Threat model
| Topic | Consideration |
|---|---|
| Prompt injection | Tool results and remote agent messages are untrusted input. Governance is enforced outside the model. |
| Shell access | shell.execute can do what action rules cannot see. Network and filesystem restrictions and isolation are the primary controls. |
| Incomplete action mappings | Rules on well-known actions apply only to mapped tools. Prefer default: deny. |
| Remote agents | The local runtime cannot enforce governance inside a remote agent. Treat them as external parties. |
| Secrets | Reference, scope and redact. |
| Approval fatigue | Requests need enough context for a meaningful decision. |
| Audit integrity | Hash chains do not detect deletion of a whole chain. |
Report problems in the specification or tooling via GitHub private vulnerability reporting.
Normative text: Security considerations, Privacy considerations.