The diagrams and findings can be included in the template to create a final report:
tm.py --report docs/template.md | pandoc -f markdown -t html > report.html
The templating format used in the report template is very simple:
# Threat Model Sample
***
## System Description
{tm.description}
## Dataflow Diagram

## Dataflows
Name|From|To |Data|Protocol|Port
----|----|---|----|--------|----
{dataflows:repeat:|||||
}
## Findings
{findings:repeat:* on element ""
}
To group findings by elements, use a more advanced, nested loop:
## Findings
{elements:repeat:
}} - }}
**Severity**: }}
**Mitigations**: }}
**References**: }}
}}}}}
All items inside a loop must be escaped, doubling the braces, so {item.name} becomes ``. The example above uses two nested loops, so items in the inner loop must be escaped twice, that’s why they’re using four braces.