Skip to content

v1.15.1

Choose a tag to compare

@thejefflarson thejefflarson released this 10 Jun 09:38
· 25 commits to main since this release

Explicit threat model threading for `vulnerability-audit` + `attack-chain-analysis`.

Stage 0 of `security-review` says "thread this JSON into every later subagent." Stage 1
(`hotspot-mapping`) and Stage 2.5 (`finding-validate`) explicitly named the threat
model in their dispatch language. But Stages 1b+2 only named it for `design-review` —
`vulnerability-audit`'s bullet was silent. Stage 3 (`attack-chain-analysis`) only
mentioned "the merged findings."

Both downstream agents' prompts (`vulnerability-audit.md`, `attack-chain-analysis.md`)
expect the threat model in their Inputs section, so this was an orchestrator ambiguity
rather than a missing capability — but ambiguity is enough to make a reasonable reader
skip the threading.

Fix

Explicit "with the threat model AND ..." language for both dispatches, with the reason
each agent benefits called out:

Agent Why the threat model helps
`vulnerability-audit` `trusted_inputs` / `untrusted_inputs` informs which sinks are reachable — don't flag a sink that only sees trusted bytes
`attack-chain-analysis` Threat model informs effective severity — does the chain cross an untrusted boundary?

The procedure intro and a few stage paragraphs were also tightened to fit the 600-word
cap after the additions.

Compatibility

No subagent code changed. This is purely an orchestrator clarification — sessions
running v1.15.0 were already free to pass the threat model down (the agent prompts
expected it); v1.15.1 just makes the orchestrator's dispatch unambiguous.

If you are pinned to `@v1`, the floating tag now points at v1.0.30 → v1.15.1.