Add a capability-token threat model for agent-kernel. Cover assets and trust boundaries around tokens, principals, handles, driver output, policy decisions, and audit traces. Include misuse cases such as token replay, confused deputy, wrong principal binding, unsafe handle expansion, driver tampering, audit-log gaps, and host-code policy bypass. State non-goals clearly: agent-kernel is not a sandbox, not a host authentication system, and not a network isolation layer. Acceptance: document is linked from README/security docs, includes mitigations/test
Add a capability-token threat model for agent-kernel. Cover assets and trust boundaries around tokens, principals, handles, driver output, policy decisions, and audit traces. Include misuse cases such as token replay, confused deputy, wrong principal binding, unsafe handle expansion, driver tampering, audit-log gaps, and host-code policy bypass. State non-goals clearly: agent-kernel is not a sandbox, not a host authentication system, and not a network isolation layer. Acceptance: document is linked from README/security docs, includes mitigations/test