Skip to content

[External Plugin]: tmforge #2947

Description

@Hacks4Snacks

Plugin name

tmforge

Short description

The Strider agent that comes with the tmforge plugin adds evidence-backed STRIDE threat modeling to GitHub Copilot, with structured risk assessment, deterministic validation, and Markdown reports. Optional tmforge integration supports creating, updating, and verifying Microsoft Threat Modeling Tool (.tm7) models.

GitHub repository

Hacks4Snacks/tmforge

Plugin path inside the repository

plugins/tmforge

Ref to review

v0.11.0

Commit SHA to review

8c22d85c4cb65f416c228bb2a73ae9f364aa549b

Version

0.11.0

License identifier

MIT

Author name

Mark Dalton Gray

Author URL

https://github.com/Hacks4Snacks

Homepage URL

https://github.com/Hacks4Snacks/tmforge/tree/main/plugins/tmforge

Keywords

data-flow-diagrams, risk-assessment, security-review, stride, strider, threat-modeling, threat-modeling-as-code, tm7, tmforge, trust-boundaries

Additional notes for reviewers

Agent Plugins 0.11.0 package with Strider and two skills. The workflow adds an evidence ledger, stable identities, complete STRIDE coverage checks, deterministic report rendering, and candidate validation for tmforge models. Python scripts use the standard library only. No hooks, bundled MCP servers, or embedded CLI binaries. A launcher downloads a version-pinned, checksum-verified CLI only after explicit user approval; normal use never downloads or changes global PATH. Markdown-only analysis requires no CLI download. The reviewed source is the nested plugin directory.

Submission checklist

  • The plugin lives in a public GitHub repository.
  • The ref and/or sha I provided is immutable (release tag and/or full 40-character commit SHA), not a branch.
  • This submission follows this repository's contribution, security, and responsible AI policies.
  • This plugin is not already listed in the Awesome Copilot marketplace.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    external-pluginPublic external plugin submissionready-for-reviewSubmission passed intake validation and is ready for maintainer review

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions