MURAGE
How it worksFeaturesSolutionsUse casesComparePricingDocs
DownloadDownload
MURAGE

An AI Chief of Staff and a team that does the work. Free and open source, from Ferrox Labs.

Product

  • Features
  • How it works
  • Engines and apps
  • Privacy and security
  • Pricing
  • Murage Cloud
  • Download
  • Changelog
  • FAQ

Solutions

  • Solopreneurs
  • Founders and startups
  • Agencies
  • Ecommerce
  • Small business
  • Creators and educators
  • Developers
  • SaaS
  • Nonprofits
  • Consultants and freelancers
  • Customer success teams
  • Legal and professional services
  • Small teams
  • Sales teams
  • Operations managers
  • Industries
  • Use cases
  • Build your team

Compare

  • vs Claude Code
  • vs Codex (ChatGPT Work)
  • vs Claude (Cowork)
  • vs Paperclip
  • vs OpenClaw
  • vs Hermes Agent
  • vs Manus
  • vs Genspark
  • vs n8n
  • vs Zapier
  • vs Grok Bot
  • vs Viktor
  • vs Lindy
  • vs Tasklet

Resources

  • Docs
  • Team library
  • Skill library
  • AI Chief of Staff
  • How we test
  • Limits
  • Switching to Murage
  • Open source
  • Blog
  • Release notes

Company

  • About
  • Partners
  • Enterprise
  • Contact
  • Privacy
  • Terms
  • Cookies
© 2026 Ferrox Labs. Murage is open source under AGPL-3.0.
Security skills

Threat Modeler

Threat modeling expertise covering STRIDE methodology, attack trees, data flow diagrams, trust boundaries, threat prioritization with DREAD scoring, mitigation strategies, threat modeling for APIs and microservices, and automated threat modeling tools for proactively identifying security risks during system design.

Download Murage

Free and open source. macOS, Windows and Ubuntu.

Try it

Add the skill to a bot, then ask your Chief of Staff:

“Use the Threat Modeler skill on this: [describe the job, or paste your notes].”

Threat modeling is the practice of identifying security threats to a system during the design phase, before code is written. It answers four fundamental questions: What are we building? What are we going to do about it? Did we do a good enough job?

What it covers

  • The Four Questions of Threat Modeling
  • Data Flow Diagrams (DFD)
  • STRIDE Methodology
  • Attack Trees
  • Trust Boundaries
  • Threat Prioritization (DREAD)
  • Threat Modeling for APIs
  • Microservices Threat Modeling

Skill Guard: clean

Scanned and clear. A bot can use it as soon as you add it.

Subject
Security
Level
advanced
License
Apache-2.0
securitythreat-modelingguide

How to use it.

  1. 1

    Download Murage

    Free for Mac, Windows and Ubuntu.

  2. 2

    Add the skill

    Open Settings → Skills and switch on Threat Modeler for any bot. Or ask your Chief of Staff to pick skills for a job.

  3. 3

    Give it a job

    The bot reads the skill when the job calls for it, and works the way it lays out.

Put this skill to work.

  • ResearchAsk a real question. Get one page with sources.
  • Skill GuardEvery skill is scanned before a bot can use it.

Questions.

What is the Threat Modeler skill?+

Threat modeling expertise covering STRIDE methodology, attack trees, data flow diagrams, trust boundaries, threat prioritization with DREAD scoring, mitigation strategies, threat modeling for APIs and microservices, and automated threat modeling tools for proactively identifying security risks during system design.

How much does it cost?+

Nothing. It ships with Murage, which is free and open source. Your bots run on the AI plan you already have.

Can I change it?+

Yes. Open it in Settings → Skills to read, edit or duplicate it. Skill Guard scans it again after every edit.

More security skills.

  • API Security EngineerAPI security expertise covering OWASP API Security Top 10, API authentication and authorization patterns and API key management.
  • Application Secrets SecuritySecrets management expertise covering HashiCorp Vault and AWS Secrets Manager patterns, secret rotation strategies and environment variable management.
  • Cryptography EngineerCryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures and key management.
  • Data Backup StrategistDesign and implement resilient backup strategies using the 3-2-1 rule, encryption best practices and cloud vs local tradeoffs.
  • Device Hardening GuideSystematically secure personal devices through OS hardening, router and network security, IoT device isolation and firmware management.
  • DevSecOps EngineerSecurity integration in CI/CD pipelines covering SAST and DAST tooling, container image scanning and dependency vulnerability auditing.

All security skills

Give your first job to Murage.

Download the free app, connect the AI you already pay for, and tell your Chief of Staff what needs doing. Plan on about ten minutes from install to a working team.

Free · Download Murage

No account needed · Runs on the AI plan you already pay for