Production agent systems · stage 05 of 09
Threat model
Which inputs you do not trust, and which risks you are consciously accepting.
The module
Lesson, exercise and rubric
Open the repository in a coding agent and run /module 05 for a Socratic session over this stage.
What you leave behind · markdown
Threat model
Required sections:
- trust boundaries
- untrusted inputs
- abuse cases
- mitigations
- accepted risks
Cohort-visible only; never published.
The eval · eval:threat-model-covers-tool-results
Tool output is treated as untrusted
- tool-results-untrustedTool and retrieval output appears in the untrusted-inputs list. Checked by: The untrusted-inputs section names tool results or retrieved documents.
- accepted-risks-namedAt least one risk is explicitly accepted rather than silently ignored. Checked by: The accepted-risks section is non-empty.
Every check must pass. There is no partial credit and no override.
Evidence that counts
Proof has to exist outside your own claim.
At least 1 of: a commit or file a third party can open; a recorded, reproducible eval run. Evidence older than 365 days is stale and does not count.