Skip to content

About

Example outputs of appsec-advisor

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

appsec-advisor examples

Example outputs of appsec-advisor, a Claude Code plugin that builds a threat model from a repository's code and configuration: it derives the architecture and runs STRIDE against it.

This repository complements the plugin's own examples/threat-modeler directory with more targets and depths. The reports show what the output looks like before you run a scan yourself.

Files

All runs are in threat-modeler/. The files of one run share the name threat-model-<target>-<depth>-v<version>. The version suffix is the plugin release (b4 is beta 4), so runs from different releases can sit side by side.

  • .md, .html, .pdf: the report
  • .figure1.svg, .figure2.svg: the figures used in the report
  • .yaml: the structured model, including plugin version, models and invocation in its meta block
  • .sarif.json: code-scanning results (SARIF 2.1)
  • .threatdragon.json: export for Threat Dragon and ThreatAtlas
  • pentest-tasks-*.yaml: endpoint catalog and pentest plan

Not every run has all of these. Only the thorough Juice Shop run was exported to HTML, PDF, SARIF and Threat Dragon.

Models

The standard runs use Claude Sonnet 4.6 as orchestrator and for the STRIDE analysis. Triage and merging of findings run on Claude Sonnet 5. The thorough run uses Claude Opus throughout.

Examples

OWASP Juice Shop

Juice Shop is a deliberately insecure web shop (version 20.1.1 in all runs). Stack: Angular, Node.js, Express, Socket.IO, Sequelize, SQLite, Docker.

  • Standard run: 6 critical, 42 high, 23 medium, 71 findings in total. Also available as YAML.
  • Thorough run: 6 critical, 24 high, 36 medium, 66 findings in total. Also available as YAML, HTML, PDF, SARIF and Threat Dragon.
  • Pentest tasks: endpoint catalog and pentest plan in the Strix dialect for http://localhost:3000, exported from the thorough run.

OWASP VulnerableApp

VulnerableApp is an application for demonstrating and testing security issues. Stack: Java, Spring Boot, JSP, PHP.

  • Standard run: 4 critical, 23 high, 21 medium, 48 findings in total. Also available as YAML.

Insecure Large Spring App

The files threat-model-insecure-large-spring-app-* come from Insecure Large Spring App, a repository built to test how the process copes with many components. It defines 42 Docker Compose services in 7 network zones.

The standard run models 21 components and 124 entry points. 14 components get a full STRIDE analysis. The other 7 are out of scope at standard depth and are listed in the report under "Components Not Individually Analyzed". Result: 13 critical, 40 high, 16 medium, 69 findings in total.

Files: report, YAML, figure 1 (architecture), figure 2 (risk flow).

All counts exclude low and informational findings (reporting threshold medium).

Assessment depths

Coverage, cost and runtime of each depth are described under Assessment depth & cost control.

  • quick: early feedback and low-risk changes. Skips abuse-case validation and the final model-based QA.
  • standard (default): the usual choice. Full analysis, abuse-case validation and QA.
  • thorough: for high-risk services and major releases. Deeper component analysis and an architecture review.

Running it yourself

Install the plugin as described in the Quick start, then run /appsec-advisor:create-threat-model in Claude Code from the repository you want to model. The meta.invocation field in each YAML file shows which options a run used. The thorough Juice Shop run, for example, used --thorough --sarif --pentest-tasks --pentest-format strix --pentest-target http://localhost:3000 --threatdragon --pdf --html.

About

Example outputs of appsec-advisor

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages