Skip to main content

Threat model (v1.0 summary)

ThreatImpactMitigation (v1)Residual risk
Malicious agent bypasses SDKUncontrolled side effectsInterceptor/MCP/gateway; code reviewUnguarded code paths
Stolen credentials in parametersSecret leakageRedaction + hash-only storageBugs in redaction rules
Policy tampering at runtimeWrong decisionsPolicy versioning + hash on recordCompromised host
Ledger modificationFalse audit trailHash chain + ledger verifyDB file access on host
Approval replayAction runs without intentApproval bound to execution + params hashConcurrent races (mitigate in store)
Identity spoofingWrong actor blamedIntegrate real IdP laterLocal SDK trusts caller
Delegation abuseOver-privileged sub-agentScope checks on delegation chainIncomplete scope modeling

This is a summary for integrators. Maintainer depth lives in internal review notes, not in public runbooks.