-
Notifications
You must be signed in to change notification settings - Fork 0
design: threat-model API, CLI, and MCP access #9
Copy link
Copy link
Open
Labels
area/integrationCRM, OMS, payment, API, CLI, event, or MCP integrationCRM, OMS, payment, API, CLI, event, or MCP integrationarea/securitySecurity, privacy, authorization, and threat modellingSecurity, privacy, authorization, and threat modellingphase/1-mvpRequired or evaluated for the Phase 1 service MVPRequired or evaluated for the Phase 1 service MVPpriority/nowRefine or execute now for the current sprint/critical pathRefine or execute now for the current sprint/critical pathsprint/1Sprint 1 walking skeleton and contractSprint 1 walking skeleton and contractstatus/needs-decisionRequires an explicit project decisionRequires an explicit project decisiontype/spikeTime-boxed uncertainty reduction ending in evidence or a decisionTime-boxed uncertainty reduction ending in evidence or a decision
Milestone
Description
Activity
Metadata
Metadata
Assignees
Labels
area/integrationCRM, OMS, payment, API, CLI, event, or MCP integrationCRM, OMS, payment, API, CLI, event, or MCP integrationarea/securitySecurity, privacy, authorization, and threat modellingSecurity, privacy, authorization, and threat modellingphase/1-mvpRequired or evaluated for the Phase 1 service MVPRequired or evaluated for the Phase 1 service MVPpriority/nowRefine or execute now for the current sprint/critical pathRefine or execute now for the current sprint/critical pathsprint/1Sprint 1 walking skeleton and contractSprint 1 walking skeleton and contractstatus/needs-decisionRequires an explicit project decisionRequires an explicit project decisiontype/spikeTime-boxed uncertainty reduction ending in evidence or a decisionTime-boxed uncertainty reduction ending in evidence or a decision
Objective: threat-model the shared application service and every adapter, with special attention to agent tool use.
Cover authentication, authorization, tenant and case boundaries, prompt injection through source documents, confused-deputy risks, token handling, output exfiltration, audit integrity, replay, confirmation gates, and fail-closed downstream behavior.
Exit gate: high-risk MCP operations are narrowly scoped, mutation tools are confirmation-gated, and release remains human-only.