# Attack surface > Living inventory of everything this project has deployed and its exposure. Updated whenever infrastructure changes and before each security review, via the `attack-surface` skill. Contains **no secrets** — only references to where secrets live. ## Assets | Asset | Type | Tech / version | Hosted | Auth in | Exposure | Defenses | Review cadence | | --- | --- | --- | --- | --- | --- | --- | --- | | _[none mapped yet]_ | | | | | | | | ## Per-asset notes ## Model / harness input surface Injection-relevant inputs to model calls (kept in sync by the `prompt-injection-audit` skill). | Input avenue | Consuming model | Reachable tools | Exposure | Defense in place | | --- | --- | --- | --- | --- | | _[e.g. web fetch results]_ | | | | | ## Gaps / unknowns - Inventory not yet populated. Run the `attack-surface` skill once real infrastructure exists, and `prompt-injection-audit` once the app makes model-driven tool calls.