# Attack Tree Desk > Build and review one attack tree for one attacker goal. Paste the tree as an indented outline > with AND/OR gates (or the JSON the attack-tree-construction skill exports), or describe a system > and have a scored tree drafted. The browser computes the roll-ups, every attack scenario, the > cheapest, easiest, stealthiest and fastest scenario, the minimal cut sets and the scenarios that > no in-place control meets, for free. A metered review then checks gates and estimates, proposes > missing branches and writes a defence plan and a stakeholder brief, all reconciled with the > browser's analysis. URL: https://attack-tree-desk.skillsafe.ai/ API tutorial: https://attack-tree-desk.skillsafe.ai/api.html Source skill: @wshobson/attack-tree-construction (https://github.com/wshobson/agents, MIT) Notice: https://attack-tree-desk.skillsafe.ai/NOTICE.txt ## Who it is for A security engineer, architect or product owner preparing an attack tree for a design review, a threat-modelling session or a stakeholder decision about where to spend on defence. ## The tree grammar One node per line, children indented two spaces under their parent. - Gate: `S1 [OR] Steal credentials` (any child reaches it) or `S2 [AND] Account recovery` (every child is required). - Step: `A1 Phishing | difficulty=low cost=low detection=medium time=4h | mitigations: MFA (in place); training` - difficulty: trivial, low, medium, high, expert (scored 1-5). cost: free, low, medium, high, very_high (0-4; $, $$, $$$ also read). detection: none, low, medium, high, certain (0-4). time: hours; 2d and 1w are read as 48 and 168 hours. - `insider=yes`, `physical=yes` mark steps that need an insider or physical access. - A mitigation ending in `(in place)` is a live control; `(planned)` is promised; anything else is only named. - Missing attributes are scored at the skill's defaults (medium, medium, medium, 8 h) and flagged. ## What the free analysis computes (in the browser) - Roll-ups: OR takes the minimum of each metric; AND takes the maximum difficulty and detection and the sum of cost and time. - Scenarios: every set of steps that reaches the goal, with cost and time summed and difficulty and detection taken from the hardest and loudest step. - Best paths: cheapest, easiest, stealthiest and fastest scenario, with fixed tie-breaks. - Minimal cut sets: the smallest sets of steps whose defence blocks every scenario, sorted by how many of their steps still lack an in-place control. Counts are exact even for trees too large to list. - Each step's share of the scenarios, and the scenarios that meet no in-place control. - Flags: reused ids, empty and single-child gates, unmarked gates, unreadable or missing attributes, unmitigated steps, no insider step, and more. - Exports: Mermaid, PlantUML, the skill's JSON schema, a canonical outline, steps CSV, scenarios CSV and a Markdown report. ## Model lanes (metered, gpt-terra) Every run sends one JSON object with a required `task` field. - `build`: input `goal`, `description`, optional `attacker` and `question`. Returns `goal`, `assumptions`, `out_of_scope`, `tree` (in the grammar above), `step_notes` (one per step, each citing the description), `open_questions`, `summary`. The page re-reads the drafted tree with the same analyzer and checks each note and each in-place control against the description. - `review`: input `facts` (a JSON string produced by the page's analyzer), optional `context` and `question`. Returns `verdict` (ready_for_review, revise_first or restructure; never below the analyzer's floor), `headline`, `flag_responses`, `gate_checks`, `estimate_challenges`, `missing_branches` (new tree lines under an existing gate), `defense_plan` (the first item is a minimal cut set from the facts), `stakeholder_brief`, `summary`. The page checks every id, quoted value, cut, share and count against the facts and lists any disagreement. Handoffs: a drafted tree goes to the review lane with one button; proposed branches and estimate changes can be written back into the tree, which re-runs the free analysis. Each defence-plan item shows how many open scenarios would remain if its steps were defended, and its controls can be added to those steps as planned. After any edit the page shows what changed since the review. The Markdown report carries the review, the analysis and a Mermaid diagram in one file. ## Limits - 60,000 characters and 300 nodes per tree; up to 2,000 scenarios and 2,000 cut sets are listed (counts stay exact beyond that). The review is sent up to 160 nodes: every gate, every flagged step and every step on a best path or a top cut first. - A control marked in place counts only if it works; the desk never assumes it does. - An attack tree is a planning aid, not a penetration test. The model writes steps at the level of technique and precondition only: no exploit code, commands, payloads or attack procedures. ## Data The analysis runs in the browser and nothing is uploaded until a run. Past runs are saved to the signed-in user's SkillSafe account (collection `trees`) and mirrored in the browser.