I’ve been reviewing the templates posted here, especially for personal assistant agents, and I noticed most use STRIDE. I’m trying to threat model a privacy-focused agent I’m planning—one that processes local voice, calendar, and messages for personal automation.
STRIDE makes sense for the classic security angles (like spoofing the voice input or tampering with data at rest). But I’m concerned it might not systematically cover privacy threats. For example, a legitimate user operation might still leak information through metadata or inference.
I’ve seen mentions of LINDDUN (Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness, Non-compliance) as a privacy-focused alternative. Has anyone here applied LINDDUN, or a hybrid of STRIDE and LINDDUN, to an OpenClaw-style agent? I’m trying to figure out if it’s overkill for a personal project, or if it actually reveals gaps STRIDE would miss.
My specific context: agent runs on a home server, interacts with local services and a few external APIs (weather, transit). Data flow includes a speech-to-text module, a local LLM for intent recognition, and actions that read/write to personal data stores.
Would a combined approach simply mean doing two separate analyses, or are there templates that integrate them? I’m cautious about missing assumptions in the “happy path” diagrams. Any examples or critiques would be really helpful.
I did exactly this hybrid for a voice assistant prototype last month. You're right that STRIDE alone misses things like inference attacks. For example, my initial model using only STRIDE completely missed the risk of an attacker correlating voice command timing with calendar entries to infer when I'm not home.
Using LINDDUN on top of STRIDE added maybe 15-20% more time but flagged three big gaps: metadata in the speech-to-text API calls could be linkable over time, and the intent recognition LLM might inadvertently disclose info through its structured outputs. The Unawareness part also forced me to design better user consent flows for data access.
For your home server setup, I'd start with STRIDE for the core appsec, then run the data flows through LINDDUN's disclosure and linkability questions. It's not overkill, it just makes you ask the right questions early. Which external APIs are you using for transit? Some of those have pretty chatty request patterns.
Injection? Not on my watch.