# CAIN-42 Evolution 14 — Threat Model
## Capability, skill, tool, plugin and model supply chain

### Assets
Execution authority; credentials; tenant data; the integrity of capability identity (artifact ↔ manifest ↔ id);
the lease/token chain from decision to execution; the evidence of what ran.

### Trust assumptions
* The fabric's Ed25519 key and the E8 boundary key are held by the operator, outside the agent's reach.
* Publisher keys in `PublisherRegistry` were registered by an operator after out-of-band verification.
* The commit boundary (or the hypervisor hook) is actually on the execution path. **A path that bypasses it is not
  governed**, and E14 makes no claim about it (UNCONTROLLED / UNVERIFIED / UNKNOWN).
* In-process state (registries, spent nonces) is not persisted by E14 itself; a process restart loses spent-nonce
  memory unless the host persists it (the E8 `AuthorizationRegistry` has the same property).

### Adversaries
A compromised or confused agent; a malicious or compromised publisher/plugin/tool server; a colluding set of
agents; poisoned tool output, memory or model output; an attacker racing a revocation or mutating a capability
between check and commit.

### Threats → controls → test (all in `CAIN-42-E14-Capability-Bench`, 44 scenarios)

| Threat | Control | Scenario(s) |
|---|---|---|
| Fake tool / skill identity, id collision | `integrity()` at discovery; forged objects never stored | fake_tool_identity, fake_skill_identity |
| Fake / substituted publisher | `PublisherRegistry.verify`; lineage check across publishers | fake_plugin_publisher, publisher_substitution |
| Unsigned artifact, broken provenance chain | admission rejects | unsigned_capability, provenance_discontinuity |
| Artifact / manifest substitution after admission | lease validation recomputes manifest; commit checks attested artifact | artifact_substitution, manifest_substitution |
| Dependency substitution, hidden dependency, revoked dependency | `DependencyLock`, observed-dependency check, dependency revocation cascade | dependency_substitution, hidden_dependency, C27 |
| Malicious upgrade, downgrade | drift SUSPICIOUS + admission MALICIOUS_UPGRADE / VERSION_ROLLBACK | malicious_upgrade, downgrade_attack |
| Lease replay / expiry / revocation | nonce spent at commit; TTL ≤ 120 s; revocation registry | replayed_capability_lease, expired_lease, revoked_lease |
| Drift while leased | `revalidate` invalidates leases | capability_drift |
| Authority / delegation / subagent escalation | grant ⊆ issuer authority; child ⊆ parent; TTL/budget/risk/depth shrink | authority_escalation, delegated_privilege_escalation, subagent_privilege_escalation |
| Collective laundering (split dangerous pair across agents) | composition over the collective's union | collective_privilege_laundering |
| Tool output / model output / memory as authority | none of them has an authority path; forged leases fail signature/registry | tool_output_privilege_injection, model_generated_privilege_request, memory_based_privilege_escalation |
| Credential laundering / secret→authority | binding bound to agent/capability/purpose; `authority_from_credential` = NONE; dangerous single-capability combos refused | credential_laundering, secret_to_authority_escalation |
| Composition / chaining | combined surface + `feeds` chains | composition_attack, capability_chaining |
| Cross-tenant leakage | capability tenant scope; lease tenant = action principal | cross_tenant_capability_leakage |
| Sandbox escape, network / filesystem / credential scope | default-deny profile, normalized paths, exact hosts | sandbox_escape_attempt, network_scope_violation, filesystem_scope_violation, credential_scope_violation |
| Stale decision / policy / authority / evidence | `CapabilityDecisionBinding` + lease current-state check + E8 bindings | stale_* |
| Decision / action / credential substitution | binding + token + lease scope + credential digest | decision_capability_substitution, capability_action_substitution, capability_credential_substitution |
| Revocation race, TOCTOU mutation | re-check inside `execute`; E8 strict capability bindings at commit | emergency_revocation_race, toctou_capability_mutation |
| Confused deputy | lease agent = action agent = token agent; hypervisor hook keyed by ZoD agent | confused_deputy_attack |
| Unknown → allow | unknown permission/side-effect refused; UNKNOWN drift suspends; no UNKNOWN → ADMITTED transition | unknown_to_allow_escalation |
| Hardware-attestation claim | software attestation cannot claim hardware; hardware requirement unsatisfiable while UNKNOWN | hardware_attestation_claim |

### Residual risk (not mitigated by E14)
* **Semantic behaviour.** A correctly signed, correctly declared tool can still misbehave inside its declared
  scope. `HASH_INTEGRITY ≠ SEMANTIC_TRUTH`.
* **Publisher key compromise** before revocation: signatures verify until the operator revokes the publisher.
* **Vulnerabilities** in admitted artifacts: no vulnerability database (`VULNERABILITY_INTELLIGENCE = UNKNOWN`).
* **OS-level confinement** only for what `cain45.confine` enforces (cgroup CPU/memory, deny-all network, seccomp);
  allowlisted egress, per-path allowlists, browser/GUI/cloud/database controls are policy-evaluated.
* **Hosted path.** E14 is not on the hosted gateway; hosted decisions are governed by the existing pipeline only.
* **Multi-host.** No multi-host run of E14 (`MULTI_HOST_SCALE = UNVERIFIED`).
