Red Hat turns six threat-modeling methods into a portable coding-agent module
The open-source Lola module runs in Claude Code, Cursor and Gemini CLI, tying proposed attack scenarios to files and lines while keeping human review in the loop.
Red Hat Product Security has open-sourced an AI-assisted threat-modeling module that developers can run from Claude Code, Cursor or Gemini CLI. The project is intended to move an initial security review closer to the engineer and the code, without treating model output as an authoritative security verdict.
What changed
The agentic-threat-modeling module profiles likely attackers, analyzes a selected feature or service and generates narrative attack scenarios grounded in the repository. Red Hat says it checks the code through six structured approaches, including STRIDE, PASTA, LINDDUN and attack trees, then connects findings to particular files and lines.
The module runs on Lola, an open-source package manager for reusable AI context. That packaging is consequential for platform teams: one module can be installed across the three supported coding-agent environments rather than maintaining separate prompt files for each tool.
Users can choose a guided /threat-model workflow or a faster /threat-model-quick pass. Red Hat’s example analyzes an unauthenticated file-upload handler and identifies a path-traversal scenario, naming the affected line and a proposed mitigation.
Who should care
Development teams adopting coding agents are the immediate audience, especially where a centralized product-security group cannot review every change before it ships. The module offers a repeatable first pass that is more structured than asking a general chatbot whether a file is secure.
Security teams may also care about the output format. Red Hat is positioning a structured threat model as a possible future input to vulnerability triage: an SBOM can show that a component contains a CVE, while a threat model may help determine whether the affected path appears reachable or protected by a compensating control. That triage pipeline is explicitly future work, not a current capability.
What to do
Teams can install Lola with uv, add Red Hat Product Security’s Lola marketplace and install the module for Cursor, Claude Code or Gemini CLI. Before putting it into a delivery workflow, they should evaluate how source code and prompts are handled by the selected agent and model, and establish a review process for generated findings.
The project should be treated as a diagnostic aid, not an approval gate. Red Hat itself says the output does not replace human judgment. A useful pilot would compare the quick and guided modes against a service with an existing human-written threat model, measuring missed attack paths, false positives and whether file-and-line references remain accurate as the code changes.
sources
- AI threat modeling shouldn't be a bottleneck, so we open sourced oursdevelopers.redhat.com
comments · 0