Attack Tree Desk https://attack-tree-desk.skillsafe.ai/ This app is a derived work built on the agent skill "attack-tree-construction" published in the wshobson/agents repository (path plugins/security-scanning/skills/attack-tree-construction, read at commit 9b15b34b0bfc13a815cbfc2366e14ea549e09422), listed on SkillSafe as @wshobson/attack-tree-construction. That repository is licensed under the MIT License, whose text is reproduced below. What was taken from the source skill: the attack-tree model (OR, AND and leaf nodes), the leaf attributes and their scales (difficulty trivial to expert, cost free to very high, detection none to certain, time in hours, insider and physical requirements), the roll-up rules (OR takes the minimum; AND takes the maximum difficulty and the sum of cost), the easiest, cheapest and stealthiest path analysis, scenario enumeration, critical-node counting and mitigation coverage, the Mermaid and PlantUML export shapes and the JSON export schema, and the worked account-takeover example (adapted, with times and control status added for illustration). What was changed: the skill is Python for an agent to run. This app is a JavaScript reimplementation that reads a tree written as an indented outline (or the skill's JSON export) in the browser. It adds AND roll-ups for time (sum) and detection (maximum), minimal cut sets, exact counts for trees too large to enumerate, controls marked in place or planned, structural flags, and two model lanes whose system prompt was written for this app. The skill's path score summed difficulty along a path; this app scores a scenario by its hardest step, consistent with the skill's own difficulty roll-up. The systems in the bundled examples are invented. Not affiliated with or endorsed by the skill's author. An attack tree is a planning aid, not a penetration test or a security assessment. ---------------------------------------------------------------------------------------------- MIT License Copyright (c) 2024 Seth Hobson Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.