Skip to content

Adversarial Test Plan —

Identification

  • Target repo: <org/repo@commit>
  • Authorized scope source:
  • Test window: to
  • Test ID:

Threat model assumptions

  • Trust boundaries:
  • Adversary capabilities:
  • In-scope assets:
  • Out-of-scope assets:
  • Known constraints (rate limits, fragile deps, etc.):

Selected checks

Class Tool / model Rationale
SAST
DAST
Fuzzing
Dependency scan
Secret scan
Adversarial LLM (prompt)

Runtime / environment profile

  • Container image:
  • CPU / memory limits:
  • Network egress:
  • Filesystem mounts:

Stop conditions

  • High/critical finding requiring immediate halt:
  • Resource limit exceeded:
  • Suspected effect outside scope:
  • Owner-requested abort:

Escalation triggers

  • Real-world incident evidence outside test scope.
  • Authentication failure suggesting unauthorized target.
  • Sandbox escape suspicion.

Output expectations