Produce a threat model for an open-source project - the implicit security contract between the project and its downstream users, structured for both integrators (which threats are theirs vs the project's) and vulnerability triagers (is a report valid, out-of-model, or by-design). Use when asked to write, draft, review, or update a threat model, security model, or trust-boundary document for a library, service, or component; when triaging whether a reported vulnerability is in scope; or when a project needs to define what counts as a security bug.
2026-07-08