Skip to content

Commit ce71f4d

Browse files
committed
Refine risk calibration and threat modeling for availability and self-attacks
- Update mantis_calibrate/SKILL.md: - Add exceptions to self-attack risk downgrade for lack of non-repudiation and side effects. - Simplify repro failure rule to always downgrade to LOW. - Add availability_tier enum check for availability-only findings to scale risk multiplier. - Output availability_tier in calibration results. - Update mantis_architecture/SKILL.md to capture component availability requirements in the KB. - Update mantis_threat_model/SKILL.md to classify availability targets into CRITICAL, STANDARD, or LOW_CRITICALITY tiers in the threat model. - Update SCHEMA.md to document the availability_tier enum in the Finding Object and define it in the THREAT_MODEL.md structure. TAG=agy CONV=af7ca8d9-a795-4f1e-996d-75d7d14ea701 Change-Id: I1602891349abbc7499b05c1a6ac32fcdcff1eda6
1 parent 05c1c60 commit ce71f4d

4 files changed

Lines changed: 61 additions & 8 deletions

File tree

‎SCHEMA.md‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -98,6 +98,9 @@ Fields schema, but with the following specific formatting.*
9898
- **`impact_score`** (Integer: 1-5): The calculated impact on CIA triad.
9999
- **`likelihood_score`** (Integer: 1-5): The probability of occurrence or
100100
exploitation.
101+
- **`availability_tier`** (Enum, Optional): The availability criticality of
102+
the component, if the finding has availability impact.
103+
- Values: `"CRITICAL"`, `"STANDARD"`, `"LOW_CRITICALITY"`, `null`
101104
- **`mantis_risk_score`** (Float: 0.1-10.0): The final calculated risk score
102105
(Hazard).
103106
- **`priority`** (String): Qualitative priority bucket (e.g., `"CRITICAL"`,
@@ -145,3 +148,32 @@ trajectory.
145148
This file serves as an ephemeral inbox/queue for new learnings. It is
146149
periodically synthesized into the permanent Markdown Knowledge Base
147150
(`workspace/kb/`) to prevent infinite loops and token bloat.
151+
152+
--------------------------------------------------------------------------------
153+
154+
## 4. Threat Model (`workspace/kb/THREAT_MODEL.md`)
155+
156+
Generated by `/mantis_threat_model`, read by `/mantis_plan` and
157+
`/mantis_calibrate`.
158+
159+
While this is a Markdown document rather than a strict JSON schema, it serves as
160+
an inter-stage contract. It must contain the following structured sections to
161+
ensure downstream agents can accurately parse exposure and criticality:
162+
163+
- **System Overview Summary:** High-level summary of the system's design and
164+
purpose.
165+
- **Deployment Intent:** Must state the deployment context (e.g., `Intent:
166+
PRODUCTION` or `Intent: SAMPLE_OR_TEST_ONLY`).
167+
- **Trust Boundaries:** Definitions of where untrusted inputs meet trusted
168+
zones, referencing specific components.
169+
- **Threat Actors & Vectors:** Profiles of potential attackers and the
170+
boundaries they can access.
171+
- **High-Risk Assets & Criticality:** The assets (data, privileges,
172+
availability) the attacker wants to compromise.
173+
- **Availability Targets:** For any availability-related assets,
174+
explicitly document their **Availability Tier** using one of these
175+
values:
176+
- `CRITICAL`: 24/7 immediate operational impact if disrupted.
177+
- `STANDARD`: Important operations; short disruptions are tolerable.
178+
- `LOW_CRITICALITY`: Non-blocking utilities; disruption is a mild
179+
annoyance.

‎mantis_architecture/SKILL.md‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -54,11 +54,15 @@ Execute the architecture stage as follows:
5454
Markdown. Follow these strict paths:
5555

5656
- `workspace/kb/architecture.md`: High-level data flows, zone
57-
definitions, and system design.
57+
definitions, system design, and overall availability/uptime
58+
requirements (if documented or inferable from configuration like
59+
systemd, kubernetes, or load balancers).
5860
- `workspace/kb/entities/[component_name].md`: Specific definitions
5961
for components (e.g., `auth_module.md`). Must include links to
6062
associated vulnerability classes and document known constraints
61-
(e.g., "This module sanitizes input X"). Incorporate trajectory
63+
(e.g., "This module sanitizes input X"). Document the component's
64+
criticality and availability requirements (classify as CRITICAL,
65+
STANDARD, or LOW_CRITICALITY if applicable). Incorporate trajectory
6266
insights here.
6367
- `workspace/kb/vulnerabilities/[CWE-ID_or_BugClass].md`: Descriptions
6468
of bug classes (e.g., `CWE-79.md` or `Memory-Corruption.md`) that

‎mantis_calibrate/SKILL.md‎

Lines changed: 17 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,10 @@ Execute the calibration as follows:
6060
- 2: Minor loss (e.g., minor information leak, localized disruption).
6161
A vulnerability whose blast radius is limited to affecting *only a
6262
single user's own data* MUST NOT be scored higher than 2.
63+
*Exception:* If the action lacks non-repudiation (allowing the user
64+
to plausibly deny the action to commit fraud or blame others), or
65+
triggers side-effects affecting other users/system stability, it
66+
should not be downgraded.
6367
- 1: Negligible impact on CIA, mostly a cosmetic issue. Findings of
6468
the type "the code is fragile", "lack of defense-in-depth", or
6569
purely theoretical hygiene issues MUST have an Impact score of 1,
@@ -107,6 +111,12 @@ Execute the calibration as follows:
107111
multiplier high.
108112
- If it affects a low-value target (e.g., internal analytics,
109113
sandboxed test data), reduce the multiplier (e.g., 0.5).
114+
- **Availability-Specific Context:** If the finding is
115+
availability-only (DoS), check the component's
116+
`availability_tier` in the Threat Model:
117+
- `LOW_CRITICALITY`: Reduce multiplier to **0.5**.
118+
- `STANDARD`: Reduce multiplier to **0.8**.
119+
- `CRITICAL`: Keep multiplier at **1.0**.
110120
- If static/dynamic analysis proves the vulnerable code is
111121
effectively "dead code" (never called in runtime execution
112122
paths), drastically reduce the multiplier to 0.2.
@@ -143,10 +153,10 @@ Execute the calibration as follows:
143153
finding's priority to **LOW** (and cap its final score at **2.0**) if it
144154
meets any of the following "weak finding" criteria:
145155

146-
- **Speculative Viability on Repro Failure:** The reproduction failed
147-
(`repro_status: "failed_to_reproduce"`), and the reasoning for why it is
148-
still viable in production is highly speculative, theoretical, or relies
149-
on unverified assumptions about downstream systems.
156+
- **Reproduction Failure:** The reproduction failed (`repro_status:
157+
"failed_to_reproduce"`). If the agent cannot successfully reproduce the
158+
vulnerability, it MUST be force-downgraded regardless of any theoretical
159+
arguments for production viability.
150160
- **Minor Configuration Hygiene:** The issue represents a minor deviation
151161
from best-practice configuration (e.g., slightly loose permissions on an
152162
internal directory, lack of modern encryption on low-value internal
@@ -176,7 +186,8 @@ Execute the calibration as follows:
176186
- **LOW (0.1 - 2.9):** Low priority. Minimal hazard. **Any finding of the
177187
type "the code is fragile", purely hygiene/defense-in-depth, or one that
178188
exclusively affects a single user's own data MUST be capped at LOW
179-
priority regardless of the calculated score.**
189+
priority regardless of the calculated score (unless the exception for
190+
lack of non-repudiation or broader side-effects applies).**
180191

181192
5. **Token-Optimized File Updates:** To minimize LLM output tokens, **do not
182193
re-emit or manually rewrite the entire JSON object in your output.**
@@ -191,6 +202,7 @@ Execute the calibration as follows:
191202

192203
- `"impact_score"` (1-5)
193204
- `"likelihood_score"` (1-5)
205+
- `"availability_tier"` (CRITICAL, STANDARD, LOW_CRITICALITY or null)
194206
- `"mantis_risk_score"` (the final Hazard score)
195207
- `"priority"` (CRITICAL, HIGH, MEDIUM, LOW)
196208
- `"outrage_commentary"` (your reasoning about the outrage factor)

‎mantis_threat_model/SKILL.md‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,12 @@ Execute the threat modeling process as follows:
6666
(e.g., Unauthenticated Network Attacker, Malicious Local User) and the
6767
specific boundaries they can reach.
6868
- **High-Risk Assets:** The data, execution privileges, or availability
69-
targets an attacker wants to compromise.
69+
targets an attacker wants to compromise. **For availability targets,
70+
classify them into one of these Availability Tiers based on the KB:**
71+
- `CRITICAL`: 24/7 immediate operational impact if disrupted.
72+
- `STANDARD`: Important operations; short downtime is tolerable.
73+
- `LOW_CRITICALITY`: Non-blocking utilities; disruption is a mild
74+
annoyance.
7075

7176
Save your final output directly to `workspace/kb/THREAT_MODEL.md`. When
7277
complete, notify the user.

0 commit comments

Comments
 (0)