Practitioner-grade threat modeling resources for agentic AI systems. Built for security engineers, AI red teamers, and architects who need a structured starting point grounded in realistic attack behavior.
Most threat modeling guidance for AI remains either too generic to apply in real reviews or too product-specific to reuse. This repository focuses on practical, reusable patterns for deployed agentic systems: tool-using agents, orchestration layers, memory-enabled assistants, and multi-agent pipelines.
It is designed for teams that need to move from "AI is risky" to concrete, defensible security decisions with documented trade-offs.
A docs-first threat modeling reference covering:
- Threat taxonomy: 50 attack patterns across 10 categories
- Control mappings: Prevent, detect, and respond controls with verification signals
- Framework crosswalks: OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF
- Risk scoring: Agentic Risk Score (ARS) rubric for triage and prioritization
- Templates: Threat model worksheets and submission templates for repeatable reviews
- Focused on deployed agentic systems, not generic LLM safety discussions.
- Uses concrete threat patterns with preconditions and affected assets.
- Includes a lightweight but practical prioritization model (ARS).
- Maps directly to OWASP LLM Top 10, MITRE ATLAS, and NIST AI RMF.
- Includes reusable templates and worked examples for real review sessions.
- Threat catalog sample:
docs/threat-catalog/llm-agent-threats.md - Scored example:
docs/examples/customer-support-agent-threat-model.md - Multi-agent example:
docs/examples/multi-agent-tool-escalation-model.md - Submission format:
docs/templates/threat-submission.md
- Content changes are reviewed through pull requests with documented rationale.
- Markdown quality checks run in CI on pull requests and pushes to
main. - Repository links are validated in CI to catch stale references.
- New threat entries are expected to include realistic attack preconditions and evidence when possible.
- Assumptions for this framework:
ASSUMPTIONS.md - Known limitations and non-goals:
LIMITATIONS.md
- Security architects designing or reviewing agentic AI deployments
- Product security teams adding AI-specific threats to existing libraries
- Red teams building test plans for tool-using and multi-agent systems
- Compliance and GRC teams mapping AI threats to governance frameworks
- Read the guide:
docs/guides/agentic-threat-modeling-guide.md - Review the catalog:
docs/threat-catalog/llm-agent-threats.md - Score threats with ARS:
docs/scoring/agentic-risk-score.md - Record decisions using templates in
docs/templates/
- Define system scope and trust boundaries.
- Pick the 5 to 10 most likely threat patterns from the catalog.
- Score each with ARS.
- Assign one prevent and one detect control for the highest scores.
- Record owners, due dates, and residual risks.
- Run the guide end-to-end with engineering, security, and operations.
- Build a complete threat table with assets, preconditions, and controls.
- Prioritize remediation by ARS tier and business criticality.
- Revisit the model when architecture, permissions, or tooling changes.
Adoption playbook: ROADMAP.md
This repository focuses on threats to deployed agentic systems: runtime attacks, orchestration weaknesses, tool abuse, data exfiltration, and supply chain compromise.
- Model pretraining security internals and lab-only model research workflows
- Domain-specific legal or regulatory interpretations
- Incident response runbooks for a specific vendor platform
Taxonomy updates are tracked in CHANGELOG.md.
Contributions are reviewed through pull requests and threat submissions.
This repository is maintained as a practitioner portfolio and community resource for production-grade agentic AI threat modeling. The primary goal is to provide material that security teams can apply directly in architecture reviews.
See CONTRIBUTING.md. New catalog entries should use
docs/templates/threat-submission.md.
Apache-2.0. See LICENSE.