Automated quarterly reminder issued by .github/workflows/quarterly-threat-model.yml.
2026-Q3 Threat Model Exercise
Cadence governance per docs/security_cadence.md requires a quarterly threat model exercise.
This issue is the trigger; the actual exercise artifact is produced by following the runbook.
Action Items
Deadline
Complete by end of 2026-Q3 (within 30 days of this issue).
References
- Cadence spec:
docs/security_cadence.md
- Runbook:
docs/red_team_runbook.md
- Scorecard:
docs/red_team_scorecard.md
- Backlog:
docs/red_team_backlog.md
- Discovery engine:
.github/skills/security-audit/SKILL.md (adapted from cloudflare/security-audit-skill, MIT)
If this issue was created in error or already addressed for this quarter, close it with a brief note.
2026-Q3 Threat Model Exercise
Cadence governance per
docs/security_cadence.mdrequires a quarterly threat model exercise.This issue is the trigger; the actual exercise artifact is produced by following the runbook.
Action Items
docs/red_team_runbook.mdfor the exercise procedure.docs/red_team_scorecard.mdfor the scoring matrix.python artifacts/scripts/run_red_team_suite.py --phase static.security-auditskill (.github/skills/security-audit/) to hunt exploitable vulnerabilities; validate itsfindings.jsonwithpython .github/skills/security-audit/scripts/validate_findings.py --findings <run>/findings.json.artifacts/governance/threat-findings-pending-update.*.jsonper SKILL.md Phase 7 (do NOT edit the frozen inventory snapshot).docs/red_team_backlog.md.Deadline
Complete by end of 2026-Q3 (within 30 days of this issue).
References
docs/security_cadence.mddocs/red_team_runbook.mddocs/red_team_scorecard.mddocs/red_team_backlog.md.github/skills/security-audit/SKILL.md(adapted from cloudflare/security-audit-skill, MIT)If this issue was created in error or already addressed for this quarter, close it with a brief note.