Threat model:
Method: STRIDE over the data-flow diagram, then a ranked list of mitigations. Scope: <the components and trust boundaries covered; the date and commit>.
System and trust boundaries
Section titled “System and trust boundaries”<Embed or link docs/c4/containers.d2. Mark each trust boundary: client to gateway, gateway to engines, worker to Python subprocesses, durable server to its PVC, agent to tools and the web, CI to the registry.>
Assets
Section titled “Assets”| Asset | Why it matters |
|---|---|
| <…> | |
| <…> | |
| <…> | |
| <…> |
Threats
Section titled “Threats”| Id | Component | STRIDE | Threat | Likelihood | Impact | Mitigation (implemented, file or test) | Residual risk |
|---|---|---|---|---|---|---|---|
| T1 | gateway | Spoofing | <L/M/H> | <L/M/H> | <…> | <…> | |
| T2 | agent | Tampering | <ag.04 gate, injection suite> | ||||
| T3 | crawler | Elevation | <ag.06 allowlist> |
Open items
Section titled “Open items”- <Threats accepted or deferred, with the reason and a revisit date.>