Get Reachability Verdicts
get_reachability_verdictsDetermine if components or attack paths are reachable in a threat model by retrieving per-CO reachability verdicts. Supports single-model and composed-tree analysis.
Instructions
Per-CO reachability verdicts, over this model alone or the composed tree. Read-only; derived each time, never stored.
composed=False (default): derived from this model's own structure
(components, asset.component_ids, trust_boundary.passes, each
attacker's trust_boundary_ids and vector, assumption exclusion
predicates), deterministic, the derivation an auditor re-runs.
co_id returns one verdict (404 if absent or tombstoned). Returns
{model_id, model_version, verdicts: [{co_id, kind, reason, narration, boundary_id?, assumption_id?}]}; kind is reachable,
unreachable or indeterminate.
composed=True: the same derivation over the model with everything
it inherits from its ancestors, for a child on the composition tree.
Paginated (page, page_size); kind_filter keeps one kind;
co_id is ignored. Returns {model_id, flag_enabled, verdicts: [{co_qid, asset_qid, attacker_qid, kind, reason}], total, page, page_size}, empty with flag_enabled: false where composition is
not available.
An indeterminate verdict names the missing structure:
attacker_unpositioned (edit_attacker with
trust_boundary_ids), asset_unbounded
(assign_to_components(target_type="asset")), no_shared_boundary
(reposition the attacker, rescope the asset, or an add_assumption
exclusion), missing_entity (restore it, or remove the CO).
model_coherence_report presents the same gaps as findings.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | ||
| co_id | No | ||
| composed | No | ||
| model_id | Yes | ||
| page_size | No | ||
| kind_filter | No | ||
| server_version | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||