Skip to content

feat: ramparts-to-ave crosswalk + numbering-mismatch caution - #147

Merged
chaksaray merged 1 commit into
developfrom
crosswalk/ramparts-to-ave
Aug 8, 2026
Merged

chaksaray merged 1 commit into
developfrom
crosswalk/ramparts-to-ave

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Ten mechanism-verified matches from issue #138. Includes the near-miss (CommandInjection) and bidirectional gaps in the note field rather than as mappings, since they're not confirmed matches. Also adds a durable caution to scaling-and-governance.md about OWASP MCP Top 10 numbering not being stable across independently-drafted crosswalks, referencing #138 as the concrete case that surfaced it.

Summary

  • crosswalks/ramparts-to-ave.json: ten Ramparts findings mapped to nine AVE records (EnvironmentVariableLeakage splits across two AVE mechanisms depending on which internal condition fires). All titles, the record count (76), static_record_count (57), and ramparts' commit SHA pulled live, not typed from memory.
  • docs/specs/scaling-and-governance.md Section 4 (new): the MCP01-MCP10 numbering-mismatch caution -- Ramparts' MCP03 (Excessive Agency) and AVE's MCP03 (Tool Poisoning) are unrelated despite sharing a number, since OWASP's MCP Top 10 isn't formally ratified yet and gets independently interpreted by early adopters. States the rule this crosswalk had to follow: match by category meaning, never by tag number.

Test plan

  • python3 scripts/validate_crosswalks.py -- 5/5 valid, ramparts-to-ave.json resolves clean against schema/crosswalk-1.0.0.schema.json
  • python3 scripts/validate_records.py -- 76/76 records valid (unaffected, no record changes in this PR)
  • pytest tests/ -x -q -- 305 passed
  • No new em-dash occurrences in the governance doc addition

From issue #138's mechanism-level verification, not label matching.
Also documents the MCP01-MCP10 numbering-mismatch caution discovered
during that verification in scaling-and-governance.md, so the lesson
outlives one closed issue.
@chaksaray
chaksaray merged commit 3375ec3 into develop Aug 8, 2026
6 checks passed
@chaksaray
chaksaray deleted the crosswalk/ramparts-to-ave branch August 8, 2026 01:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant