Model the threat before any code exists
Walks the feature’s data flow element by element applying STRIDE — spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege — and adds the lens of risks specific to systems with agents. The result isn’t a document that sits still: it becomes an acceptance criterion of the feature itself, with a reference to the matching ASVS control.
/threat-model