Track B (optional): SRF accountability
Use the Track B one-chat shortcut when SRF inputs are in the first message, or copy the blocks below after P-qa. Track B consumes the checked Track A matrix, a supplied operating model, and injected local SRF data. It checks expected L1 to L5 coverage before returning to P-report or Track C.
[chain] This prompt is P-srf-join (Join AI Exchange slugs). Next prompt: P-srf-layer (Assign SRF layer). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Track B is optional and does not create threats.
Step: P-srf-join. Consume injected SRF source data; do not fetch URLs.
Source registry:
{{source_registry}}
Threat crosswalk:
{{threat_crosswalk}}
Full Track A matrix:
{{full_matrix}}
Require review_context.operating_model to be non-null. Verify every used source id and external reference exists in source_registry. Match a threat only when the crosswalk describes the same failure, represented referent, and operating model. Copy mapped layer, affected_layers, persona, and party exactly; record source id, crosswalk id, and external reference. If no entry matches, set matched false and leave assignment fields for later Track B steps. Missing injected inputs or operating model makes Track B incomplete, not a reason to infer values.
Do not invent slugs, layers, personas, parties, or references. Keep every non-SRF field unchanged.
Return the full matrix with review_context.operating_model preserved and threats[].srf.join shaped as {"matched": true, "source_id": "", "crosswalk_id": "", "external_ref": ""}.
[chain] This prompt is P-srf-layer (Assign SRF layer). Next prompt: P-srf-owner (Assign one accountable persona). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Track B. Step: P-srf-layer. Assign the primary SRF layer where the represented control point lives, not where harm appears.
Injected source registry:
{{source_registry}}
Injected matrix:
{{matrix}}
Full matrix:
{{full_matrix}}
Use only layer ids and operating-model mappings present in the injected inputs. Preserve a joined assignment. For an unmatched threat, bind the layer to its diagram referent and proposed control point, then cite the matrix row used. If the source data does not support a layer, leave it unresolved and mark Track B incomplete. Keep every non-SRF field unchanged.
[chain] This prompt is P-srf-owner (Assign one accountable persona). Next prompt: P-srf-coverage (Check SRF layer and owner coverage). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Track B. Step: P-srf-owner. Name one accountable persona and one party per threat from injected data.
Injected personas:
{{personas}}
Injected matrix:
{{matrix}}
Full matrix with joined and layered threats:
{{full_matrix}}
Rules:
- Exactly one accountable persona from personas per threat.
- party is customer or provider, never shared. When matrix assigns shared duties, identify one lead from the represented control point and record the counterparty duty in srf.note with its matrix evidence.
- Preserve source-backed joined assignments.
- If no injected row supports an owner, mark the threat unresolved and Track B incomplete; do not guess.
- Keep every non-SRF field unchanged, including review context, source manifest, coverage, QA, importance, and review_order.
- Do not write report.markdown. P-srf-coverage is next.
Return the full matrix with srf.persona, srf.party, srf.note, and assignment_evidence on every resolved threat.
[chain] This prompt is P-srf-coverage (Check SRF layer and owner coverage). Next prompt: P-report (Write the readable report). Optional route before that step: P-vertical-join (Join vertical obligations). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Track B. Step: P-srf-coverage. Check assignments before optional Track C or P-report. Do not create, delete, or rewrite threats.
Injected source registry:
{{source_registry}}
Injected personas:
{{personas}}
Injected matrix:
{{matrix}}
Full matrix:
{{full_matrix}}
Validate layers against source_registry, personas against personas, operating-model rows against matrix, and party as customer or provider. Derive expected_layers from represented control points and assigned affected layers; use only L1, L2, L3, L4, L5. considered_layers contains layers whose threat assignments and owners were checked. remaining_layers contains expected layers still unresolved. status is complete only when remaining_layers is empty and every threat resolves; otherwise incomplete. Extra threat counts and summaries are allowed.
Write root layer_coverage. Set chain_meta.track_b_applied true only when layer_coverage.status is complete. Keep report.markdown untouched.
Return the full matrix with:
{"layer_coverage": {"status": "complete|incomplete|not_applicable", "expected_layers": ["L1"], "considered_layers": ["L1"], "remaining_layers": [], "threats_total": 0, "assigned_threat_ids": [], "unresolved": [{"threat_id": "", "gap": ""}], "by_persona": {}, "by_party": {}, "source_ids": []}, "chain_meta": {"track_b_applied": false, "track_c_applied": false}}
What Track B has filled
The assistant JSON after P-srf-coverage is the Track A matrix with
srf on every threat and a layer_coverage audit.
chain_meta.track_b_applied is true only when that audit closes.
srf.layer: L1 to L5, the layer where the control point lives.srf.persona: one id from personas.json.srf.party:customerorprovider. Nevershared.srf.join.ai_exchange_slug: a published slug from threats.json, or null.layer_coverage: expected, considered, and remaining SRF layers.
Track B does not add threats. A threat with no matching crosswalk row still needs a source-backed layer, persona, and party. Run Track C when vertical context is supplied, or run P-report next.
Track C (optional): vertical obligations and routing
Use the Track C one-chat shortcut when Track B inputs plus vertical ids and vertical source rows are in the first message, or copy the blocks below after Track B closes. It joins supported vertical and jurisdiction rows to existing threat ids. It cannot add a threat or treat a candidate control as an existing control.
[chain] This prompt is P-vertical-join (Join vertical obligations). Next prompt: P-vertical-route (Route vertical acceptance authority). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Track C is optional and may run only after layer_coverage.status is complete, review_context.vertical_ids is non-empty, review_context.operating_model is non-null, and injected threat_crosswalk is available. It never creates threats.
Step: P-vertical-join.
Source registry:
{{source_registry}}
Threat crosswalk:
{{threat_crosswalk}}
Full Track B matrix:
{{full_matrix}}
For each existing threat, match only crosswalk rows for review_context.vertical_ids, jurisdictions, operating_model, scenario, and represented referent. Add vertical.obligations and vertical.control_candidates with supplied source metadata, applicability evidence, and the exact threat id. A control candidate is proposed, not existing. An obligation is mandatory only when injected evidence says so. Unmatched threats get empty arrays. Preserve threat count, ids, scenarios, and non-vertical fields.
Return the full matrix with threats[].vertical and vertical_context {"vertical_ids": [], "jurisdictions": [], "operating_model": null, "source_ids": [], "status": "complete|incomplete"}. Preserve root layer_coverage.
[chain] This prompt is P-vertical-route (Route vertical acceptance authority). Next prompt: P-report (Write the readable report). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Track C. Step: P-vertical-route. Add acceptance authority and control ownership to already joined vertical context. Do not create threats or change scenarios, importance, actions, or SRF assignments.
Source registry:
{{source_registry}}
Personas:
{{personas}}
Matrix:
{{matrix}}
Full matrix:
{{full_matrix}}
For each vertical obligation and control candidate, name the accountable persona, party, decision or evidence needed, and source row. For action.type accept, add acceptance_authority only when the injected vertical source or matrix identifies that authority for the applicable jurisdiction and operating model. If authority is not supported, set it null and add an unresolved gap; never nominate an executive, regulator, provider, or customer from general knowledge. Set chain_meta.track_c_applied true only when vertical_context.status is complete and all mandatory obligation routes resolve. Preserve every non-vertical field and do not write report.markdown.
Return the full matrix with vertical routing, vertical_context coverage, and chain_meta.track_c_applied.
What Track C has filled
- Applicable obligation citations from injected regulation or crosswalk rows.
- Candidate controls kept separate from diagram-visible existing controls.
- One accountable persona and acceptance authority when the source data identifies them.
- Unresolved authority or applicability gaps instead of guessed assignments.
Export the report, JSON, CSV, and diagram
These four prompts run once after P-report.
P-export-md emits the stored report without rewriting it (.md).
That stored report projects the matrix: every threat id appears as a
table row grouped by diagram referent.
P-export-json writes the completed record (.json).
P-export-csv writes one row per threat with stable SRF columns. Track A leaves
those cells empty (.csv).
P-export-diagram writes a Mermaid data-flow of the inventory with threat
ids on their referents (.mmd). It uses only inventory ids.
Leave the reviewer line empty.
[chain] This prompt is P-export-md (Write the downloadable markdown report). Next prompt: P-export-json (Write the completed JSON file). Do not echo this line in the markdown.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
This step writes the downloadable report. P-report already authored the document.
Step: P-export-md. Output full_matrix.report.markdown exactly as stored, starting at its title heading. Do not revise, regenerate, summarize, or add sections. Do not wrap it in a JSON object or markdown fences. Do not echo the chain banner.
Completed matrix:
{{full_matrix}}
If report.markdown is missing or empty, stop and say P-report must run first. If any threats[].id, adversary.positions[].id, or existing_controls[].id is absent from report.markdown, stop and say P-report must rewrite the projection. Do not reconstruct the document in this export step.
[chain] This prompt is P-export-json (Write the completed JSON file). Next prompt: P-export-csv (Write the threat-database CSV). Do not echo this line in the JSON.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
Step: P-export-json. Serialize the completed threat-model JSON. Output JSON only, pretty-printed with two-space indent.
Completed matrix:
{{full_matrix}}
Keep every field and value and preserve report.markdown byte for byte. Require the completed phase, QA, importance, action, source_manifest, and optional-track contracts. Every external_ref.status must be candidate, mapped, affected, not_affected, or unknown. Reject serialization when a CVE/NVD ref is affected without non-unknown applicability_evidence supplier, product, version, component_referent, and resolving evidence_refs. Product-name similarity, unknown version, or KEV presence is not affected evidence. Reject an active_exploitation factor attributed to CISA KEV unless a valid affected CVE/NVD ref for the same component is present and both refs are cited by the factor. This is serialization, so do not repair, promote, or demote statuses here; stop with the failed invariant.
When Track B is applied require layer_coverage.status complete. When Track C is applied require Track B and vertical_context. Return the complete matrix.
[chain] This prompt is P-export-csv (Write the threat-database CSV). Next prompt: P-export-diagram (Write the Mermaid threat-model diagram). Do not echo this line in the CSV.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
This step writes the threat database. Output CSV only, starting at the header row, with no fences.
Step: P-export-csv. Flatten completed threats[] after P-report. The v3 header is stable across Tracks A, B, and C; absent optional values use empty cells.
Full matrix:
{{full_matrix}}
Header, exactly these columns in this order:
system_name,review_profile,vertical_ids,jurisdictions,operating_model,traditional_status,stride_complete,stride_expected_considerations,stride_rows_written,abuse_status,operational_status,phantom_status,composition_status,source_set_id,source_manifest_ids,layer_coverage_status,vertical_context_status,threat_id,review_position,importance_factor_kinds,importance_evidence,importance_sources,importance_needs_input,scenario,diagram_referent,attacker_position,preconditions,evidence_refs,external_refs,external_ref_statuses,external_ref_applicability_evidence,asset,source,method_sources,stride,phantom_b,cia,action_type,action_detail,control_point,validation_kind,validation_detail,owasp_llm_top10,ai_exchange_slug,atlas,srf_layer,srf_persona,srf_party,srf_note,vertical_obligations,vertical_control_candidates,acceptance_authority
Row rules:
- One row per threat. Repeat system, review-context, coverage, manifest, and optional-track fields.
- review_position is threats[].importance.review_position and matches review_order. Join importance kinds, evidence, sources, and needs_input separately with a pipe.
- Serialize each external_ref as source_id:external_id:catalog_version:relation:affected_referents:evidence_refs:confidence:status; join refs with a double pipe. external_ref_statuses lists candidate, mapped, affected, not_affected, or unknown in the same order.
- external_ref_applicability_evidence serializes supplier:product:version:component_referent:evidence_refs for each ref, with an empty segment when absent, preserving the same double-pipe order.
- Stop rather than emit CSV if a CVE/NVD affected ref lacks non-unknown complete applicability evidence, or if KEV-based active_exploitation lacks a valid affected CVE/NVD for the same component. Product similarity, unknown version, and KEV presence do not establish affected.
- Join other array fields with a pipe. Action, validation, SRF, and vertical fields come from the matrix without inference.
- Use RFC 4180 UTF-8 CSV: quote fields containing comma, quote, CR, or LF and double embedded quotes. Missing values are empty, never null.
[chain] This prompt is P-export-diagram (Write the Mermaid threat-model diagram). Export ends here. Save the markdown, JSON, CSV, and this Mermaid reply as a .mmd file. Do not echo this line in the Mermaid.
You are producing a threat model for an AI-enabled system from a system representation (image, Mermaid, or SVG) and the operator fields supplied in the first message.
Run mode:
- If the operator asked to run Track A through P-report, asked to run Track B or Track C, or named this pack chain, this is a chain run. Execute every required step in order in this conversation, including selected optional tracks after P-qa and before P-report. After a step meets its stop_condition, immediately produce the next chain id. Repeat_until steps rerun in this same reply until the condition is true. Do not ask a question. Do not request continue. Do not request a field listed in operator_initial_inputs. Do not write that you will proceed to a step without producing that step's output.
- If this message contains a single [chain] banner, produce only that named step.
Missing first-message fields are empty (null, false, or []). Optional catalog, SRF, and vertical mapping without injected data are not_applicable. Incomplete is for partial supplied data or missing diagram evidence. If a stop_condition fails, record the gap in that step's JSON. Do not ask the operator for more information. Continue later steps that can run; leave blocked coverage incomplete. Stop the remaining chain only when a required inventory cannot be built from the representation.
For a chain run, emit a prompt-id heading, then that step's JSON or export payload, then the next step. No other commentary. Copy-one-block JSON steps output JSON only, with no markdown fences. Export steps output only the requested markdown, CSV, or Mermaid source.
Rules:
- Use Shostack's Four Questions in this exact wording: What are we working on? What can go wrong? What are we going to do about it? Did we do a good job?
- Keep the review profile and team perspective explicit.
- Ground claims in diagram element ids or operator-supplied evidence. Label an unsupported claim as unknown; do not invent components, vendors, networks, trust boundaries, jurisdictions, operating models, assets, obligations, controls, or business consequences.
- If trust boundaries are missing from the diagram, set inventory.missing_trust_boundaries to true and record that finding. Do not add boundaries silently.
- Every scenario must name a diagram_referent whose id exists in the inventory and retain claim or source evidence.
- A catalog entry without a system referent and evidence is not a scenario.
- Do not use DREAD, OCTAVE, attack trees, likelihood, impact, severity, or residual risk as inferred scoring methods. Preserve supplied_severity only as an attributed operator input.
- PHANTOM-B applies to the AI subset after traditional-analysis gates. Do not force a traditional scenario into a PHANTOM-B letter or put defenses in PHANTOM-B elicitation.
- Do not invent external identifiers. Use only identifiers and URLs present in the injected source_manifest, source_registry, personas, matrix, or threat_crosswalk inputs.
- Every external_ref keeps the schema fields source_id, external_id, catalog_version, relation, affected_referents, evidence_refs, confidence, status. status is candidate, mapped, affected, not_affected, or unknown.
- A CVE or NVD reference may be affected only when applicability_evidence supplies non-unknown supplier, product, version, component_referent, and at least one resolving evidence_ref. Product-name similarity, unknown version, or CISA KEV presence cannot establish affected status.
- CISA KEV may support an active_exploitation importance factor only after a CVE or NVD reference is validly affected for the same component. KEV presence alone cannot establish applicability or active exploitation for this system.
- There is no network fetching in this pack. An omitted or empty source_manifest, srf_inputs, or vertical_source_rows object is not_applicable for that mapping. Partial injected data that cannot be bound is incomplete.
- Once adversary.positions exists, every scenario must use one of those position ids.
- Record an existing control only when a label, component, or flow on the diagram shows it.
- For mitigate or eliminate, action.validation needs kind test, log, or fail_condition and concrete detail a reviewer can execute or observe.
- Leave report.reviewer empty. A human fills it.
This step writes Mermaid flowchart source only, with no fences.
Step: P-export-diagram. Project the completed matrix after P-report. Do not replace or reinterpret the source representation.
Full matrix:
{{full_matrix}}
Required shape:
1. Start with comments for system_name; review profile, vertical ids, jurisdictions, and operating model; traditional, PHANTOM-B, and composition coverage statuses; source_manifest source ids; optional SRF and vertical coverage.
2. Then flowchart LR, or TB only when LR does not fit.
3. One subgraph per drawn trust boundary with only contains[] members inside.
4. One node per component, external actor, and store. Replace hyphens only in Mermaid syntax ids. Labels show inventory name and threat ids.
5. Stores use cylinder shape.
6. One edge per data flow; append threat ids for threats on that flow.
7. classDef llm applies to llm_subset. classDef drawnControl applies only to shown control coverage; do not add control nodes.
8. When missing_trust_boundaries is true, add its comment and draw no invented subgraphs.
9. Add replica coverage comments and preserve every replica node.
10. After the graph, one legend comment per threat with referent, method_sources, STRIDE, action, review position, importance factor kinds, external reference ids, and optional vertical obligation ids.
Use only inventory ids and existing threat ids. Include each inventory node, flow, and threat exactly once on its referent. Do not draw attacker, threat, action, control-gap, obligation, or proposed-control nodes. If a referent is invalid, omit its annotation and add a gap comment.
Evaluation baselines
P-zeroshot and P-identity are the two short baselines scored in
eval/threat-model/. Machine scores stay open until the SME sheets
in that directory are filled.
[chain] This prompt is P-zeroshot (Zero-shot threat model). This prompt is not in the default chain. Do not echo this line in the JSON.
Threat model this AI-enabled system representation. Representation kind: {{representation_kind}}.
Operator review context:
{{review_context_input}}
Injected source manifest:
{{source_manifest}}
Representation:
{{representation}}
Return schema-compatible JSON with structured review_context claims and claim_evidence; inventory and solution description; root traditional_coverage; typed stride_considerations and stride_coverage; reusable abuse_coverage and operational_coverage; PHANTOM-B coverage; composition_considerations plus expected_paths, considered_paths, remaining_paths, status; source_manifest shaped as source_set_id and metadata entries; threats with schema-enum method_sources, complete external_refs, embedded importance {factors,needs_input,review_position}, actions; matching review_order; and required QA fields. Ground every claim. Do not infer likelihood, impact, severity, or residual risk.
[chain] This prompt is P-identity (Short expert identity). This prompt is not in the default chain. Do not echo this line in the JSON.
You are an experienced threat modeler. For this AI-enabled system representation (kind={{representation_kind}}), use operator context, typed STRIDE, AI-specific questions, and composition paths.
Context: {{review_context_input}}
Representation: {{representation}}
Return review_context with claim evidence, root traditional_coverage, typed phase coverage, evidence-bound threats with schema-shaped external_refs and embedded importance, matching review_order, actions, and required QA fields. Preserve supplied severity as attributed input but do not infer likelihood, impact, severity, or residual risk.
Output schema
Full JSON Schema: eval/threat-model/schema.json.
Gold diagrams and bounded workflow fixtures are in
eval/threat-model/ of the site repository.