Contributing to the threat model
기준일: 2026-07-26
공식 기준: Contributing to the threat model
Contributing to the threat model 문서는 OpenClaw 공식 문서(security/CONTRIBUTING-THREAT-MODEL)를 한국어로 정리한 가이드입니다. How to contribute to the OpenClaw threat model 명령·설정 키·코드 예시는 공식 문서를 그대로 보존하며, 해석과 절차 안내는 한국어로 제공합니다. 최종 동작은 설치된 CLI 버전과 공식 원문을 확인하세요.
핵심 요약
How to contribute to the OpenClaw threat model
한국어 가이드 범위: security/CONTRIBUTING-THREAT-MODEL 경로의 설정·명령·제약·예시를 학습용으로 재구성합니다.
문서 구성
공식 문서의 주요 섹션은 다음과 같습니다.
- Ways to contribute
- Framework reference
- Review process
- Resources
- Contact
- Recognition
- 관련 문서
상세 내용
본문
The threat model is a living document. Contributions are welcome from anyone; you do not need security or MITRE ATLAS background.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
Ways to contribute
Maintainers assign the ATLAS mapping, threat ID, and risk level during review.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
주요 항목:
- The attack scenario and how it could be exploited.
- Which components are affected (CLI, gateway, channels, ClawHub, MCP servers, etc.).
- Your estimate of severity (low / medium / high / critical).
- Links to related research, CVEs, or real-world examples.
Framework reference
Threats are mapped to MITRE ATLAS (Adversarial Threat Landscape for AI Systems), a framework for AI/ML-specific threats like prompt injection, tool misuse, and agent exploitation. You do not need to know ATLAS to contribute; maintainers map submissions during review.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
| Code | Category |
|---|---|
| RECON | Reconnaissance - information gathering |
| ACCESS | Initial access - gaining entry |
| EXEC | Execution - running malicious actions |
| PERSIST | Persistence - maintaining access |
| EVADE | Defense evasion - avoiding detection |
| DISC | Discovery - learning about the environment |
| EXFIL | Exfiltration - stealing data |
| IMPACT | Impact - damage or disruption |
| Level | Meaning |
|---|---|
| Critical | Full system compromise, or high likelihood + critical impact |
| High | Significant damage likely, or medium likelihood + critical impact |
| Medium | Moderate risk, or low likelihood + high impact |
| Low | Unlikely and limited impact |
Review process
- Triage - new submissions are reviewed within 48 hours. 2. Assessment - maintainers verify feasibility, assign ATLAS mapping and threat ID, validate risk level. 3. Documentation - formatting and completeness pass. 4. Merge - added to the threat model and visualization.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
Resources
주요 항목:
- ATLAS website
- ATLAS techniques
- ATLAS case studies
Contact
주요 항목:
- Security vulnerabilities: Trust page for reporting instructions, or
security@openclaw.ai. - Threat model questions: open an issue on openclaw/trust.
- General chat: Discord
#securitychannel.
Recognition
Contributors to the threat model are recognized in the threat model acknowledgments, release notes, and the OpenClaw security hall of fame for significant contributions.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
관련 문서
주요 항목:
- Threat model
- Incident response
- Formal verification
실습 체크리스트
- 공식 문서와 로컬 버전을 대조합니다:
https://docs.openclaw.ai/security/CONTRIBUTING-THREAT-MODEL - 관련 CLI는
openclaw --help및 하위 명령--help로 옵션을 확인합니다. - 설정 변경 시
openclaw config/openclaw doctor로 유효성을 검사합니다. - Gateway·채널·플러그인 변경 후에는 필요 시 Gateway를 재시작합니다.
관련 링크
이 가이드는 공식 문서를 한국어 학습용으로 재구성한 것입니다. 옵션 기본값·플래그 이름은 설치 버전에 따라 달라질 수 있습니다.