Create a practical threat model for an AI agent that names boundaries, threats, controls, and tests.
An AI customer-success agent reads untrusted customer emails and can update CRM opportunity stages. Diagram -> classify -> control -> test The common trap is saying the model will not do dangerous things because the system prompt forbids them. In an agent, the application must constrain tool authority even when the model is confused. Draw the boundary Map user, customer email, retrieval store, model context, CRM tool, secrets, audit log, and CRM database. This shows where low-trust text can influence high-authority actions. Classify threats Apply STRIDE: spoofing user identity, tampering with tool arguments, repudiation without logs, information disclosure from CRM,…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in