Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Threat model

TopicConsideration
Prompt injectionTool results and remote agent messages are untrusted input. Governance is enforced outside the model.
Shell accessshell.execute can do what action rules cannot see. Network and filesystem restrictions and isolation are the primary controls.
Incomplete action mappingsRules on well-known actions apply only to mapped tools. Prefer default: deny.
Remote agentsThe local runtime cannot enforce governance inside a remote agent. Treat them as external parties.
SecretsReference, scope and redact.
Approval fatigueRequests need enough context for a meaningful decision.
Audit integrityHash chains do not detect deletion of a whole chain.

Report problems in the specification or tooling via GitHub private vulnerability reporting.

Normative text: Security considerations, Privacy considerations.