Skip to content

Threat model:

Method: STRIDE over the data-flow diagram, then a ranked list of mitigations. Scope: <the components and trust boundaries covered; the date and commit>.

<Embed or link docs/c4/containers.d2. Mark each trust boundary: client to gateway, gateway to engines, worker to Python subprocesses, durable server to its PVC, agent to tools and the web, CI to the registry.>

AssetWhy it matters
<…>
<…>
<…>
<…>
IdComponentSTRIDEThreatLikelihoodImpactMitigation (implemented, file or test)Residual risk
T1gatewaySpoofing<L/M/H><L/M/H><…><…>
T2agentTampering<ag.04 gate, injection suite>
T3crawlerElevation<ag.06 allowlist>
  • <Threats accepted or deferred, with the reason and a revisit date.>