{"repo":"davidmatousek/tachi","free":true,"listed":false,"github":"https://github.com/davidmatousek/tachi","clone":"git clone https://github.com/davidmatousek/tachi.git","description":"Threat modeling and AI-reasoning vulnerability detection harness for Claude Code — STRIDE + AI + MAESTRO","language":"Python","stars":89,"topics":["agentic-security","ai-security","attack-trees","claude-code","cybersecurity","devsecops","llm-security","sarif","security","stride"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"tachi Threat Modeling and Vulnerability Detection Harness for Claude Code. AI-Reasoning Scanner — STRIDE + AI + MAESTRO. Get started : Quick Start Developer Guide (full walkthrough with worked examples) --- OWASP Coverage 50/50 across five frameworks — every catalogued threat in each framework has a tachi detection agent. Framework Coverage Anchor --- --- --- OWASP LLM Top 10 (2026) 10/10 LLM 2026 OWASP Agentic Top 10 (2026) 10/10 Agentic 2026 OWASP ML Security Top 10 (2023) 10/10 ML 2023 OWASP Mobile Top 10 (2024) 10/10 Mobile 2024 OWASP Web/API\\ (2021 + 2023) 10/10 Web 2021 · API 2023 \\ Web/API combined slot: OWASP Web Top 10:2021 (A01–A10) + OWASP API Security Top 10:2023 (API1–API10) — 20 items, 20/20. Canonical matrix: docs/standards/OWASP COVERAGE.md · Byte-deterministic Coverage Attestation: examples/ /sample-report/ What is tachi? tachi is a threat modeling and AI-reasoning vulnerability detection harness for Claude Code. SAST catches syntax-level bugs; the harness reasons over your architecture description to catch logic-level ones — broken authentication flows, missing privilege boundaries, prompt injection paths, agent autonomy gaps, cross-layer attack chains. It runs as a new scanning column alongside SAST / SCA / Secrets, with two views of one engine: - Threat modeling view — structured artifacts: threats.md , SARIF, narrative report, attack trees, MAESTRO classification. - Vulnerability scanning view — per-finding logic-level risks surfaced from the architecture","default_branch":null,"files":null,"tree":[],"storefront":"/r/davidmatousek","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/davidmatousek/tachi/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}