Extension ID
attacktree
Extension Name
AttackTree
Version
0.1.0
Description
Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability
Author
hupe1980
Repository URL
https://github.com/hupe1980/spec-kit-attacktree
Download URL
https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
License
MIT
Homepage (optional)
https://hupe1980.github.io/spec-kit-attacktree/
Documentation URL (optional)
https://hupe1980.github.io/spec-kit-attacktree/docs/
Changelog URL (optional)
https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md
Required Spec Kit Version
=1.0.0
Required Tools (optional)
- python + pyyaml (or uv instead) (>=3.11) - required: Python 3.11+ with the PyYAML package, OR uv. The wrappers use uv only when no Python with PyYAML is found; uv then provides Python, PyYAML, and jsonschema itself.
- uv (instead of python + pyyaml) - optional: alternative to the line above, not needed when Python with PyYAML is installed
- jsonschema (python package, full schema validation) - optional
Number of Commands
4
Number of Hooks (optional)
7
Tags
security, attack-trees, threat-modeling, risk-simulation, traceability
Key Features
- Builds
attack-tree.yaml from spec.md and plan.md: threat actors with capabilities, attacker goals with business impact, AND/OR paths, rated attack vectors, and security controls
- Simulates the tree with Schneier's propagation rules and attacker-profile feasibility: most likely and cheapest path per actor, residual risk per goal, choke points, single points of failure, what-if per control, a cost-ranked roadmap, and a seeded Monte Carlo
- Publishes controls as testable
CR-### requirements with Given/When/Then acceptance into spec.md
- 16 deterministic checks (A1–A16) plus semantic review, with Markdown, JSON, and SARIF output; a bundled GitHub Action uploads to code scanning
- Evidence-based convergence: verdicts from tests, reviews, or micro attack simulations, measured bypass rates for probabilistic controls, residual risk from verified controls only, and remediation tasks appended to
tasks.md
- Agentic profile with five attack-surface zones and references to the OWASP Top 10 for LLM and Agentic Applications 2026 and MITRE ATLAS
- Optional Open Threat Model (OTM) import; seven optional lifecycle hooks; a companion preset and workflow
- The engine needs no LLM: a single Python script that runs in CI
Testing Checklist
Submission Requirements
Testing Details
Tested on:
- macOS (Darwin 25) with Spec Kit 1.0.7, Python 3.11, 3.13, and 3.14
- CI: Ubuntu and Windows, Python 3.11 and 3.13
Test project: scratch project from specify init --integration claude, plus the shipped example examples/agent-assistant
Test scenarios:
- Manifest validated with
specify_cli.extensions.ExtensionManifest (4 commands, 7 hooks, no warnings)
specify extension add --dev into the scratch project: the 4 skills were registered, the config was scaffolded, and the hooks were written to .specify/extensions.yml
- Companion preset and workflow installed with
specify preset add and specify workflow add
- The engine run on the example: validate, render, check (md, json, sarif), simulate (all scenarios, what-if, Monte Carlo), converge-scan, converge-apply
- Test suite: 132 tests, including 40 seeded randomized property tests of the propagation rules
- The release workflow smoke-installs the built archive with
specify extension add --from
Example Usage
# Install
specify extension add attacktree --from https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
# In your agent, after /speckit-specify
/speckit.attacktree.model
# After /speckit-plan
/speckit.attacktree.model --from-plan
/speckit.attacktree.simulate
# After /speckit-tasks
/speckit.attacktree.check
# After /speckit-implement
/speckit.attacktree.converge
# Or without an agent, e.g. in CI
.specify/extensions/attacktree/scripts/bash/attacktree.sh check --format sarif --output attacktree.sarif
.specify/extensions/attacktree/scripts/bash/attacktree.sh simulate --scenario current
Proposed Catalog Entry
{
"attacktree": {
"name": "AttackTree — Attack Tree Modeling & Control Simulation",
"id": "attacktree",
"description": "Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability",
"author": "hupe1980",
"version": "0.1.0",
"download_url": "https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip",
"repository": "https://github.com/hupe1980/spec-kit-attacktree",
"homepage": "https://hupe1980.github.io/spec-kit-attacktree/",
"documentation": "https://hupe1980.github.io/spec-kit-attacktree/docs/",
"changelog": "https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md",
"license": "MIT",
"requires": {
"speckit_version": ">=1.0.0",
"tools": [
{ "name": "python + pyyaml (or uv instead)", "version": ">=3.11", "required": true },
{ "name": "uv (instead of python + pyyaml)", "required": false },
{ "name": "jsonschema (python package, full schema validation)", "required": false }
]
},
"provides": {
"commands": 4,
"hooks": 7
},
"tags": ["security", "attack-trees", "threat-modeling", "risk-simulation", "traceability"],
"verified": false,
"downloads": 0,
"stars": 0,
"created_at": "2026-10-05T00:00:00Z",
"updated_at": "2026-10-05T00:00:00Z"
}
}
Additional Context
AttackTree brings attack-tree threat modelling (Schneier 1999; Christian Schneider's scenario-driven practice at attacktree.online) into Spec-Driven Development. The agent builds the tree and judges evidence; a deterministic Python engine does all propagation, simulation, and checks, so results are reproducible and CI-ready. All hooks are optional, and core commands are unchanged unless the optional preset is installed. Interop is limited to open standards: OTM import, SARIF output, and a JSON Schema for the tree.
Extension ID
attacktree
Extension Name
AttackTree
Version
0.1.0
Description
Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability
Author
hupe1980
Repository URL
https://github.com/hupe1980/spec-kit-attacktree
Download URL
https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip
License
MIT
Homepage (optional)
https://hupe1980.github.io/spec-kit-attacktree/
Documentation URL (optional)
https://hupe1980.github.io/spec-kit-attacktree/docs/
Changelog URL (optional)
https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md
Required Spec Kit Version
Required Tools (optional)
Number of Commands
4
Number of Hooks (optional)
7
Tags
security, attack-trees, threat-modeling, risk-simulation, traceability
Key Features
attack-tree.yamlfromspec.mdandplan.md: threat actors with capabilities, attacker goals with business impact, AND/OR paths, rated attack vectors, and security controlsCR-###requirements with Given/When/Then acceptance intospec.mdtasks.mdTesting Checklist
Submission Requirements
extension.ymlmanifest includedTesting Details
Tested on:
Test project: scratch project from
specify init --integration claude, plus the shipped exampleexamples/agent-assistantTest scenarios:
specify_cli.extensions.ExtensionManifest(4 commands, 7 hooks, no warnings)specify extension add --devinto the scratch project: the 4 skills were registered, the config was scaffolded, and the hooks were written to.specify/extensions.ymlspecify preset addandspecify workflow addspecify extension add --fromExample Usage
Proposed Catalog Entry
{ "attacktree": { "name": "AttackTree — Attack Tree Modeling & Control Simulation", "id": "attacktree", "description": "Attack trees with attacker profiles, AND/OR path simulation, control roadmaps, and control-to-test traceability", "author": "hupe1980", "version": "0.1.0", "download_url": "https://github.com/hupe1980/spec-kit-attacktree/archive/refs/tags/v0.1.0.zip", "repository": "https://github.com/hupe1980/spec-kit-attacktree", "homepage": "https://hupe1980.github.io/spec-kit-attacktree/", "documentation": "https://hupe1980.github.io/spec-kit-attacktree/docs/", "changelog": "https://github.com/hupe1980/spec-kit-attacktree/blob/main/CHANGELOG.md", "license": "MIT", "requires": { "speckit_version": ">=1.0.0", "tools": [ { "name": "python + pyyaml (or uv instead)", "version": ">=3.11", "required": true }, { "name": "uv (instead of python + pyyaml)", "required": false }, { "name": "jsonschema (python package, full schema validation)", "required": false } ] }, "provides": { "commands": 4, "hooks": 7 }, "tags": ["security", "attack-trees", "threat-modeling", "risk-simulation", "traceability"], "verified": false, "downloads": 0, "stars": 0, "created_at": "2026-10-05T00:00:00Z", "updated_at": "2026-10-05T00:00:00Z" } }Additional Context
AttackTree brings attack-tree threat modelling (Schneier 1999; Christian Schneider's scenario-driven practice at attacktree.online) into Spec-Driven Development. The agent builds the tree and judges evidence; a deterministic Python engine does all propagation, simulation, and checks, so results are reproducible and CI-ready. All hooks are optional, and core commands are unchanged unless the optional preset is installed. Interop is limited to open standards: OTM import, SARIF output, and a JSON Schema for the tree.