Wild West API

Threat model a new feature with STRIDE and Apex Flash

STRIDE is a checklist for asking what can go wrong with each part of a design. Apex Flash can run the checklist across your data flow description quickly and suggest threats you then review with the people who built the thing.

Set it up

  1. Write a short description of the feature: components, data flows and trust boundaries.
  2. List the assets and the actors, including the attacker types you care about.
  3. Send the description to apex-flash with the STRIDE prompt.
  4. Review each threat and discard the ones that do not apply.
  5. Pick mitigations from your own standards.
  6. Record the accepted threats and owners in your backlog.

Authorisation boundary

Model systems you are designing or responsible for. The output is a list of risks to fix before release, not a plan for attacking a third party's system.

The six categories

Microsoft's threat modeling guidance defines STRIDE as Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Elevation of Privilege. Put the category names in your prompt so the output uses them consistently.

Sanitised sample input

Feature: password reset by email link.
Components: web app, API, user database, email service.
Flow: user enters email -> API creates a token, stores its hash with expiry
-> email service sends link -> user opens link and sets a new password.
Trust boundaries: internet to API; API to email service.
Assets: user accounts, reset tokens.

The prompt and the call

Do a STRIDE threat model of the feature below.
For each component and data flow, list threats under Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service and Elevation of Privilege. Only include a category where a real threat exists.
For each threat give: description, which asset, likelihood (low/medium/high) and a concrete mitigation.
Finish with the five risks you would fix first and any assumptions you made. Mark assumptions clearly.

<design>
...description...
</design>
import os
from openai import OpenAI

client = OpenAI(base_url="https://wildwestapi.com/v1",
                api_key=os.environ["WILDWEST_API_KEY"])

resp = client.chat.completions.create(
    model="apex-flash",
    temperature=0.2,
    messages=[
        {"role": "system", "content": "You are a careful application security architect."},
        {"role": "user", "content": open("stride_prompt.txt", encoding="utf-8").read()},
    ],
)
print(resp.choices[0].message.content)

Keys look like sk-ww-...; keep yours in the WILDWEST_API_KEY environment variable, never in the script. Calls to /v1/chat/completions use the OpenAI format, billing is pay-as-you-go, and prompts are not retained on /v1.

What good output includes

For the reset flow, expect threats like these:

  • Spoofing: someone requests a reset for a victim's address and guesses or intercepts the token.
  • Tampering: the token is not bound to the account, or the link can be changed to set another user's password.
  • Repudiation: resets are not logged, so a takeover cannot be traced.
  • Information disclosure: the response reveals whether an email address has an account, or tokens appear in logs.
  • Denial of service: reset requests used to flood a user with email.
  • Elevation of privilege: a reset for a user with admin rights skips an extra check.

What to check

  • Threats must match your design. Delete generic ones.
  • Missing threats are the real risk. Ask a teammate what the list does not cover.
  • Mitigations should be specific: token entropy, expiry, single use, rate limits, uniform responses.
  • Assumptions the model made. Correct them and rerun.

Both apex-flash and glm-5.3-flash-cyber are security-tuned models with a 1M-token context window, tool calling and vision. They are not uncensored models, and they are meant for defensive and authorised work like this. It is a brainstorming aid, so the value comes from your review.

Where this fits

After design, use security code review on the implementation, then show results in a tabletop. See penetration testing for how testers validate designs and red team tools for tooling.

FAQ

Does it replace a threat modelling workshop?

No. It speeds up the first pass. The workshop finds what the model cannot know about your system.

Can it draw the data flow diagram?

It can write a text description or diagram code, but you should draw it with the team so assumptions are visible.

What about other methods such as PASTA?

You can name another method in the prompt, but this playbook uses STRIDE, the method documented in the Microsoft guidance cited above.

Related

Uncensored AI models on one key

OpenAI and Anthropic compatible, pay as you go. New to it? Start with uncensored AI, explained.