Repository navigation
v1.15.1
Explicit threat model threading for `vulnerability-audit` + `attack-chain-analysis`.
Stage 0 of `security-review` says "thread this JSON into every later subagent." Stage 1
(`hotspot-mapping`) and Stage 2.5 (`finding-validate`) explicitly named the threat
model in their dispatch language. But Stages 1b+2 only named it for `design-review` —
`vulnerability-audit`'s bullet was silent. Stage 3 (`attack-chain-analysis`) only
mentioned "the merged findings."
Both downstream agents' prompts (`vulnerability-audit.md`, `attack-chain-analysis.md`)
expect the threat model in their Inputs section, so this was an orchestrator ambiguity
rather than a missing capability — but ambiguity is enough to make a reasonable reader
skip the threading.
Fix
Explicit "with the threat model AND ..." language for both dispatches, with the reason
each agent benefits called out:
| Agent | Why the threat model helps |
|---|---|
| `vulnerability-audit` | `trusted_inputs` / `untrusted_inputs` informs which sinks are reachable — don't flag a sink that only sees trusted bytes |
| `attack-chain-analysis` | Threat model informs effective severity — does the chain cross an untrusted boundary? |
The procedure intro and a few stage paragraphs were also tightened to fit the 600-word
cap after the additions.
Compatibility
No subagent code changed. This is purely an orchestrator clarification — sessions
running v1.15.0 were already free to pass the threat model down (the agent prompts
expected it); v1.15.1 just makes the orchestrator's dispatch unambiguous.
If you are pinned to `@v1`, the floating tag now points at v1.0.30 → v1.15.1.