KSKS Security Research
Learning map / Session 4 / Scenes 03–15

WORKSHOP 02 · THREAT MODEL

Map the harm pathbefore the tool path.

Map assets, actors, trust boundaries, data flows, abuse paths, side effects, and recovery before granting an agent capabilities.

threat modelingtoolsdata flowSTRIDE
Learning guide
Level
Intermediate
Reading time
13 min
Presentation
Session 4
Progress
2 of 3

01 · Mental model

Threat-model the whole system, not only the model call

Identify the user and service identities, model provider, retrieval sources, MCP servers, tools, data stores, memory, observability, outputs, and human approvals. Draw where trust or authority changes. Then ask how an attacker could inject, poison, impersonate, exfiltrate, overreach, persist, exhaust, or hide.

Controls should interrupt the path before consequence: source filtering before retrieval, authorization before tool execution, schema checks before persistence, DLP before egress, and rollback before production change.

02 · Visual explanation

01Identityuser + service
02Dataprompt + retrieval
03Toolsside effects
04Statememory + checkpoints
05Evidencelogs + approvals
The agent attack surfaceThe model is one component inside a larger system of identities, data, tools, storage, and operators.

03 · Compare and decide

Turn abuse paths into controls and tests

Decision lensThreatTestable control
Indirect injectionHostile retrieved content proposes an actionTool policy denies scope and records the attempt
Credential misuseAgent obtains standing admin authorityPer-run identity with narrow roles and expiry
Data exfiltrationOutput contains sensitive evidenceClassification-aware redaction and destination allowlist
Memory poisoningFalse instruction persists across sessionsTyped memory schema, source, TTL, and approval

04 · Cybersecurity example

Architecture-review attack exercise

A malicious diagram note asks the reviewer agent to upload the design to an external URL.

01

The note is classified as untrusted diagram data.

02

No generic network tool is available.

03

Allowed tools cannot send artifacts externally.

04

The denied intent becomes a security test and signal.

Outcome: The architecture removes the exfiltration path rather than depending only on model refusal.

05 · What to remember

The 60-second recall

01

Threat models include identities, stores, tools, operators, and data movement.

02

Design out dangerous capabilities before adding detection.

03

Every important control should have an abuse-case test.

Teach-back prompt: Explain this concept to a teammate using the diagram, then name one failure mode and the control that stops it.

06 · Questions people ask

FAQ

Yes as a system threat-modeling lens, supplemented with AI-specific risks such as prompt injection, poisoned context, excessive agency, model behavior, and evaluation drift.

07 · Primary sources

Continue with authoritative guidance