Skip to content

design: threat-model API, CLI, and MCP access #9

Description

@veil-chow-fyaic

Objective: threat-model the shared application service and every adapter, with special attention to agent tool use.

Cover authentication, authorization, tenant and case boundaries, prompt injection through source documents, confused-deputy risks, token handling, output exfiltration, audit integrity, replay, confirmation gates, and fail-closed downstream behavior.

Exit gate: high-risk MCP operations are narrowly scoped, mutation tools are confirmation-gated, and release remains human-only.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/integrationCRM, OMS, payment, API, CLI, event, or MCP integrationarea/securitySecurity, privacy, authorization, and threat modellingphase/1-mvpRequired or evaluated for the Phase 1 service MVPpriority/nowRefine or execute now for the current sprint/critical pathsprint/1Sprint 1 walking skeleton and contractstatus/needs-decisionRequires an explicit project decisiontype/spikeTime-boxed uncertainty reduction ending in evidence or a decision

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions