Contributing to the Fased Threat Model
Thanks for helping make Fased more secure. This threat model is a living document, and contributions are welcome. You do not need to be a security expert.Ways to Contribute
Add a Threat
Spotted an attack vector or risk we haven’t covered? Open an issue on fased-ai/fased and describe it in your own words. You don’t need to know any frameworks or fill in every field - just describe the scenario. Helpful to include (but not required):- The attack scenario and how it could be exploited
- Which parts of Fased are affected: Agent setup tabs, gateway, channels, services, skills/plugin catalog, dependency installers, Agent tool policy, wallets, SAT mining, Advanced diagnostics, nodes, MCP servers, CLI, and related surfaces.
- How severe you think it is (low / medium / high / critical)
- Any links to related research, CVEs, or real-world examples
This is for adding to the threat model, not reporting live vulnerabilities.
If you found an exploitable vulnerability, use SECURITY.md.
Suggest a Mitigation
Have an idea for how to address an existing threat? Open an issue or PR referencing the threat. Useful mitigations are specific and actionable. For example, “per-sender rate limiting of 10 messages/minute at the gateway” is more useful than “implement rate limiting.” For skills and wallets, specify which gate should change: install review, Agent skill allowlist, Agent tool policy, Wallet > Skill Grants, passkey approval, or mining wallet policy.Propose an Attack Chain
Attack chains show how multiple threats combine into a realistic scenario. If you see a dangerous combination, describe the steps and how an attacker would chain them together. A short narrative is more useful than a formal template.Fix or Improve Existing Content
Typos, clarifications, outdated info, better examples - PRs welcome, no issue needed.What We Use
MITRE ATLAS
This threat model is built on MITRE ATLAS (Adversarial Threat Landscape for AI Systems), a framework for AI/ML threats such as prompt injection, tool misuse, and agent exploitation. You do not need to know ATLAS to contribute. Maintainers map submissions to the framework during review.Threat IDs
Each threat gets an ID likeT-EXEC-003. The categories are:
IDs are assigned by maintainers during review. You don’t need to pick one.
Risk Levels
If you’re unsure about the risk level, just describe the impact and we’ll assess it.
Review Process
- Triage - We review new submissions within 48 hours
- Assessment - We verify feasibility, assign ATLAS mapping and threat ID, validate risk level
- Documentation - We ensure everything is formatted and complete
- Merge - Added to the threat model and visualization
Resources
Contact
- Security vulnerabilities: use
SECURITY.md - Threat model questions: open an issue on fased-ai/fased
- General discussion: use the normal repo issue/discussion flow