Systematically identifying how an agent could be misled, abused, or given excessive authority.
Threat modeling inventories assets, actors, entry points, trust boundaries, model-controlled decisions, credentials, tools, data flows, side effects, and recovery paths. It then pairs credible abuse cases with enforceable controls and tests, recognizing that prompts cannot replace authorization, isolation, or audit systems.