Repository navigation
fix: researcher field attribution rule and worked example - #154
Merged
Merged
Conversation
…loguer The go-forward convention (individual name, not a team name) fixed inflation but missed a separate, more serious problem: crediting whoever wrote the AVE record instead of whoever did the actual vulnerability research. Caught via an external maintainer's correction (alexgreensh/repo-forensics#39). Fixed the rule in both docs/specs/researcher-process.md and the live add-ave-record skill (.claude/skills/add-ave-record/SKILL.md), which didn't mention the researcher field at all before this. Fixed the worked example in researcher-process.md, which carried the identical error, and left a visible note about the correction rather than a silent edit. Swept the corpus for the same pattern and fixed ten records, not just the two directly named in the correction: - AVE-2026-00074, AVE-2026-00075: the two repo-forensics-sourced records alexgreensh actually flagged, now AIR Security and CSA / Trail of Bits respectively. - AVE-2026-00055, AVE-2026-00060: same shape, independently found during the sweep, both citing OX Security's own disclosure while crediting the AVE cataloguer. - AVE-2026-00071, AVE-2026-00072, AVE-2026-00073, AVE-2026-00076: each credits predictor2718 by name in its own references field for real analytical work (a detailed mechanism breakdown, or the PR that surfaced the candidate), not reflected in researcher. - AVE-2026-00063, AVE-2026-00064: narrower fix, team name to individual name only, no re-attribution, their references describe a gap found during AVE's own crosswalk comparison, not a named external party's original analysis. Every other record matching the old team-name pattern was checked against its own references and left as-is where no single named external source exists to credit instead.
Matches how this project already credits him elsewhere (issue #68, AVE-2026-00073's own references field: "predictor2718 (cfgaudit maintainer)"). No GitHub profile surname is available, so this uses the real first name he has public with the handle for disambiguation.
This was referenced Aug 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This whole correction exists because of an external maintainer's honesty, not routine cleanup. alexgreensh's correction on repo-forensics#39 pointed out that AVE-2026-00074 and AVE-2026-00075 credited "Saray Chak" as researcher when neither vulnerability class originated with AVE -- AIR Security disclosed SkillJacking, CSA/Trail of Bits demonstrated the bytecode-poisoning technique, repo-forensics built the detectors.
Summary
docs/specs/researcher-process.md(Accountability and sourcing section) and added directly to.claude/skills/add-ave-record/SKILL.md, which didn't mention theresearcherfield at all before this -- the live skill a drafting session actually reads needed it stated, not just reachable through a cross-reference. Both now also coverresearcher_url: crediting the right name while still linking to AVE's own site is the same mistake relocated, not fixed.researcher-process.md's own STDIO-shell-injection worked example had the identical error (credited "Saray Chak" while its own references correctly cited OX Security). Fixed, with a visible note left in place rather than a silent edit.AVE-2026-00074,AVE-2026-00075-- the two repo-forensics-sourced records, now AIR Security and CSA/Trail of Bits.AVE-2026-00055,AVE-2026-00060-- same shape, both independently citing OX Security's own disclosure while crediting the cataloguer.AVE-2026-00071,AVE-2026-00072,AVE-2026-00073,AVE-2026-00076-- each credits predictor2718 by name in its own references for real analytical work (a detailed mechanism breakdown on issue Taxonomy gaps identified by cfgaudit crosswalk (credit: predictor2718) #68, or the PR that surfaced the AVE-2026-00076 candidate), not reflected inresearcher.AVE-2026-00063,AVE-2026-00064-- narrower fix, team name to individual name only. Their references describe a gap found during AVE's own crosswalk comparison, not a named external party's analytical work, so no re-attribution, just the pre-existing team-to-individual convention applied.Test plan
python3 scripts/validate_records.py-- 76/76 records validpytest tests/ -x -q-- 305 passedSKILL.md's 5 pre-existing occurrences are untouched by this diff)