threat-modeling.sgit.ai / admin / comms
Comms: tasks, requests & status
The working channel between the founder and the site agent, kept in public on the site itself — which is an instance of the discipline this site argues for. Current release: v0.1.0, 8 September 2026. Full history: versions.
Needed from the founder
| # | Request | Why it blocks | Status |
|---|---|---|---|
| N1 | The closure pass (comms Q1, from the commissioning pack). Every finding in the practice section — the seven threat models, the validated pair — dates from February–March 2026. Which findings are fixed, and which are still open, as of today? This gates a fuller findings table on /validated/ and a fuller /practice/: nothing may be published as open or closed until re-checked against current code. | The single launch blocker named in the commissioning pack | waiting on the founder |
| N2 | Recompute the vault figures from source. 51 nodes, 179 threats, 3 critical findings are currently quoted from the vault's own published index page, not computed from the vault's underlying JSON on this site's own build. Access to that JSON (or confirmation it is already reachable from this repo's build environment) would let /eleven-layers/ mark these as generated rather than quoted. | Affects one page's honesty label, not the pipeline | open |
| N3 | The ThreatModCon 2025 talk itself. Slides, a recording if one exists, and the abstract are not in the commissioning pack. If they exist, /eleven-layers/ should carry them. | Nice-to-have; does not block the current page | open |
| N4 | StrideGPT contact. Has any contact been made with the maintainer of StrideGPT (mrwadams/stride-gpt), named on /graph/ as the first integration target? The page currently states this as intention only and should not imply a partnership that doesn't exist. | Affects one paragraph's wording, not the pipeline | open |
| N5 | Threat models 4 and 5, read in depth. The token-consumption-flow and office-document-viewers-and-print threat models are catalogued (date, title, path) but have not had a full read-and-publish pass. Confirm whether they should get their own pages under /practice/ once read. | Expands /practice/; does not block the current pages | open |
| N6 | A security.txt disclosure policy for the sgit.ai network as a whole (commissioning pack Q6) — does one exist yet? This site ships its own /.well-known/security.txt regardless, but a network-wide policy would let this one point at it. | Cosmetic until asked | open |
| N7 | Cross-link the mandatory-disclosure position with the subscriptions site's legislative model as a single "our regulatory positions" thread across the network (commissioning pack Q7)? A founder-level editorial call, not a site-agent one. | Nothing blocks; a cross-link is one paragraph whenever decided | open |
Task board
| # | Task | Owner | Status |
|---|---|---|---|
| T1 | CI pipeline: validate → auto-tag → deploy to Pages, copied from pki.sgit.ai and influences.sgit.ai. Release gate extended with two rules specific to this site: the 40-word cap on quotations attributed outside this site, and the file-and-line disclosure-location tripwire | site agent | done v0.1.0 |
| T2 | Shared chrome: nav and footer from one definition in admin/build/chrome.py, rewritten in place across every page; the version badge is read at load time from assets/version.js rather than stamped into every page, so a release does not need to rewrite the whole tree — the lesson pki.sgit.ai learned at v0.1.66, applied here from the first release | site agent | done v0.1.0 |
| T3 | Theme carried over from influences.sgit.ai and pki.sgit.ai, with this site's own additions: verdict pills, the claim/check two-column block, the eleven-layer ladder, STRIDE status cells, the disclosure held-count box and the boundary marker | site agent | done v0.1.0 |
| T4 | Full site built from the commissioning pack: front page, eleven-layers, validated, all seven papers, practice with three sub-pages, graph, disclosure, agentic, network, participant disclosure, shipped | site agent | done v0.1.0 |
| T5 | Commissioning pack published verbatim under /briefs/, with a reader page per document generated under /documents/ via gen_documents.py | site agent | done v0.1.0 |
| T6 | llms.txt, generated /llms-full.txt (this site's own words plus every source document), generated /sitemap.xml, /robots.txt, /.well-known/security.txt | site agent | done v0.1.0 |
| T7 | The closure pass (N1) — re-check every February–March 2026 finding against current code, and publish the fuller findings table this unblocks | site agent, pending the founder's input | queued |