- Names, aliases, dates of birth, addresses, emails, and phone numbers.
- Requester identity and authorization evidence.
- Browser sessions, confirmation links, and future mailbox credentials.
- Submission receipts and broker response history.
- Local configuration enters the trusted core.
- Declarative adapters request individual semantic fields.
- The browser transmits selected values to declared domains.
- External broker pages and their resources are untrusted.
- Repository contributions and dependency updates are untrusted until reviewed.
An adapter could attempt to navigate to an attacker domain or request unnecessary fields.
Controls:
- Declarative workflows instead of arbitrary adapter code.
- Semantic field injection rather than complete profile access.
- Manifest validation and per-adapter domain allowlists.
- Human-readable plans and minimum-field review.
- Tests for destinations and submission checkpoints.
Values could leak through logs, URLs, screenshots, fixtures, errors, or issue reports.
Controls:
- Safe summaries and URL sanitization.
- No screenshots, traces, videos, or storage by default.
- Synthetic fixtures and
.invalidaddresses. - Ignored local profiles, receipts, artifacts, and state directories.
- Contribution and issue templates that prohibit PII.
A crash or selector change could produce an uncertain outcome or click the wrong control.
Controls:
- Explicit submission checkpoints.
- Accessible role and label locators.
- Playwright actionability checks.
- No automatic retry after an unknown submission outcome.
- Future persistent state must distinguish prepared, submitted, unknown, and confirmed outcomes.
Automation could improperly evade a service control or misrepresent a subject.
Controls:
- Known CAPTCHA detection and manual checkpoints.
- No CAPTCHA-solving services.
- Interactive login, MFA, residency verification, and identity upload.
- Separate requester capacity and authorization metadata.
A broker page can intentionally or accidentally send entered data to third parties.
Controls:
- All network destinations require manifest declaration.
- Production traffic requires HTTPS.
- Plans display broker destinations before execution.
- New resource domains require adapter review.
- Persistent encrypted state.
- Mailbox integrations and confirmation-link automation.
- Identity-document upload.
- Live broker submissions.
- Plugin execution or untrusted imperative adapter code.
Each feature must update this threat model before implementation.