Add Asset
add_assetAdd a new asset to a threat model to capture protected data or resources and their security properties, creating a new version.
Instructions
Add a new asset to a threat model. Creates a new version.
Authoring contract: name the data or resource being protected and
the security property at stake (Confidentiality / Integrity /
Availability / Usage), not a mechanism or control ("per-organization
key-wrapping material", not "KMS encryption"). An asset phrased as a
mechanism is flagged with a quality_warning and yields
under-specified control objectives. An asset that does not apply is
recorded with a non-applicability assumption or
create_co_disposition; there is no status to set.
The platform reasons the factor decomposition and composes impact
with the prompt generation uses, so factors are calibrated alike;
override one afterwards with edit_asset and a change_reason.
component_ids links the asset to the deployable units that hold it,
which feeds reachability (several for a multi-instance asset, e.g. a
session token on client and cache).
A proposal matching a soft-deleted asset is gated: it either restores
that asset (auto_restored: true, restored_asset_id,
discarded_fields; its CO tombstones revive) or is refused as similar
({accepted: false, classification: "similar", candidate_restore_id},
nothing saved). A normal create returns {model, controls_carried, ...}. 503: an evaluator is unavailable, retry with backoff; 502: it
answered malformed, retry.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Asset name (required). | |
| notes | No | Optional notes. | |
| model_id | Yes | ID of the threat model. | |
| description | No | Optional description (recommended — feeds the factor-reasoning prompt). | |
| component_ids | No | Comma-separated component IDs scoping the asset (e.g., "CMP1,CMP2"). Empty / omitted = unscoped. Validated against components declared on the model. | |
| server_version | Yes | ||
| security_properties | No | Comma-separated properties, e.g. "C,I,A" (default: "C"). |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||