Threat model

Threat model.

Threat model

Four flows, scored differently.

We take the side of a user who has chosen an agent and a model provider, and who already sends that provider their code. The question is what else happens.

(a) To the model providerThe model request and anything added to it. The user chose this recipient, so identifiers here are not scored as leaks; we report them.Reported
(b) The vendor's own telemetryUsage analytics, metrics, logs and error reports sent to the agent's maker, including data attached to model requests for a separate purpose.Scored
(c) Third-party telemetryThe same kinds of data sent to someone else, such as Sentry, PostHog, Segment, Mixpanel or Datadog.Scored
(d) The fake secretWhere a planted fake secret ends up: it may reach the model provider if the agent reads it, and nobody else.Scored

A telemetry service counts as the vendor's own when a company in the vendor's own group operates it. Update checks and downloads from package registries or GitHub are not leaks; whether the opt-outs stop them is scored separately. Out of scope: what servers do with data after receipt, and logged-in modes other than for agents that require an account.