Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
114 commits
Select commit Hold shift + click to select a range
334bb96
Add cfgaudit → AVE crosswalk (static config-auditor) (#67)
predictor2718 Jul 23, 2026
f4d9b4e
docs: scaling and governance policy (#80)
chaksaray Jul 27, 2026
0ce799e
docs: cross-reference scaling-and-governance.md in README (#83)
chaksaray Jul 28, 2026
a367da6
docs: cross-reference scaling-and-governance.md in CLAUDE.md (#82)
chaksaray Jul 28, 2026
79406d0
docs: cross-reference scaling-and-governance.md in CONTEXT.md (#84)
chaksaray Jul 28, 2026
798a9c6
docs: cross-reference scaling-and-governance.md in CONTRIBUTING.md (#85)
chaksaray Jul 28, 2026
43928ee
docs: cross-reference scaling-and-governance.md in GOVERNANCE.md (#86)
chaksaray Jul 28, 2026
ad2ecf2
docs: add status glossary entry, cross-referencing scaling-and-govern…
chaksaray Jul 28, 2026
e94a8de
docs: CHANGELOG entry for scaling-and-governance.md (#88)
chaksaray Jul 28, 2026
8fcc70b
docs: cross-reference scaling-and-governance.md in ARCHITECTURE.md (#89)
chaksaray Jul 28, 2026
86a2a71
feat: validate records and update skills (#91)
chaksaray Jul 28, 2026
a699f5e
fix add ave record skill
chaksaray Jul 28, 2026
5b2b340
feat: AVE-2026-00060 through 00064 -- five new records from policy/co…
chaksaray Jul 28, 2026
fbbb422
Merge remote-tracking branch 'origin/main' into develop
chaksaray Jul 28, 2026
0cedb18
chore: regenerate consolidated records JSON
chaksaray Jul 28, 2026
f4cc426
feat: AVE-2026-00065 -- A2A agent card poisoning via embedded adversa…
chaksaray Jul 29, 2026
c9dce1e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Jul 29, 2026
445a178
fix: stale piranha.bawbel.io reference in README (#99)
chaksaray Jul 31, 2026
a08240e
docs: add researcher-process.md (#101)
chaksaray Jul 31, 2026
8955456
chore: add ave gap diagram (#107)
chaksaray Jul 31, 2026
e1fe630
fix: GOVERNANCE.md deprecation_reason field claim (#106)
chaksaray Jul 31, 2026
2789ac1
docs: add API link and gap diagram to README (#108)
chaksaray Jul 31, 2026
e5953c6
Change image width to 100% in README
chaksaray Jul 31, 2026
b464ed9
docs: link AVE-2026-00046 writeup from its own record (#111)
chaksaray Aug 2, 2026
d8861a5
feat: AVE-2026-00066 -- hallucinated skill-name squatting (HalluSquat…
chaksaray Aug 3, 2026
46fc1ce
feat: AVE-2026-00067 -- skill composition trust transfer (SCR-TrustLi…
chaksaray Aug 3, 2026
c302152
feat: AVE-2026-00068 -- CLI command composition risk (MOSAIC) (#115)
chaksaray Aug 3, 2026
270a263
feat: AVE-2026-00069 -- multimodal image-hidden instructions (SkillCa…
chaksaray Aug 3, 2026
34a692f
feat: AVE-2026-00070 -- distributed cross-agent backdoor fragments (C…
chaksaray Aug 3, 2026
211f71c
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 3, 2026
8e7b0e4
docs: collapsible record index (#119)
chaksaray Aug 3, 2026
375e853
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 3, 2026
d2e597a
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 6, 2026
0f79df3
feat: AVE-2026-00071 -- MCP daemon redirect (container posture) (#128)
chaksaray Aug 6, 2026
ccb716a
feat: AVE-2026-00072 -- MCP server bound to all interfaces (NeighborJ…
chaksaray Aug 6, 2026
66f821e
feat: AVE-2026-00073 -- telemetry/endpoint redirect via static config…
chaksaray Aug 6, 2026
16b459e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 6, 2026
9fa75bb
fix: pytest tests/ (CI's actual invocation) fails to collect tests/te…
chaksaray Aug 6, 2026
dfc9846
Remove 'Bawbel' reference from README (#134)
chaksaray Aug 6, 2026
3032813
feat: AVE-2026-00074 -- reclaimable dead external anchor (SkillJackin…
chaksaray Aug 6, 2026
c6761de
fix: use scoped PAT for dist/ regenerate auto-PR, not default GITHUB_…
chaksaray Aug 7, 2026
ca05ec6
feat: AVE-2026-00075 -- bytecode poisoning (compiled cache/source div…
chaksaray Aug 7, 2026
c22e000
chore: regenerate consolidated records JSON (#139)
chaksaray Aug 7, 2026
ca358df
Merge branch 'main' into develop
chaksaray Aug 7, 2026
79cad0d
feat: AVE-2026-00076 -- natural-language steering of an approval clas…
chaksaray Aug 7, 2026
4785a17
docs: clarify AVE-2026-00073 scope (MCP server URL, agent_card_url) (…
chaksaray Aug 7, 2026
772f768
chore: regenerate consolidated records JSON (#143)
chaksaray Aug 7, 2026
5f889ed
Merge branch 'main' into develop
chaksaray Aug 7, 2026
2fe60c5
fix: escape commit message in notify-ave-site client-payload (#145)
chaksaray Aug 8, 2026
3375ec3
feat: ramparts-to-ave crosswalk + numbering-mismatch caution (#147)
chaksaray Aug 8, 2026
2bd9a36
feat: nova-proximity-to-ave crosswalk (#152)
chaksaray Aug 8, 2026
fefcc62
fix: researcher field attribution rule and worked example (#154)
chaksaray Aug 9, 2026
33ade7a
feat: soft researcher/disclosure misattribution check (#157)
chaksaray Aug 9, 2026
d233d83
chore: regenerate consolidated records JSON (#156)
chaksaray Aug 9, 2026
d1efc63
fix: resolve the 10 records flagged by the researcher/disclosure chec…
chaksaray Aug 9, 2026
1caa0b0
chore: regenerate consolidated records JSON (#159)
chaksaray Aug 9, 2026
5e1e23e
Merge branch 'main' into develop
chaksaray Aug 9, 2026
243b19d
fix: mitre_atlas citation corrections per issue #127's audit (#162)
chaksaray Aug 9, 2026
416882c
chore: regenerate consolidated records JSON (#163)
chaksaray Aug 9, 2026
bb98dd9
Merge branch 'main' into develop
chaksaray Aug 9, 2026
47d628f
fix: ave-record-1.0.0.schema.json's $id still pointed at ave.bawbel.i…
chaksaray Aug 9, 2026
4f9e454
feat: AVE-2026-00077 -- cross-origin tool/resource declaration in a s…
chaksaray Aug 9, 2026
c16a4b9
Merge branch 'main' into develop
chaksaray Aug 9, 2026
ad5267f
chore: regenerate consolidated records JSON (#169)
chaksaray Aug 11, 2026
869b401
docs: add CONTRIBUTORS.md (#172)
chaksaray Aug 12, 2026
6dafbb2
Merge branch 'main' into develop
chaksaray Aug 13, 2026
d9409df
Add AVE-2026-00078/79/80: multi-agent pipeline boundary records (arXi…
chaksaray Aug 14, 2026
bdf12f3
Merge branch 'main' into develop
chaksaray Aug 14, 2026
d11da48
fix: correct AVE-2026-00070 researcher attribution (#182)
chaksaray Aug 14, 2026
dbc56d2
chore: regenerate consolidated records JSON (#180)
chaksaray Aug 14, 2026
ba0b0f1
research: AVE → OpenCRE pilot mapping (Batch 1 submitted, issue open)…
chaksaray Aug 15, 2026
e4db9d4
Merge branch 'main' into develop
chaksaray Aug 15, 2026
4b016ba
docs: independent validation section and technical write-ups (#184)
chaksaray Aug 15, 2026
37c91c7
docs: sync CONTRIBUTING.md with current process (#188)
chaksaray Aug 15, 2026
a6491b3
Sync main into develop, resolves PR #187's conflict (#189)
chaksaray Aug 15, 2026
dbb5b6d
feat: semia-to-ave crosswalk (#190)
chaksaray Aug 15, 2026
ff57a18
Merge branch 'main' into develop
chaksaray Aug 15, 2026
8ec7c2f
feat: skillsentry-to-ave and skill-security-scanner-to-ave crosswalks…
chaksaray Aug 15, 2026
604498a
docs: owasp_asi tagging rule, from the #196 audit (#197)
chaksaray Aug 23, 2026
b5e33bd
fix: owasp_asi mapping audit (48 corrected, 13 confirmed, 11 flagged …
chaksaray Aug 23, 2026
9365f00
chore: regenerate consolidated records JSON (#198)
chaksaray Aug 23, 2026
8602092
Merge branch 'main' into develop
chaksaray Aug 23, 2026
c494f8c
fix: AVE-2026-00048 attribution and remediation branding (#202)
chaksaray Aug 25, 2026
236360e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 25, 2026
8e910fc
Sync main into develop, resolves PR #204's conflict (#206)
chaksaray Aug 26, 2026
a1e50c1
chore: regenerate consolidated records JSON (#203)
chaksaray Aug 26, 2026
228d545
fix: researcher-attribution audit across the corpus (49 of 50) (#205)
chaksaray Aug 26, 2026
3048d1f
chore: regenerate consolidated records JSON (#207)
chaksaray Aug 26, 2026
00b69c5
Sync main into develop, resolves PR #204's conflict (#209)
chaksaray Aug 26, 2026
858d46d
Sync main into develop, resolves PR #204's conflict (again) (#210)
chaksaray Aug 26, 2026
759dddf
docs: fix stale independent-crosswalk count in README (3 -> 8) (#200)
chaksaray Aug 27, 2026
e843ea5
docs: three real improvements surfaced by external critique (#215)
chaksaray Aug 28, 2026
038dbf6
Sync main into develop, resolves PR #222's conflict (#226)
chaksaray Aug 29, 2026
8bdddfa
Sync main into develop, resolves PR #222's conflict (round 2) (#227)
chaksaray Aug 29, 2026
070b8ca
fix conflic test validate data
chaksaray Aug 29, 2026
4827171
fix generated at manifest
chaksaray Aug 29, 2026
824279a
docs: capability-behavior-vulnerability taxonomy audit (all 80 record…
chaksaray Aug 29, 2026
18da735
crosswalks: refresh cfgaudit to v1.13.0 (64 rules onto 27 classes) (#…
predictor2718 Aug 29, 2026
742d897
docs: cross-reference the boundary-failure record family (#233)
chaksaray Aug 29, 2026
8dcddde
Apply external_authority to AVE-2026-00074, clearing its enum-gap fix…
narko4u Aug 29, 2026
543bb3b
feat: standing capability-vulnerability taxonomy check (#231)
chaksaray Aug 30, 2026
81c3665
chore: regenerate consolidated records JSON (#235)
chaksaray Aug 30, 2026
475b18c
Sync main into develop, resolves PR #238's conflict (#239)
chaksaray Aug 30, 2026
f68e888
fix generate manifest time
chaksaray Aug 30, 2026
d997b25
Split the confidence floor warning into two named findings (#242)
astrogilda Sep 2, 2026
c9b8b58
crosswalks: add AVE to MAESTRO pilot (6 records, 3 of 7 layers) (#243)
chaksaray Sep 2, 2026
a6b9605
fix: benchmark-2026-06.md citation audit (closes #241) (#244)
chaksaray Sep 2, 2026
1786eee
docs: contain the benchmark-2026-06.md retraction (#249 follow-up, St…
chaksaray Sep 3, 2026
c35afa9
feat: framework_sources -- record which framework version a mapping w…
chaksaray Sep 3, 2026
1fc097b
feat: framework_sources backfill (owasp_asi, mitre_atlas), and a sche…
chaksaray Sep 4, 2026
fef4109
fix: owasp_mcp audit corrections (39 records) and framework_sources b…
chaksaray Sep 4, 2026
c7e1092
chore: regenerate consolidated records JSON (#258)
chaksaray Sep 4, 2026
8dd1d1f
update ave records latest date
chaksaray Sep 5, 2026
92bb011
docs: generated terms.md with sync check (#262)
chaksaray Sep 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -39,5 +39,8 @@ jobs:
- name: Capability-vulnerability taxonomy soft warning
run: python scripts/check_vulnerability_taxonomy.py

- name: docs/terms.md matches the live schema (hard failure)
run: python scripts/check_terms_sync.py

- name: Run tests
run: pytest tests/ -x -q
9 changes: 9 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -159,6 +159,8 @@ python scripts/write_verification_basis.py # derives verification_basis; repor
python scripts/check_vulnerability_taxonomy.py # soft-warns on records missing security_boundary/missing_control/vulnerability_rationale
python scripts/check_vulnerability_taxonomy.py --strict --only AVE-2026-NNNNN # your new record must carry all three taxonomy fields
python scripts/check_framework_sources.py --strict --only AVE-2026-NNNNN # if your record carries owasp_mcp/owasp_asi/mitre_atlas/nist_ai_rmf, each needs a framework_sources entry
python scripts/generate_terms.py # regenerate docs/terms.md after any schema field or description change
python scripts/check_terms_sync.py # hard failure if docs/terms.md disagrees with the live schema -- run before opening a PR
pytest tests/ -x -q # full suite: schema, AIVSS arithmetic, mitigation enums
```

Expand Down Expand Up @@ -240,6 +242,13 @@ Current schema: **v1.1.0**.
Canonical file: `schema/ave-record-1.1.0.schema.json`.
(`schema/ave-record-1.0.0.schema.json` remains, permanently, as the frozen v1.0.0 canonical.)

**Any change to a field's description, additive or structural, requires
regenerating `docs/terms.md`**: `python scripts/generate_terms.py`, then
confirm with `python scripts/check_terms_sync.py` before opening the PR.
That file's per-field definitions are generated from the schema's own
descriptions and are never hand-edited; `check_terms_sync.py` is a hard
CI failure, not a soft warning, if the two disagree.

---

## Improving existing records
Expand Down
2 changes: 1 addition & 1 deletion dist/ave-records-latest.manifest.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema_version": "1.1.0",
"record_count": 80,
"generated_at": "2026-09-04T23:22:53.346Z",
"generated_at": "2026-09-04T23:32:41.508Z",
"source": "https://github.com/aveproject/ave"
}
76 changes: 76 additions & 0 deletions docs/terms-relationships.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
**confidence_baseline vs. verification_basis**: confidence_baseline is a
float a record's author assigns as a scanner hint (a starting-point
confidence for a single-engine match, before false-positive adjustment)
— the same shape whether the underlying evidence is a formally disclosed
CVE or a speculative pattern match. verification_basis is computed, never
authored, derived from a record's own evidence_vantage and evidence_method,
each taken by weakest input together with the vantage its
evidence_basis_engines set can reach. A declared verification_basis is
checked against this derivation by validate_records.py and rejected if
they disagree; confidence_baseline has no equivalent check — it stays a
self-report by design. See issue #98 for why the distinction exists,
raised independently from two unrelated angles (a supply-chain
attestation engineer and a compliance/governance reader) that converged
on the same underlying gap.

**evidence_vantage vs. evidence_method**: two independent axes, not a
single scale. evidence_vantage says where an observation was obtained
(substrate: somewhere the artifact could neither forge nor suppress it,
versus artifact: derived from something the artifact itself produced).
evidence_method says how it was established (intercepted: captured live
as events occurred, versus reconstructed: examined after the fact).
Absence on either axis reads as its floor value (artifact, reconstructed
respectively) rather than a stronger claim by default. A record can be
`substrate_reconstructed` — evidence externally verifiable but assembled
after the fact — which is a real, legitimate combination the schema's own
verification_basis enum names explicitly, not a contradiction.

**entry_class vs. detection_layer vs. detection_stage**: entry_class
(inside provenance_vector) names where in a component's context supply
chain a behavior enters — a closed vocabulary of content, server_card,
registry_metadata, runtime, transport, tool_response, tool_schema,
server_card_document, model_generated, memory, retrieved_document,
user_input, operator_config, or skill_file. detection_stage names when a
scanning approach caught it: static_detection or runtime_observed.
detection_layer names what layer of the agent ecosystem the detection
mechanism inspected (content, server_card, registry_metadata, runtime, or
transport) — and entry_class's own schema description says to reuse the
record's detection_layer value directly when the class is layer-scoped,
falling back to a more precise session-scoped token from its own broader
vocabulary only when detection_layer isn't precise enough. The three
fields answer different questions about the same finding (where it
enters, what layer catches it, when in the lifecycle it's catchable) and
are easy to conflate because all three sound like "where/when did this
happen" — but entry_class and detection_layer are deliberately designed
to share values in the common case, not to always diverge.

**security_boundary vs. missing_control**: security_boundary names the
trust boundary crossed (untrusted content to instruction context, agent
to agent, human approval to autonomous action, and so on) — it answers
audit question Q2, the question this project's own capability-vulnerability
audit treats as the sharpest single check distinguishing a real
vulnerability from a bare capability or technique description.
missing_control names the specific absent check that makes crossing that
boundary possible (no explicit tool allowlist, no provenance label, no
approval gate). A record can state the boundary without stating the
control, or vice versa, but a record with neither is a candidate for
capability-only or technique-only conflation per that same audit (#224).

**owasp_mcp / owasp_asi / mitre_atlas / nist_ai_rmf vs.
framework_sources**: the first four are the mapping itself — which
category a record corresponds to in an external framework.
framework_sources is provenance for that mapping — which version or
commit of the referenced framework the mapping was made against. A
record can carry the mapping without the provenance; as of the last
corpus-wide backfill pass, `owasp_mcp` (required on every record) and
`owasp_asi` have full coverage (80 of 80, and 69 of 69 tagged records
respectively), `mitre_atlas` is partially backfilled (40 of 50 tagged
records, covering exactly the ones a dated, citable audit event actually
verified), and `nist_ai_rmf` has none yet — no audit trail for it was
ever found in this project's history. framework_sources exists
specifically because an unversioned or unratified framework's category
meaning can shift under an unpinned mapping: see
OWASP/www-project-mcp-top-10#52, the live case (not a hypothetical) that
prompted the field, where two independent projects assigned the same MCP
category number to genuinely unrelated categories because each read the
spec at a different point while it was still moving.
Loading
Loading