Threat Modeling for AI Systems
A structured security review of how your agents, LLM features and MCP integrations could be misused, delivered one week after a single session with the people who built it.
- Scope
- One week from the session with your team · Design documents up front, no production access
- Built for
- Teams designing an agentic feature, adding tool calling, or connecting an LLM to internal data and systems.
What this service does
I map the complete system, not just the model: users, prompts, agents, tools, memory, retrieval, data stores, external content and the permissions between them. From that architecture I identify assets, trust boundaries, attacker entry points and realistic abuse paths.
The value
You get a shared picture of where risk actually concentrates and which design changes matter most. A trust boundary is a whiteboard edit before launch and a migration after it, so this is the cheap moment to move one. It also gives later penetration testing a focused, defensible scope.
How it runs
I work from your design documents, sent ahead so I arrive prepared, and one session with the people who built it. The model comes back a week after that session. Production access is not required.
I gave a talk on this
Agent TM, a multi-agent system for threat modelingQuestions this work answers
Where can untrusted instructions, data or tool output enter the system?
What can an attacker reach if an agent, identity or permission boundary fails?
Which mitigations reduce the most credible risks before production?
What you get
04- D/01Architecture and data-flow diagram covering models, agents, tools, memory, retrieval and external dependencies
- D/02Trust boundaries, assets, entry points and abuse paths documented against the real design
- D/03Prioritized threat register mapped to OWASP guidance for LLM and agentic systems, plus MITRE ATLAS
- D/04Mitigation plan and working session to turn findings into concrete architecture decisions
All services
Something already in production you are not sure about?
Tell me what you are building and what worries you about it. If it is not something I can help with, I will tell you that too.

