NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Back to source intakeMapping studio: 1 of 1 confirmed
dosing-api.openapi.yaml
SRC-0002OpenAPI 3.1 (.yaml)semantic sourceParsed
- Uploaded (passed)03 Apr
- Scanned (passed)03 Apr
- Parsed (passed)03 Apr
- Mapped (current phase)
- Accepted (pending)
- Source id
- SRC-0002
- External version
- v1.4.0-rc.2
- Source system
- Git repository np200-dosing-api @ 61f2c9a
- Author
- Tomas Novak (R&D Manager)
- Captured
- 03 Apr 2026
- Uploaded
- Marcus Chen, 03 Apr 2026, 16:41 UTC
- WarningOAS-W031Operation declares no security scheme; endpoint treated as unauthenticated in candidate model.POST /dose (line 214)
- InfoOAS-I007Remote $ref resolution disabled by policy; all refs resolved locally.
Elements
- AE-000042Infusion dosing command processorOpenAPI POST /dose
Data flows
- DF-000077Remote dosing commandOpenAPI POST /dose (line 214)
None recorded.
- TV-000118Attacker sends unauthorized dosing commandMitigation pending
- TV-000124Replay of captured dosing command re-doses patientTreatment planned
- TV-000140EHR adapter verbose errors leak integration credentialsDismissed
- POST /dose unauthenticated finding fed rule DFL-AUTH-02 (TV-000118)Sourcesystem
- Parse completed (openapi-3x 2.8.0); 12 endpoints extractedSourcesystem
- Scan clean; declared/detected media type matchSourcesystem
- Imported from repository np200-dosing-api @ 61f2c9aSourceMarcus Chen