Imagine you're building a house, and instead of a single floor plan, you bolt together rooms designed by different architects — a kitchen from one, a bathroom from another, a front door from a third. Each room might be fine on its own, but the seams between rooms are where burglars get in. That's the security problem with Retrieval-Augmented Generation: the pipeline stages (ingestion, retrieval, generation, output) each introduce attack surfaces, and the real danger lives at the joints. The committed claim here: this is the first formal meta-model that captures explicit causal chains from RAG pipeline surfaces through attacks, weaknesses, and risks to CIA (Confidentiality, Integrity, Availability) impacts. Not a checklist. Not a taxonomy. A directed graph where you can follow a path from 'poisoned document in the knowledge base' through 'retrieval contamination' to 'integrity breach in generated output.' The authors built this iteratively from 43 publications spanning 2023–2026, producing a populated catalog of threats and remediations. The architecture is a meta-model in the formal sense — an ontology with defined entity types (surfaces, attacks, weaknesses, risks, mitigations) and typed causal relationships between them. It sits in the threat-modeling family alongside STRIDE, MITRE ATT&CK, and OWASP frameworks, but is purpose-built for the RAG pipeline rather than adapted from general software or LLM-only threat models. The key structural choice is making the causal chain explicit and navigable, rather than presenting a flat list. An interactive web visualizer lets users filter by deployment configuration (textual, graph-based, or multimodal RAG) to produce a risk profile specific to their system. The most actionable finding from the catalog analysis: there is a persistent imbalance between attack-focused and defense-focused research. The literature is heavily skewed toward demonstrating new attacks, with far fewer papers proposing validated mitigations. Ingestion — the stage where external documents enter the knowledge base — concentrates the most threats. Output integrity has notable coverage gaps, meaning the field has not yet adequately addressed how to ensure generated answers haven't been corrupted by upstream poisoning. The authors map their catalog against the OWASP LLM Top 10 as a coverage check, which provides a useful external anchor. The validation regime is literature-based, not experimental. The meta-model's completeness is grounded in coverage of 43 papers, not in penetration testing or red-teaming of live RAG systems. This is a strength for comprehensiveness but a weakness for proving that the causal chains hold in deployed systems under adversarial pressure. The authors acknowledge this scope: the contribution is a framework for security engineers to reason about risk, not a proof that any specific mitigation works. The obvious next step the authors did not take: instantiating the meta-model against a real, production RAG deployment and running adversarial testing to see whether the predicted causal chains actually fire. This would transform the contribution from a reasoning tool to an empirical validation. The honest read is (a) — this is a different kind of work (systematization of knowledge, not attack/defense experimentation), and live red-teaming would require a different team, budget, and IRB posture. The framework is designed to enable exactly that next step. For practitioners deploying RAG systems today, the immediate value is the filterable catalog and the ingestion-concentration finding. If you're hardening a RAG system and have limited security budget, this paper tells you where to spend it first: ingestion and output integrity. The web visualizer moves this from 'read the paper' to 'navigate the graph,' which is a meaningful usability contribution for security teams who need to scope threat models without reading 43 papers themselves.