Add project risk register for mesh safety and AI-assisted development
Purpose
Create a living risk register so the project can explicitly track safety, security, AI, hardware, and operational risks before live Meshtastic work begins.
This helps turn risk awareness into actionable mitigations, tests, SOPs, and follow-up issues.
Scope
Add:
Recommended fields:
Risk ID
Risk description
Category
Severity
Likelihood
Mitigation
Detection method
Tests / controls
Owner
Status
Linked issues
Initial risks should include:
- public mesh spam
- unsummoned public auto-reply
- automatic multi-packet flooding
- live radio accidentally enabled
- private-channel leakage
- secret/PSK/API key exposure
- AI hallucinated response or action
- rate-limit bypass
- hardware disconnect or serial failure
- config drift between docs and implementation
Non-goals
Do not implement mitigations in this issue unless they are documentation-only.
Do not add live hardware behavior.
Do not add runtime code unless a tiny helper is clearly necessary.
Acceptance criteria
Rollback plan
Revise the format if it is too heavy or not useful after initial use.
Add project risk register for mesh safety and AI-assisted development
Purpose
Create a living risk register so the project can explicitly track safety, security, AI, hardware, and operational risks before live Meshtastic work begins.
This helps turn risk awareness into actionable mitigations, tests, SOPs, and follow-up issues.
Scope
Add:
Recommended fields:
Initial risks should include:
Non-goals
Do not implement mitigations in this issue unless they are documentation-only.
Do not add live hardware behavior.
Do not add runtime code unless a tiny helper is clearly necessary.
Acceptance criteria
docs/risk-register.mdexists.README.mdor SOP docs link to the risk register.Rollback plan
Revise the format if it is too heavy or not useful after initial use.