Tools / System Instructions / Threat modeling / Pack v3.0

AI-enabled system threat modeling

Attach a system representation (image, Mermaid, or SVG) and run one chat. The pack writes a threat matrix and four export replies: .md, .json, .csv, and .mmd. Start with Track A. Open Track B to assign one SRF layer, persona, and party. Open Track C after Track B to join vertical obligations. Templates: prompts.json. Release notes. Evaluation method and fixtures.

Prompt injection warning Always review prompts before referencing or copying them into an assistant, agent, or production system.

On this page

Start here: one chat

  1. Attach the representation and set representation_kind to image, mermaid, or svg.
  2. Copy the Track A shortcut. Send it once with the representation.
  3. Save the four export replies as .md, .json, .csv, and .mmd.

The model loads prompts.json and runs Track A through the four exports. Omitted fields stay empty. Catalog, SRF, and vertical mapping without injected data are not applicable. Optional JSON stays on this page; it is not in the copied shortcut. If the chat cannot load that file, use Run one prompt at a time.

Track A

Default path. Representation and representation_kind are enough. Default role is experienced-threat-modeler. Default if_no_ai_nodes is continue_without_llm.

Attach this system representation. Load https://aisharedresponsibility.com/tools/prompts/threat-model/prompts.json.

Use pack version 3.0, runtime_defaults, chain_execution, and operator_initial_inputs. Run required Track A from P-context through P-report, then P-export-md, P-export-json, P-export-csv, and P-export-diagram. Fill every later template slot from accumulated JSON. Keep the representation attached when a template includes {{representation}}. Set representation_kind to image, mermaid, or svg. Role: experienced-threat-modeler unless this message names another role.

Treat omitted operator fields as empty and continue. Do not ask for review context, source records, SRF data, or continue. If this message already contains review_context_input, source_manifest, source_records, srf_inputs, or vertical_source_rows, use those values.

Do not skip a step. If a stop_condition fails, record the gap in that step's JSON and continue later steps that can run. When a chain object has repeat_until, rerun that same step with its cumulative prior output until the condition is true, in this same reply.

Do not fetch catalog or SRF data. Use data/threat-sources.json as the named source registry only. An omitted or empty source_manifest makes catalog coverage not_applicable. Track B runs only when this message includes srf_inputs. Track C runs only after Track B when this message includes vertical_ids and vertical_source_rows.

Leave report.reviewer empty.
Do not rephrase Shostack's four questions. Do not put mitigations in P-phantom.
Add review context (optional JSON)

Paste this JSON in the same first message when you have claims the diagram does not show. Omit keys you do not know. Rewrite names and labels to match the attached diagram. Role values: experienced-threat-modeler (default), application-security, llm-caller. Profile values: full-system, bounded-subsystem, artifact-only. A catalog overlay is a source_manifest object with pinned entries; omit it to leave catalog coverage not applicable.

{
  "role": "application-security",
  "if_no_ai_nodes": "continue_without_llm",
  "review_context_input": {
    "profile": "full-system",
    "profile_confirmation": {
      "operator_confirmed": false,
      "evidence_ref": null
    },
    "perspective": "Healthcare application team that owns intake, triage workflow, model integration, and clinician review.",
    "vertical_ids": [],
    "jurisdictions": [],
    "operating_model": null,
    "critical_assets": [
      {
        "id": "asset-patient-record",
        "name": "patient record",
        "diagram_referents": [
          "Patient record"
        ],
        "evidence_refs": [
          "operator-review-context"
        ]
      },
      {
        "id": "asset-triage-priority",
        "name": "triage priority",
        "diagram_referents": [
          "Triage queue"
        ],
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "prohibited_outcomes": [
      {
        "id": "outcome-no-clinician",
        "statement": "Model output must not suppress an urgent case without clinician review.",
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "continuity_safety_constraints": [
      {
        "id": "constraint-fallback",
        "statement": "Urgent intake must route to a clinician when the model path is unavailable.",
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "supplied_severity": null,
    "scope": {
      "included_labels": [],
      "excluded_labels": [
        "model-provider training pipeline"
      ],
      "boundary_statement": "Review the drawn clinical application, data stores, and model API call. Do not review provider training."
    }
  }
}

Artifact-only confirmation. Traditional-phase not_applicable is allowed only when profile_confirmation.operator_confirmed is true and evidence_ref states that integration is out of scope.

{
  "review_context_input": {
    "profile": "artifact-only",
    "profile_confirmation": {
      "operator_confirmed": true,
      "evidence_ref": "This review covers the model package and model card only. Integration, inference, deployment, identity, retrieval, and tools are out of scope."
    },
    "perspective": "Assurance team reviewing a model package without a runtime claim.",
    "vertical_ids": [],
    "jurisdictions": [],
    "operating_model": null,
    "critical_assets": [],
    "prohibited_outcomes": [],
    "continuity_safety_constraints": [],
    "supplied_severity": null,
    "scope": {
      "included_labels": [
        "model package",
        "model card"
      ],
      "excluded_labels": [
        "runtime",
        "deployment",
        "identity",
        "retrieval",
        "tools"
      ],
      "boundary_statement": "Static artifact inspection only."
    }
  }
}
Track B: assign SRF accountability

Use this when the first message already includes an operating model plus the full personas, matrix, and threat_crosswalk objects. Operating model values: AI-SaaS, AI-PaaS, Agent-PaaS, IaaS.

  1. Copy the Track B shortcut.
  2. Open the three files. Copy each file's full JSON object.
  3. Copy the example below. Replace the three REPLACE_WITH_FULL_OBJECT strings with those objects. Keep operating_model the same in review_context_input and srf_inputs.
  4. Paste the shortcut, the representation, and the filled JSON in the same first message.
Attach this system representation. Load https://aisharedresponsibility.com/tools/prompts/threat-model/prompts.json.

Use pack version 3.0, runtime_defaults, chain_execution, and operator_initial_inputs. Run required Track A from P-context through P-qa, then Track B from P-srf-join through P-srf-coverage, then P-report, then P-export-md, P-export-json, P-export-csv, and P-export-diagram. Fill every later template slot from accumulated JSON. Keep the representation attached when a template includes {{representation}}. Set representation_kind to image, mermaid, or svg. Role: experienced-threat-modeler unless this message names another role.

Treat omitted operator fields as empty and continue. Do not ask for review context, source records, SRF data, or continue. Use srf_inputs already in this message. If srf_inputs or operating_model is missing, mark Track B incomplete and continue to P-report. Do not ask.

Do not skip a step. If a stop_condition fails, record the gap in that step's JSON and continue later steps that can run. When a chain object has repeat_until, rerun that same step with its cumulative prior output until the condition is true, in this same reply.

Do not fetch catalog or SRF data. Use data/threat-sources.json as the named source registry only. An omitted or empty source_manifest makes catalog coverage not_applicable. Track C runs only after Track B when this message also includes vertical_ids and vertical_source_rows.

Leave report.reviewer empty.
Do not rephrase Shostack's four questions. Do not put mitigations in P-phantom.
{
  "role": "application-security",
  "if_no_ai_nodes": "continue_without_llm",
  "review_context_input": {
    "profile": "full-system",
    "profile_confirmation": {
      "operator_confirmed": false,
      "evidence_ref": null
    },
    "perspective": "Healthcare application team that owns intake, triage workflow, model integration, and clinician review.",
    "vertical_ids": [],
    "jurisdictions": [],
    "operating_model": "AI-PaaS",
    "critical_assets": [
      {
        "id": "asset-patient-record",
        "name": "patient record",
        "diagram_referents": [
          "Patient record"
        ],
        "evidence_refs": [
          "operator-review-context"
        ]
      },
      {
        "id": "asset-triage-priority",
        "name": "triage priority",
        "diagram_referents": [
          "Triage queue"
        ],
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "prohibited_outcomes": [
      {
        "id": "outcome-no-clinician",
        "statement": "Model output must not suppress an urgent case without clinician review.",
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "continuity_safety_constraints": [
      {
        "id": "constraint-fallback",
        "statement": "Urgent intake must route to a clinician when the model path is unavailable.",
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "supplied_severity": null,
    "scope": {
      "included_labels": [],
      "excluded_labels": [
        "model-provider training pipeline"
      ],
      "boundary_statement": "Review the drawn clinical application, data stores, and model API call. Do not review provider training."
    }
  },
  "srf_inputs": {
    "operating_model": "AI-PaaS",
    "personas": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/personas.json",
    "matrix": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/matrix.json",
    "threat_crosswalk": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/threats.json"
  }
}
Track C: join vertical obligations

Use this after Track B inputs are in the first message, plus vertical_ids and vertical_source_rows. The two rows in the example are reshaped from healthcare-controls.json. Copy more rows from that file or the matching vertical file and keep this object shape. A control candidate is a proposed control. Vertical ids on this site: healthcare, finance, public-sector, insurance, defense, manufacturing. Jurisdiction ids include us-federal and eu from jurisdictions.json.

  1. Complete the Track B packing steps.
  2. Set vertical_ids and jurisdictions on review_context_input.
  3. Add obligation and control-candidate rows. Paste shortcut, representation, and the filled JSON in the same first message.
Attach this system representation. Load https://aisharedresponsibility.com/tools/prompts/threat-model/prompts.json.

Use pack version 3.0, runtime_defaults, chain_execution, and operator_initial_inputs. Run required Track A from P-context through P-qa, then Track B from P-srf-join through P-srf-coverage, then Track C from P-vertical-join through P-vertical-route, then P-report, then P-export-md, P-export-json, P-export-csv, and P-export-diagram. Fill every later template slot from accumulated JSON. Keep the representation attached when a template includes {{representation}}. Set representation_kind to image, mermaid, or svg. Role: experienced-threat-modeler unless this message names another role.

Treat omitted operator fields as empty and continue. Do not ask for review context, source records, SRF data, or continue. Use srf_inputs, vertical_ids, and vertical_source_rows already in this message. If Track B cannot close, skip Track C, record the gap, and continue to P-report. Do not ask.

Do not skip a step. If a stop_condition fails, record the gap in that step's JSON and continue later steps that can run. When a chain object has repeat_until, rerun that same step with its cumulative prior output until the condition is true, in this same reply.

Do not fetch catalog or SRF data. Use data/threat-sources.json as the named source registry only. An omitted or empty source_manifest makes catalog coverage not_applicable.

Leave report.reviewer empty.
Do not rephrase Shostack's four questions. Do not put mitigations in P-phantom.
{
  "role": "application-security",
  "if_no_ai_nodes": "continue_without_llm",
  "review_context_input": {
    "profile": "full-system",
    "profile_confirmation": {
      "operator_confirmed": false,
      "evidence_ref": null
    },
    "perspective": "Healthcare application team that owns intake, triage workflow, model integration, and clinician review.",
    "vertical_ids": [
      "healthcare"
    ],
    "jurisdictions": [
      "us-federal"
    ],
    "operating_model": "AI-PaaS",
    "critical_assets": [
      {
        "id": "asset-patient-record",
        "name": "patient record",
        "diagram_referents": [
          "Patient record"
        ],
        "evidence_refs": [
          "operator-review-context"
        ]
      },
      {
        "id": "asset-triage-priority",
        "name": "triage priority",
        "diagram_referents": [
          "Triage queue"
        ],
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "prohibited_outcomes": [
      {
        "id": "outcome-no-clinician",
        "statement": "Model output must not suppress an urgent case without clinician review.",
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "continuity_safety_constraints": [
      {
        "id": "constraint-fallback",
        "statement": "Urgent intake must route to a clinician when the model path is unavailable.",
        "evidence_refs": [
          "operator-review-context"
        ]
      }
    ],
    "supplied_severity": null,
    "scope": {
      "included_labels": [],
      "excluded_labels": [
        "model-provider training pipeline"
      ],
      "boundary_statement": "Review the drawn clinical application, data stores, and model API call. Do not review provider training."
    }
  },
  "srf_inputs": {
    "operating_model": "AI-PaaS",
    "personas": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/personas.json",
    "matrix": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/matrix.json",
    "threat_crosswalk": "REPLACE_WITH_FULL_OBJECT from https://aisharedresponsibility.com/data/threats.json"
  },
  "vertical_source_rows": [
    {
      "source_id": "srf-healthcare-controls",
      "vertical_id": "healthcare",
      "kind": "obligation",
      "id": "SRF-L3-DEV-001",
      "title": "Human-in-the-Loop Gate for High-Stakes Outputs",
      "statement": "Clinical AI outputs classified as high-risk (diagnosis, treatment selection, medication dosing, procedure recommendation) must be surfaced as advisory only and require explicit clinician confirmation before any downstream action is taken.",
      "mandatory": true,
      "layer": "L3",
      "accountable_persona": "clinical-application-developer",
      "canonical_url": "https://aisharedresponsibility.com/data/healthcare-controls.json"
    },
    {
      "source_id": "srf-healthcare-controls",
      "vertical_id": "healthcare",
      "kind": "control_candidate",
      "id": "SRF-L3-VV-002",
      "title": "Prompt Injection and Input Manipulation Defense",
      "statement": "LLM-based clinical AI tools must implement and validate defenses against prompt injection, jailbreak, and adversarial input manipulation before clinical deployment.",
      "mandatory": false,
      "layer": "L3",
      "accountable_persona": "clinical-application-developer",
      "canonical_url": "https://aisharedresponsibility.com/data/healthcare-controls.json"
    }
  ]
}

Run one prompt at a time

Use this when the chat cannot load prompts.json. Copy P-context first, then use Copy next. Optional review context, SRF data, and vertical rows still belong in the first message. Role values: experienced-threat-modeler, application-security, llm-caller. Default is experienced-threat-modeler. Copy-one-block text starts with a [chain] line. A chain run of P-stride repeats in the same reply until its typed denominator closes. P-importance is required before P-act. After P-report, run the export steps.

Last copied: none. Next: P-context (Establish review context).

Shostack's Four Questions

  1. What are we working on?
  2. What can go wrong?
  3. What are we going to do about it?
  4. Did we do a good job?

Wording is from the Four Question Framework (CC-BY). Use those four sentences as written. State the team view and what we are working on right now.

PHANTOM-B questions (LLM subset)

Ask these eight questions for each eligible AI node after traditional applicability closes. Write mitigations in P-act.

Roles

Sources

What each track records

Track A records review context, the full inventory, traditional and AI applicability, composition paths, threats, actions, and source provenance. Track B assigns one SRF layer, persona, and party. Track C adds source-bound obligations, control candidates, and acceptance authority. A catalog entry needs an inventory referent and evidence before it can attach to a threat.

Q1. What are we working on?

Set the review profile and claim boundary, then read the whole representation into a structured inventory.

Q2. What can go wrong?

Complete typed STRIDE and conditional abuse and operational passes before PHANTOM-B. Then test AI-to-traditional paths and pinned source mappings.

Q3. What are we going to do about it?

Map method labels, record evidence-backed importance, and choose one action with a testable control point.

Q4. Did we do a good job?

Check phase gates, denominators, evidence, and actions. Optional accountability and vertical joins run here before the report.

What Track A has filled

P-qa produces the checked Track A matrix. Run optional Track B and Track C before P-report, or run P-report immediately. Then run the export steps and save the .md, .json, .csv, and .mmd replies. Schema: eval/threat-model/schema.json. Eval path: <system-id>/image.json (or mermaid.json / svg.json).

Track B and Track C are optional. After the selected tracks, return to P-report. Then run the export steps and save the .md, .json, .csv, and .mmd replies.

Track B (optional): SRF accountability

Use the Track B one-chat shortcut when SRF inputs are in the first message, or copy the blocks below after P-qa. Track B consumes the checked Track A matrix, a supplied operating model, and injected local SRF data. It checks expected L1 to L5 coverage before returning to P-report or Track C.

What Track B has filled

The assistant JSON after P-srf-coverage is the Track A matrix with srf on every threat and a layer_coverage audit. chain_meta.track_b_applied is true only when that audit closes.

Track B does not add threats. A threat with no matching crosswalk row still needs a source-backed layer, persona, and party. Run Track C when vertical context is supplied, or run P-report next.

Track C (optional): vertical obligations and routing

Use the Track C one-chat shortcut when Track B inputs plus vertical ids and vertical source rows are in the first message, or copy the blocks below after Track B closes. It joins supported vertical and jurisdiction rows to existing threat ids. It cannot add a threat or treat a candidate control as an existing control.

What Track C has filled

Export the report, JSON, CSV, and diagram

These four prompts run once after P-report. P-export-md emits the stored report without rewriting it (.md). That stored report projects the matrix: every threat id appears as a table row grouped by diagram referent. P-export-json writes the completed record (.json). P-export-csv writes one row per threat with stable SRF columns. Track A leaves those cells empty (.csv). P-export-diagram writes a Mermaid data-flow of the inventory with threat ids on their referents (.mmd). It uses only inventory ids. Leave the reviewer line empty.

Evaluation baselines

P-zeroshot and P-identity are the two short baselines scored in eval/threat-model/. Machine scores stay open until the SME sheets in that directory are filled.

Output schema

Full JSON Schema: eval/threat-model/schema.json. Gold diagrams and bounded workflow fixtures are in eval/threat-model/ of the site repository.