PRODUCT GUIDE
threat model
Local software · limited supported scope
Threat model
Assets: vendor CBOM, internal source locations, customer questions, generated statements. Trust boundary 1 is untrusted JSON/XLSX/CSV into local parser. Boundary 2 is internal evidence into customer-facing artifacts. Boundary 3 is customer pack leaving the vendor after human approval.
| Threat | PoC control | Residual risk |
|---|---|---|
| XLSX ZIP bomb or traversal | size, expansion, ratio and name checks; no archive extraction | OOXML parser bugs remain possible |
| Formula injection | question-cell formulas are skipped; generated text is escaped; original template formulas are preserved without evaluation | malicious formulas already present in a customer workbook can remain in the copied output; vendor must inspect untrusted templates |
| Secret/path disclosure | whitelist output fields; public evidence IDs; internal map excluded from ZIP; high-confidence secret and absolute-path screening | free text and existing workbook content may still be sensitive; no DLP guarantee |
| Fabricated technical claims | bounded known algorithm/library names, no component-name fallback, deterministic eligibility and UNKNOWN/owner states | incomplete or false CBOM can still contain incorrect positives |
| Misuse of absence as a negative | no absence-based “No” answers | reviewer may overread PARTIAL |
| Stale evidence | CBOM timestamp exposed; no freshness claim | timestamp may be wrong |
| Dependency compromise | two pinned MIT/Expat packages; no runtime network | package integrity must be managed at installation |
| Wrong-cell XLSX write-back | exact header aliases, all-sheet scan, ambiguity stop, explicit vendor-user mapping, empty target check and preservation tests | unusual templates can still be misidentified; vendor must compare output |
| Customer workbook damage or unwanted overwrite | source/output path inequality, separate output copy, existing values including whitespace/formulas preserved, protected/merged targets skipped | unsupported Excel features can be lost by the XLSX library |
| Unreviewed existing answer in customer ZIP | original content is preserved and approve_existing is required for finalization | vendor may bypass the workflow by sending a local draft manually |
| Ambiguous or unsupported template creates unsafe output | preflight blocks compile; reusable user mapping is explicit; every nonempty unmapped sheet needs content-bound vendor acknowledgement; unsupported OOXML parts and target cells are rejected | vendor can incorrectly acknowledge a question sheet, so counts and sheets still need review |
| Unseen workbook content leaks through write-back | preflight rejects hidden sheets and hidden rows/columns before compilation | visible comments, free text and metadata may still be sensitive; vendor reviews output |
| Stale or misapplied organizational statement | exact product scope, approval/expiry date, exact-question or narrow canonical-intent match, separate OWNER_APPROVED status | a vendor reviewer can approve a false or outdated assertion |
| Submission without review | compile creates visibly marked draft only; finalize requires a decision for each row, checks public artifact and original source-input hashes, and binds review IDs/evidence/status eligibility to the fingerprinted manifest | local files can always be copied manually; approval identity is self-declared |
| Wrong-product organizational answer | library scope must exactly match the supplied CBOM product name; narrow question/answer templates and expiry checks | CBOM identity and reviewer authority are self-declared |
No source repository scan, secret retrieval, private key storage, external transfer or remote execution is in scope. A production release would need schema validation, fuzzing, signature/provenance controls for CBOM origin, secure local storage guidance, and independent security review.