Skip to content

docs(security): add agentic control-plane threat model#437

Merged
Luis85 merged 2 commits into
developfrom
docs/issue-342-control-plane-threat-model
May 9, 2026
Merged

docs(security): add agentic control-plane threat model#437
Luis85 merged 2 commits into
developfrom
docs/issue-342-control-plane-threat-model

Conversation

@Luis85
Copy link
Copy Markdown
Owner

@Luis85 Luis85 commented May 9, 2026

Summary

  • Adds docs/agentic-control-plane-threat-model.md with named trust boundaries, six threat surfaces, risk × mitigation map, six actionable gaps (GAP-TM-001 through GAP-TM-006), and a regression-check table for reviewers.
  • Updates docs/rbac.md Part 3 to reference the new dedicated doc rather than embed a sparse summary there.
  • Adds the new file to docs/sink.md layout and ownership table.

Closes #342.

Test plan

  • check:workflow passes (automation registry, agents, specs, traceability all ok)
  • check:frontmatter passes on the new doc
  • check:links passes (no broken internal links introduced)
  • All verify failures are pre-existing test timeouts unrelated to docs changes (confirmed same failures on develop without these changes)

🤖 Generated with Claude Code

Symprowire and others added 2 commits May 9, 2026 22:13
Names trust boundaries, six threat surfaces (local permissions,
memory/state files, prompt instructions, GitHub mutation paths,
operational bots, GitHub Actions), and maps risks to existing
controls. Surfaces six actionable gaps (GAP-TM-001 through
GAP-TM-006) and a regression-check table for reviewers.

Updates docs/rbac.md Part 3 to reference the dedicated doc and
adds the new file to docs/sink.md.

Closes #342.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@Luis85 Luis85 merged commit 52a547c into develop May 9, 2026
6 checks passed
@Luis85 Luis85 deleted the docs/issue-342-control-plane-threat-model branch May 9, 2026 20:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docs(security): add agentic control-plane threat model

2 participants