Skip to main content

AI Threat Models

Each threat model documents the attack mechanism, preconditions, observable indicators, and how Vallum's containment strategy addresses the vector — with honest limitations and residual risks.

OWASP LLM Top 10 — LLM01Vallum Threat ModelSLSA FrameworkOWASP API SecurityOWASP LLM Top 10 — LLM05OWASP LLM Top 10 — LLM02OWASP LLM Top 10 — LLM04OWASP LLM Top 10 — LLM03OWASP LLM Top 10 — LLM06OWASP LLM Top 10 — LLM07OWASP LLM Top 10 — LLM09OWASP LLM Top 10 — LLM10

Published (50)

Prompt Injection in Agent tool execution

OWASP LLM Top 10 — LLM01 · prompt-injection-agent-tool-execution · PARTIAL TECHNICAL SUPPORT

Published

Prompt Injection in Multi tenant authorization

OWASP LLM Top 10 — LLM01 · prompt-injection-multi-tenant-authorization · SUPPORTED EVIDENCE

Published

Prompt Injection in Evidence provenance certification

OWASP LLM Top 10 — LLM01 · prompt-injection-evidence-provenance-certification · PARTIAL TECHNICAL SUPPORT

Published

Unauthorized Tool Invocation in Agent tool execution

Vallum Threat Model · unauthorized-tool-invocation-agent-tool-execution · PARTIAL TECHNICAL SUPPORT

Published

Unauthorized Tool Invocation in Multi tenant authorization

Vallum Threat Model · unauthorized-tool-invocation-multi-tenant-authorization · SUPPORTED EVIDENCE

Published

Unauthorized Tool Invocation in Evidence provenance certification

Vallum Threat Model · unauthorized-tool-invocation-evidence-provenance-certification · PARTIAL TECHNICAL SUPPORT

Published

Receipt Replay Attack in Agent tool execution

Vallum Threat Model · receipt-replay-agent-tool-execution · PARTIAL TECHNICAL SUPPORT

Published

Receipt Replay Attack in Multi tenant authorization

Vallum Threat Model · receipt-replay-multi-tenant-authorization · SUPPORTED EVIDENCE

Published

Receipt Replay Attack in Evidence provenance certification

Vallum Threat Model · receipt-replay-evidence-provenance-certification · PARTIAL TECHNICAL SUPPORT

Published

Wrong-Tenant Authorization in Agent tool execution

Vallum Threat Model · wrong-tenant-authorization-agent-tool-execution · PARTIAL TECHNICAL SUPPORT

Published

Wrong-Tenant Authorization in Multi tenant authorization

Vallum Threat Model · wrong-tenant-authorization-multi-tenant-authorization · SUPPORTED EVIDENCE

Published

Wrong-Tenant Authorization in Evidence provenance certification

Vallum Threat Model · wrong-tenant-authorization-evidence-provenance-certification · PARTIAL TECHNICAL SUPPORT

Published

Wrong-Scope Authority Escalation in Agent tool execution

Vallum Threat Model · wrong-scope-authority-agent-tool-execution · RESEARCH

Published

Wrong-Scope Authority Escalation in Multi tenant authorization

Vallum Threat Model · wrong-scope-authority-multi-tenant-authorization · RESEARCH

Published

Wrong-Scope Authority Escalation in Evidence provenance certification

Vallum Threat Model · wrong-scope-authority-evidence-provenance-certification · RESEARCH

Published

Agent Impersonation in Agent tool execution

Vallum Threat Model · agent-impersonation-agent-tool-execution · RESEARCH

Published

Agent Impersonation in Multi tenant authorization

Vallum Threat Model · agent-impersonation-multi-tenant-authorization · RESEARCH

Published

Agent Impersonation in Evidence provenance certification

Vallum Threat Model · agent-impersonation-evidence-provenance-certification · RESEARCH

Published

Stale Inventory Attestation in Agent tool execution

Vallum Threat Model · stale-inventory-attestation-agent-tool-execution · RESEARCH

Published

Stale Inventory Attestation in Multi tenant authorization

Vallum Threat Model · stale-inventory-attestation-multi-tenant-authorization · RESEARCH

Published

Stale Inventory Attestation in Evidence provenance certification

Vallum Threat Model · stale-inventory-attestation-evidence-provenance-certification · RESEARCH

Published

Manifest Tampering in Agent tool execution

Vallum Threat Model · manifest-tampering-agent-tool-execution · RESEARCH

Published

Manifest Tampering in Multi tenant authorization

Vallum Threat Model · manifest-tampering-multi-tenant-authorization · RESEARCH

Published

Manifest Tampering in Evidence provenance certification

Vallum Threat Model · manifest-tampering-evidence-provenance-certification · RESEARCH

Published

Proof-Package Substitution in Agent tool execution

Vallum Threat Model · proof-package-substitution-agent-tool-execution · RESEARCH

Published

Proof-Package Substitution in Multi tenant authorization

Vallum Threat Model · proof-package-substitution-multi-tenant-authorization · RESEARCH

Published

Proof-Package Substitution in Evidence provenance certification

Vallum Threat Model · proof-package-substitution-evidence-provenance-certification · RESEARCH

Published

Signature Misuse in Agent tool execution

Vallum Threat Model · signature-misuse-agent-tool-execution · RESEARCH

Published

Signature Misuse in Multi tenant authorization

Vallum Threat Model · signature-misuse-multi-tenant-authorization · RESEARCH

Published

Signature Misuse in Evidence provenance certification

Vallum Threat Model · signature-misuse-evidence-provenance-certification · RESEARCH

Published

Certificate-Status Spoofing in Agent tool execution

Vallum Threat Model · certificate-status-spoofing-agent-tool-execution · RESEARCH

Published

Certificate-Status Spoofing in Multi tenant authorization

Vallum Threat Model · certificate-status-spoofing-multi-tenant-authorization · RESEARCH

Published

Certificate-Status Spoofing in Evidence provenance certification

Vallum Threat Model · certificate-status-spoofing-evidence-provenance-certification · RESEARCH

Published

Audit Suppression in Agent tool execution

Vallum Threat Model · audit-suppression-agent-tool-execution · PARTIAL TECHNICAL SUPPORT

Published

Audit Suppression in Multi tenant authorization

Vallum Threat Model · audit-suppression-multi-tenant-authorization · SUPPORTED EVIDENCE

Published

Audit Suppression in Evidence provenance certification

Vallum Threat Model · audit-suppression-evidence-provenance-certification · PARTIAL TECHNICAL SUPPORT

Published

Metadata Leakage in Agent tool execution

Vallum Threat Model · metadata-leakage-agent-tool-execution · RESEARCH

Published

Metadata Leakage in Multi tenant authorization

Vallum Threat Model · metadata-leakage-multi-tenant-authorization · RESEARCH

Published

Metadata Leakage in Evidence provenance certification

Vallum Threat Model · metadata-leakage-evidence-provenance-certification · RESEARCH

Published

Supply-Chain Artifact Substitution in Agent tool execution

SLSA Framework · supply-chain-artifact-substitution-agent-tool-execution · RESEARCH

Published

Supply-Chain Artifact Substitution in Multi tenant authorization

SLSA Framework · supply-chain-artifact-substitution-multi-tenant-authorization · RESEARCH

Published

Supply-Chain Artifact Substitution in Evidence provenance certification

SLSA Framework · supply-chain-artifact-substitution-evidence-provenance-certification · RESEARCH

Published

Excessive Autonomous Authority in Agent tool execution

Vallum Threat Model · excessive-autonomous-authority-agent-tool-execution · RESEARCH

Published

Excessive Autonomous Authority in Multi tenant authorization

Vallum Threat Model · excessive-autonomous-authority-multi-tenant-authorization · RESEARCH

Published

Excessive Autonomous Authority in Evidence provenance certification

Vallum Threat Model · excessive-autonomous-authority-evidence-provenance-certification · RESEARCH

Published

Evidence Chain Break in Agent tool execution

Vallum Threat Model · evidence-chain-break-agent-tool-execution · RESEARCH

Published

Evidence Chain Break in Multi tenant authorization

Vallum Threat Model · evidence-chain-break-multi-tenant-authorization · RESEARCH

Published

Evidence Chain Break in Evidence provenance certification

Vallum Threat Model · evidence-chain-break-evidence-provenance-certification · RESEARCH

Published

Authorization Token Exfiltration in Agent tool execution

OWASP API Security · token-exfiltration-agent-tool-execution · RESEARCH

Published

Authorization Token Exfiltration in Multi tenant authorization

OWASP API Security · token-exfiltration-multi-tenant-authorization · RESEARCH

Published

In Progress (100)

These threat models are under editorial review and will be published after quality verification.

Authorization Token Exfiltration in Evidence provenance certification

OWASP API Security · Under review

Cross-Context Confusion in Agent tool execution

OWASP LLM Top 10 — LLM05 · Under review

Cross-Context Confusion in Multi tenant authorization

OWASP LLM Top 10 — LLM05 · Under review

Cross-Context Confusion in Evidence provenance certification

OWASP LLM Top 10 — LLM05 · Under review

Tool Output Injection in Agent tool execution

OWASP LLM Top 10 — LLM02 · Under review

Tool Output Injection in Multi tenant authorization

OWASP LLM Top 10 — LLM02 · Under review

Tool Output Injection in Evidence provenance certification

OWASP LLM Top 10 — LLM02 · Under review

Model Denial of Service in Agent tool execution

OWASP LLM Top 10 — LLM04 · Under review

Model Denial of Service in Multi tenant authorization

OWASP LLM Top 10 — LLM04 · Under review

Model Denial of Service in Evidence provenance certification

OWASP LLM Top 10 — LLM04 · Under review

Training Data Poisoning in Agent tool execution

OWASP LLM Top 10 — LLM03 · Under review

Training Data Poisoning in Multi tenant authorization

OWASP LLM Top 10 — LLM03 · Under review

Training Data Poisoning in Evidence provenance certification

OWASP LLM Top 10 — LLM03 · Under review

Sensitive Information Disclosure in Agent tool execution

OWASP LLM Top 10 — LLM06 · Under review

Sensitive Information Disclosure in Multi tenant authorization

OWASP LLM Top 10 — LLM06 · Under review

Sensitive Information Disclosure in Evidence provenance certification

OWASP LLM Top 10 — LLM06 · Under review

Insecure Plugin Execution in Agent tool execution

OWASP LLM Top 10 — LLM07 · Under review

Insecure Plugin Execution in Multi tenant authorization

OWASP LLM Top 10 — LLM07 · Under review

Insecure Plugin Execution in Evidence provenance certification

OWASP LLM Top 10 — LLM07 · Under review

Overreliance on LLM Output in Agent tool execution

OWASP LLM Top 10 — LLM09 · Under review

Overreliance on LLM Output in Multi tenant authorization

OWASP LLM Top 10 — LLM09 · Under review

Overreliance on LLM Output in Evidence provenance certification

OWASP LLM Top 10 — LLM09 · Under review

Unbounded Resource Consumption in Agent tool execution

OWASP LLM Top 10 — LLM10 · Under review

Unbounded Resource Consumption in Multi tenant authorization

OWASP LLM Top 10 — LLM10 · Under review

Unbounded Resource Consumption in Evidence provenance certification

OWASP LLM Top 10 — LLM10 · Under review

Certificate Lifecycle Manipulation in Agent tool execution

Vallum Threat Model · Under review

Certificate Lifecycle Manipulation in Multi tenant authorization

Vallum Threat Model · Under review

Certificate Lifecycle Manipulation in Evidence provenance certification

Vallum Threat Model · Under review

Evidence Package Inflation in Agent tool execution

Vallum Threat Model · Under review

Evidence Package Inflation in Multi tenant authorization

Vallum Threat Model · Under review

Evidence Package Inflation in Evidence provenance certification

Vallum Threat Model · Under review

Temporal Ordering Attack in Agent tool execution

Vallum Threat Model · Under review

Temporal Ordering Attack in Multi tenant authorization

Vallum Threat Model · Under review

Temporal Ordering Attack in Evidence provenance certification

Vallum Threat Model · Under review

Verification Endpoint Abuse in Agent tool execution

Vallum Threat Model · Under review

Verification Endpoint Abuse in Multi tenant authorization

Vallum Threat Model · Under review

Verification Endpoint Abuse in Evidence provenance certification

Vallum Threat Model · Under review

Revocation Delay Exploitation in Agent tool execution

Vallum Threat Model · Under review

Revocation Delay Exploitation in Multi tenant authorization

Vallum Threat Model · Under review

Revocation Delay Exploitation in Evidence provenance certification

Vallum Threat Model · Under review

Forge Readiness Escalation in Agent tool execution

Vallum Threat Model · Under review

Forge Readiness Escalation in Multi tenant authorization

Vallum Threat Model · Under review

Forge Readiness Escalation in Evidence provenance certification

Vallum Threat Model · Under review

Handshake Protocol Downgrade in Agent tool execution

Vallum Threat Model · Under review

Handshake Protocol Downgrade in Multi tenant authorization

Vallum Threat Model · Under review

Handshake Protocol Downgrade in Evidence provenance certification

Vallum Threat Model · Under review

Multi-Tenant Side Channel in Agent tool execution

Vallum Threat Model · Under review

Multi-Tenant Side Channel in Multi tenant authorization

Vallum Threat Model · Under review

Multi-Tenant Side Channel in Evidence provenance certification

Vallum Threat Model · Under review

Delegation Chain Abuse in Agent tool execution

Vallum Threat Model · Under review

Delegation Chain Abuse in Multi tenant authorization

Vallum Threat Model · Under review

Delegation Chain Abuse in Evidence provenance certification

Vallum Threat Model · Under review

Evidence Selective Disclosure Manipulation in Agent tool execution

Vallum Threat Model · Under review

Evidence Selective Disclosure Manipulation in Multi tenant authorization

Vallum Threat Model · Under review

Evidence Selective Disclosure Manipulation in Evidence provenance certification

Vallum Threat Model · Under review

API Key Leakage via Agent in Agent tool execution

OWASP API Security · Under review

API Key Leakage via Agent in Multi tenant authorization

OWASP API Security · Under review

API Key Leakage via Agent in Evidence provenance certification

OWASP API Security · Under review

Context Window Overflow in Agent tool execution

OWASP LLM Top 10 — LLM01 · Under review

Context Window Overflow in Multi tenant authorization

OWASP LLM Top 10 — LLM01 · Under review

Context Window Overflow in Evidence provenance certification

OWASP LLM Top 10 — LLM01 · Under review

Indirect Prompt Injection in Agent tool execution

OWASP LLM Top 10 — LLM01 · Under review

Indirect Prompt Injection in Multi tenant authorization

OWASP LLM Top 10 — LLM01 · Under review

Indirect Prompt Injection in Evidence provenance certification

OWASP LLM Top 10 — LLM01 · Under review

Model Extraction via API in Agent tool execution

OWASP LLM Top 10 — LLM10 · Under review

Model Extraction via API in Multi tenant authorization

OWASP LLM Top 10 — LLM10 · Under review

Model Extraction via API in Evidence provenance certification

OWASP LLM Top 10 — LLM10 · Under review

Output Manipulation for Downstream Systems in Agent tool execution

Vallum Threat Model · Under review

Output Manipulation for Downstream Systems in Multi tenant authorization

Vallum Threat Model · Under review

Output Manipulation for Downstream Systems in Evidence provenance certification

Vallum Threat Model · Under review

Phantom Authority Claims in Agent tool execution

Vallum Threat Model · Under review

Phantom Authority Claims in Multi tenant authorization

Vallum Threat Model · Under review

Phantom Authority Claims in Evidence provenance certification

Vallum Threat Model · Under review

Split Responsibility Gap in Agent tool execution

Vallum Threat Model · Under review

Split Responsibility Gap in Multi tenant authorization

Vallum Threat Model · Under review

Split Responsibility Gap in Evidence provenance certification

Vallum Threat Model · Under review

Compliance Theater via Automation in Agent tool execution

Vallum Threat Model · Under review

Compliance Theater via Automation in Multi tenant authorization

Vallum Threat Model · Under review

Compliance Theater via Automation in Evidence provenance certification

Vallum Threat Model · Under review

Evidence Staleness in Agent tool execution

Vallum Threat Model · Under review

Evidence Staleness in Multi tenant authorization

Vallum Threat Model · Under review

Evidence Staleness in Evidence provenance certification

Vallum Threat Model · Under review

Cascading Revocation Failure in Agent tool execution

Vallum Threat Model · Under review

Cascading Revocation Failure in Multi tenant authorization

Vallum Threat Model · Under review

Cascading Revocation Failure in Evidence provenance certification

Vallum Threat Model · Under review

Authorization Caching Inconsistency in Agent tool execution

Vallum Threat Model · Under review

Authorization Caching Inconsistency in Multi tenant authorization

Vallum Threat Model · Under review

Authorization Caching Inconsistency in Evidence provenance certification

Vallum Threat Model · Under review

Synthetic Evidence Injection in Agent tool execution

Vallum Threat Model · Under review

Synthetic Evidence Injection in Multi tenant authorization

Vallum Threat Model · Under review

Synthetic Evidence Injection in Evidence provenance certification

Vallum Threat Model · Under review

Tenant Boundary Erosion in Agent tool execution

Vallum Threat Model · Under review

Tenant Boundary Erosion in Multi tenant authorization

Vallum Threat Model · Under review

Tenant Boundary Erosion in Evidence provenance certification

Vallum Threat Model · Under review

Key Rotation Gap in Agent tool execution

Vallum Threat Model · Under review

Key Rotation Gap in Multi tenant authorization

Vallum Threat Model · Under review

Key Rotation Gap in Evidence provenance certification

Vallum Threat Model · Under review

Audit Log Tampering in Agent tool execution

Vallum Threat Model · Under review

Audit Log Tampering in Multi tenant authorization

Vallum Threat Model · Under review

Audit Log Tampering in Evidence provenance certification

Vallum Threat Model · Under review