Field note · Build v1

The threat model found the unlocked door

Situation. Second skill, same day. The setup skill had written down how the company ships; the threat-model skill’s job is to write down who can reach the company and what they can make it do. There was a test built into this run: a security document already existed, written in early 2025, and the question was whether the skill would treat it as input or start from a blank page.

What happened. It treated it as input, and that is exactly what made the result uncomfortable. The old document’s assets and supply-chain sections carried straight over, still true. Its list of attacks did not, because it was written before the business grew the surfaces that matter now: an email address published in customer DNS that accepts mail from anyone, a privacy-request form open to the internet, marketing forms, hosted pages, a dozen token links that travel in URLs. Three readers went through eight services in parallel and mapped roughly a hundred and twenty ways in. Then came the part no checklist predicted: the biggest finding was not in any of the new surfaces. It was in the oldest, most reviewed code in the company: sign-up. A branch meant for invited teammates accepts the invitation token without ever checking it, so anyone holding a customer’s account identifier, which several public endpoints will happily hand out, could join that customer’s account as a member. It had sat there through every feature review, because feature reviews ask “is this change safe” and nobody had asked “who can reach this” of code that never changed. Seven findings of that weight went into the written model, each with the file and line to fix. The run changed nothing except the document, so the read-only rule held, and the honest tally is uncomfortable on purpose: a reviewer that found a real hole last week still missed a wide-open door, until the question changed.

Next. Fix the door before writing anything else: the sign-up branch, the token expiry that is never checked, the privacy form that lets a stranger verify someone else’s identity. Then wire the model into the review skill, which is the point of the whole exercise: every future change gets read against “who can reach this”, not just “what did this change”.

Spend in October 2026: £45.00. Spend to date: £45.00. As of 11 October 2026. Cost tracker.

Search

Filter results by project and type.