Application Capability Threat Model

Hi all,

I've opened an issue to request a threat model (re-)review of the 
Application Capability specification:

https://github.com/w3c/threat-model-web/issues/22

(Not sure if there is a more suitable repository for the issue based on 
https://www.w3.org/groups/ig/security/tools/ , but happy for it to be 
moved.)

Application Capability is a declarative description of an application's 
capabilities, requirements, and policies that other consumers, such as 
applications, servers, and user agents, can discover and act on:

https://dokieli.github.io/application-capability/

The specification already includes a Threat Model section, so the 
request here is to identify any errors or improvements that can be made.

Thanks!

-Sarven
https://csarven.ca/#i

Received on Friday, 4 September 2026 06:32:43 UTC