Skip to content

Use threat-model.md in Phase 5 exploitation planning #36

@pruiz

Description

@pruiz

Context

The Phase 1 threat-modeling integration plan adds itemdb/notes/threat-model.md as a required Phase 1b artifact. The initial implementation will explicitly wire this artifact into Phase 2 and Phase 3, but Phase 5 consumption is intentionally deferred.

Phase 5 exploitation could use the threat model to keep exploit attempts realistic and scoped.

Proposal

Update Phase 5 prompts and supporting checks, where appropriate, so exploitation planning considers:

  • attacker capabilities and explicit non-capabilities,
  • documented exploit preconditions,
  • trust boundaries crossed by the confirmed finding,
  • affected assets and security objectives,
  • existing controls that may narrow exploitability,
  • open assumptions that would change exploit feasibility.

Acceptance criteria

  • Phase 5 prompt explicitly references itemdb/notes/threat-model.md when present.
  • Exploitation attempts do not assume capabilities contradicted by the threat model.
  • Exploit documentation records material threat-model assumptions affecting feasibility.
  • Existing Phase 5 behavior remains compatible with projects that do not yet have threat-model artifacts.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions