Threat Model & Security Controls
Formal threat modeling subsystem aligned with MITRE ATLAS and STRIDE. Identifies critical assets, threat actors, trust boundaries, and residual risk scores.
Identified Threats
10
100% Control Coverage
Critical Assets
8
All Sinks Enforced
Trust Boundaries
7
In-Line Interception
Mean Residual Risk
2.8 / 10
Grade: LOW (Controlled)
| Threat ID | Severity | Threat Description | Control Effectiveness | Residual Risk |
|---|---|---|---|---|
| thr_indirect_prompt_injection | CRITICAL | Indirect Prompt Injection via Untrusted Context | PREVENTS | 1.2 / 10.0 |
| thr_delegation_escalation | HIGH | Multi-Hop Delegation Authority Escalation | PREVENTS | 1.0 / 10.0 |
| thr_pii_exfiltration | CRITICAL | Customer PII Data Exfiltration to External Sink | PREVENTS | 1.5 / 10.0 |
| thr_rag_poisoning | HIGH | RAG Knowledge Base & Document Store Poisoning | REDUCES | 2.8 / 10.0 |