MAESTRO Security Framework for Claude Code Projects
Apply the MAESTRO 7-layer threat-modeling framework to any autonomous Claude Code / Agent SDK project — enumerate threats across the whole chain and fill in a reusable threat model for your own stack.
- ▸**01 — Threat Enumeration Worksheet:** 50 pre-populated threat rows across all 7 MAESTRO layers plus 8 Claude Code–specific extension IDs. Fill in three columns for your stack: Affects My Project, Notes, Mitigation Status.
- ▸**02 — Trust Boundary Diagram:** Mermaid diagram of the full Claude Code / Agent SDK attack surface — 5 named trust boundaries with annotations. Paste into any Mermaid renderer and customize for your topology.
- ▸**03 — MCP Server Vetting Checklist:** Initial onboarding checklist (run once per server) and quarterly audit checklist. Covers the vulnerability classes most commonly missed on first deploy.
- ▸**04 — CLAUDE.md Injection Scenarios:** Three documented attack scenarios — tool-result write-back, settings.json escalation via MCP, and git-pull poisoning — each with attacker narrative, detection signals, and a mitigation checklist.
- ▸**05 — CI/CD Integration Guide:** Copy-paste GitHub Actions workflow that gates every PR on threat model currency. Includes a sovereignty-mode threat delta appendix for local Ollama deployments.
## goes-well-with
From the same shelf
Agentic Migration Playbook: API Endpoint Modernization
For DevOps and platform engineers with a real migration deadline — the complete Claude Code workflow you'd otherwise spend months reverse-engineering.
MCP Tunnel Explainer: Private Network MCP Without Public Endpoints
A hands-on tutorial and code walkthrough showing how to wire a local Ollama MCP server behind an outbound-only encrypted tunnel — no public IP, no inbound firewall rules, yet agents still reach private enterprise tools.
Prompt Injection Defense Toolkit for Claude Code Users
Detect injected instructions in fetched content, audit tool call chains, and run agentic workflows safely — the prompt injection defense guide Anthropic hasn't written yet.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.