

Also from Kynth Studios


Also from Kynth Studios


Also from Kynth Studios
1# Threat Model23This project maintains a living threat model at [`docs/threat-model.md`](docs/threat-model.md).45The threat model describes:67- The implicit contract between Apache Dubbo and its downstream users8- Trust boundaries, adversary model, and assumptions about the deployment environment9- Security properties Dubbo provides (conditional on configuration)10- Security properties Dubbo explicitly does *not* provide11- Downstream responsibilities for integrators12- Known misuse patterns and recurring false positives13- Triage dispositions for classifying vulnerability reports1415## For vulnerability reporters1617Before reporting, consult the threat model to determine whether the finding:1819- Violates a claimed security property (§8) — report to [security@dubbo.apache.org](mailto:security@dubbo.apache.org)20- Falls under an out-of-scope or by-design disclaimer (§3, §9) — will be closed citing the threat model21- Matches a known non-finding (§11a) — already documented as a false positive2223## For automated security tools2425The threat model includes a machine-readable companion structure (§15) and a triage disposition table (§13) that can be used to automate report classification.2627Key triage dispositions:2829| Disposition | When to apply |30|-------------|--------------|31| `VALID` | Violates §8 property via in-scope adversary |32| `OUT-OF-MODEL: trusted-input` | Requires attacker control of trusted registry/config |33| `OUT-OF-MODEL: adversary-not-in-scope` | Requires excluded attacker capability |34| `BY-DESIGN: property-disclaimed` | Concerns property explicitly disclaimed in §9 |35| `KNOWN-NON-FINDING` | Matches documented false positive in §11a |36
Same format, overlapping stack, ranked by quality.
| Repository | Format | Stack | Covers | Score | Changed |
|---|---|---|---|---|---|
| n8n-io/n8npackages/@n8n/agents/AGENTS.md · 200k | AGENTS.md | buildteststylearch+3 | 100/100 | 14 days ago | |
| aaif-goose/gooseAGENTS.md · 53k | AGENTS.md | setupbuildtestlint-format+7 | 100/100 | 8 days ago | |
| duckduckgo/content-scope-scriptsspecial-pages/AGENTS.md · 70 | AGENTS.md | buildteststylearch+3 | 100/100 | 14 days ago | |
| TryGhost/Ghoste2e/AGENTS.md · 55k | AGENTS.md | setupteststylearch+2 | 100/100 | 14 days ago | |
| vllm-project/vllmAGENTS.md · 88k | AGENTS.md | setuptestlint-formatstyle+5 | 100/100 | 14 days ago | |
| elastic/elasticsearchx-pack/plugin/inference/AGENTS.md · 78k | AGENTS.md | buildtestlint-formatstyle+3 | 100/100 | 14 days ago | |
| rails/railsAGENTS.md · 59k | AGENTS.md | teststylearchgit+4 | 100/100 | 14 days ago | |
| wpscanteam/wpscanAGENTS.md · 9.7k | AGENTS.md | setupbuildteststyle+6 | 100/100 | 13 days ago |
A badge carrying the measured quality of the strongest agent config file in this repository, out of 100. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://rulestack.kynth.studio/configs/apache-dubbo-agents)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.