Trust boundaries
Figure 1. Nine crossings where untrusted input becomes trusted only after an explicit check. Every row in the register below sits on at least one of them.Severity and evidence discipline
Severity usescritical, high, medium and low. Every high or critical item carries an owner,
executable or inspection evidence, and a residual-risk statement. The residual-risk column is the
one worth reading closely — it is where the honest limits live.
High and critical register
TM-01 · critical · Direct prompt injection exceeds purpose
TM-01 · critical · Direct prompt injection exceeds purpose
AgentDefinition and WorkOrder binding;
default-deny policy with a per-effect recheck.Evidence. Core identity, runtime command and policy adversarial suites.Owner and residual risk. Runtime and policy maintainers. An allowed model action can still be
undesirable inside an over-broad host grant.TM-02 · critical · Indirect injection causes goal hijack or data export
TM-02 · critical · Indirect injection causes goal hijack or data export
TM-03 · critical · A poisoned or drifted tool keeps an old identity
TM-03 · critical · A poisoned or drifted tool keeps an old identity
TM-05 · critical · Approval replay, forgery or weak-auth decision
TM-05 · critical · Approval replay, forgery or weak-auth decision
DecisionChallenge; keyed opaque proof; atomic consumption with
exact effect, grant and SecretRef bindings; expiry and role strength.Evidence. Approval and challenge replay, cross-tenant, wrong-role and zero-dispatch tests.Owner and residual risk. Decision-system owner. Human misunderstanding of an accurate preview
remains possible.TM-06 · critical · Secret exfiltration through context or observability
TM-06 · critical · Secret exfiltration through context or observability
ModelCredentialRef and SecretRef; resolution only in the bound adapter;
sealed credential lifecycle; redaction canaries across all outputs.Evidence. Credential-boundary, secret, telemetry, public-surface and release audits.Owner and residual risk. Credential and adapter owners. A compromised host process or
provider endpoint can still access authorised values.TM-07 · critical · Cross-tenant storage access
TM-07 · critical · Cross-tenant storage access
TM-08 · critical · An uncertain external effect is repeated
TM-08 · critical · An uncertain external effect is repeated
TM-09 · high · Scope or path traversal escapes an allowed boundary
TM-09 · high · Scope or path traversal escapes an allowed boundary
TM-10 · high · SSRF or redirect abuse reaches internal origins
TM-10 · high · SSRF or redirect abuse reaches internal origins
TM-11 · high · Model or tool cost exhaustion
TM-11 · high · Model or tool cost exhaustion
TM-12 · high · Lease theft, stale commit or duplicate command
TM-12 · high · Lease theft, stale commit or duplicate command
TM-13 · critical · Sandbox escape or resource attack
TM-13 · critical · Sandbox escape or resource attack
no-new-privileges and hard resource bounds.Evidence. Container probes for secret, path, symlink, socket, network, fork, loop and output.Owner and residual risk. Deployment owner. The fixture is explicitly not production
arbitrary-code isolation.TM-14 · high · Malicious MCP metadata, drift or transport abuse
TM-14 · high · Malicious MCP metadata, drift or transport abuse
SandboxAdapter.TM-15 · critical · Dependency, lifecycle or build compromise
TM-15 · critical · Dependency, lifecycle or build compromise
TM-16 · critical · Package confusion or tarball substitution
TM-16 · critical · Package confusion or tarball substitution
TM-17 · high · Logs, telemetry or evidence leak sensitive content
TM-17 · high · Logs, telemetry or evidence leak sensitive content
TM-18 · high · Evidence misrepresented as truth or certification
TM-18 · high · Evidence misrepresented as truth or certification
Additional medium risks
- A third-party adapter ignores cancellation or a deadline.
- Backup, retention, deletion or key rotation is incomplete across replicas.
- A supported provider changes semantics without a versioned adapter update.
- Denial messages become an enumeration oracle.
- Performance degradation causes queue growth inside configured but overly generous bounds.
- A maintainer account or external organisation setting is compromised.