Commit 70daa42
docs(security): merge full OWASP/LLM security review into threat model (#126)
Adds T16-T18 (Drive fileId confused-deputy/IDOR, API key exposure via
URL + echoed exceptions, malicious hyperlink injection in AI/grounding
markdown), extends T5/T6/T8/T10/T11/T13/T14 with gaps the 2026-07-08
security review surfaced, and adds 19 new responses (R21-R39) and Open
Items so the findings are tracked alongside the existing threats.
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>1 parent a95b5dc commit 70daa42
1 file changed
Lines changed: 52 additions & 11 deletions
0 commit comments