attasec/tmdd
p/attasec
Version-controlled threat modeling with AI for dev teams
0 reviews5 followers
Start new thread
trending

attasec/tmdd - Version-controlled threat modeling with AI for dev teams

TMDD keeps a threat model inside your repo and makes AI coding agents security-aware. As teams use Cursor, Claude Code and other agents to ship features fast, business logic and authorization bugs are easy to miss. SAST/DAST rarely catch them. TMDD: • Stores a threat model (YAML format) in your repo • Lets AI agents update it alongside code • Generates secure-by-design prompts • Produces a full report with data flow diagram Threat modeling as code - versioned, reviewable, agent-friendly.