In this article
Security/Tm7 Generation Workflow
| Field | Value |
|---|---|
| Kind | instruction |
| Source | .github/instructions/security/tm7-generation-workflow.instructions.md |
| Invocation | Applied automatically to .github/agents/security/security-planner.agent.md, .github/agents/security/security-reviewer.agent.md |
| Interactive | No |
What it does
Human-in-the-loop contract for TM7 threat-model generation and the native Windows TMT feedback loop
When to use it
Apply this contract when a Security Planner or Reviewer generates a TM7 draft, updates a model, or considers the native Windows TMT feedback loop. Generation still requires explicit authorship confirmation before handoff, while native UI automation requires a separate desktop-takeover confirmation and visual review.
Example usage
Provide a concrete example that shows the asset in action, including representative input and the resulting output.