Documentation
README
threat-model
Codex skill: MCP threat-model artifact for PR / compliance review (iter 112 → iter 114). User-labelled "enterprise gold."
What it does
Renders the existing mcp-scan findings as a clean threat-model artifact
in the shape a security / compliance reviewer wants to see attached to a
PR:
MCP Threat Model
Allowed tools: 3
Denied tools: 14
Dangerous permissions: 0
Secrets reachable: no
Network access: no
Shell access: no
File write: no
Default-deny policy: yes
Audit log: yes
Verdict: clean (exit 0)
Same underlying scan as mcp-scan, presented as a single-screen artifact.
This is the opening of the README. Read the full README on GitHub.