Skip to content

fix: researcher field attribution rule and worked example - #154

Merged
chaksaray merged 2 commits into
developfrom
fix/researcher-field-attribution-rule
Aug 9, 2026
Merged

chaksaray merged 2 commits into
developfrom
fix/researcher-field-attribution-rule

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

This whole correction exists because of an external maintainer's honesty, not routine cleanup. alexgreensh's correction on repo-forensics#39 pointed out that AVE-2026-00074 and AVE-2026-00075 credited "Saray Chak" as researcher when neither vulnerability class originated with AVE -- AIR Security disclosed SkillJacking, CSA/Trail of Bits demonstrated the bytecode-poisoning technique, repo-forensics built the detectors.

Summary

  • The rule itself: fixed in docs/specs/researcher-process.md (Accountability and sourcing section) and added directly to .claude/skills/add-ave-record/SKILL.md, which didn't mention the researcher field at all before this -- the live skill a drafting session actually reads needed it stated, not just reachable through a cross-reference. Both now also cover researcher_url: crediting the right name while still linking to AVE's own site is the same mistake relocated, not fixed.
  • The worked example: researcher-process.md's own STDIO-shell-injection worked example had the identical error (credited "Saray Chak" while its own references correctly cited OX Security). Fixed, with a visible note left in place rather than a silent edit.
  • The corpus sweep: checked every record still carrying "Saray Chak" or "Bawbel Security Research Team" against its own references, not assumed. Ten records needed fixing, not just the two named in the correction:
    • AVE-2026-00074, AVE-2026-00075 -- the two repo-forensics-sourced records, now AIR Security and CSA/Trail of Bits.
    • AVE-2026-00055, AVE-2026-00060 -- same shape, both independently citing OX Security's own disclosure while crediting the cataloguer.
    • AVE-2026-00071, AVE-2026-00072, AVE-2026-00073, AVE-2026-00076 -- each credits predictor2718 by name in its own references for real analytical work (a detailed mechanism breakdown on issue Taxonomy gaps identified by cfgaudit crosswalk (credit: predictor2718) #68, or the PR that surfaced the AVE-2026-00076 candidate), not reflected in researcher.
    • AVE-2026-00063, AVE-2026-00064 -- narrower fix, team name to individual name only. Their references describe a gap found during AVE's own crosswalk comparison, not a named external party's analytical work, so no re-attribution, just the pre-existing team-to-individual convention applied.
  • Every other record matching the old team-name pattern was checked against its own references and left as-is -- most cite general frameworks (CWE/OWASP/MITRE) or foundational academic literature as background context, not a specific named discloser of that exact mechanism.

Test plan

  • python3 scripts/validate_records.py -- 76/76 records valid
  • pytest tests/ -x -q -- 305 passed
  • No new em-dashes introduced in either doc (SKILL.md's 5 pre-existing occurrences are untouched by this diff)

…loguer

The go-forward convention (individual name, not a team name) fixed
inflation but missed a separate, more serious problem: crediting
whoever wrote the AVE record instead of whoever did the actual
vulnerability research. Caught via an external maintainer's correction
(alexgreensh/repo-forensics#39).

Fixed the rule in both docs/specs/researcher-process.md and the live
add-ave-record skill (.claude/skills/add-ave-record/SKILL.md), which
didn't mention the researcher field at all before this. Fixed the
worked example in researcher-process.md, which carried the identical
error, and left a visible note about the correction rather than a
silent edit.

Swept the corpus for the same pattern and fixed ten records, not just
the two directly named in the correction:
- AVE-2026-00074, AVE-2026-00075: the two repo-forensics-sourced
  records alexgreensh actually flagged, now AIR Security and
  CSA / Trail of Bits respectively.
- AVE-2026-00055, AVE-2026-00060: same shape, independently found
  during the sweep, both citing OX Security's own disclosure while
  crediting the AVE cataloguer.
- AVE-2026-00071, AVE-2026-00072, AVE-2026-00073, AVE-2026-00076: each
  credits predictor2718 by name in its own references field for real
  analytical work (a detailed mechanism breakdown, or the PR that
  surfaced the candidate), not reflected in researcher.
- AVE-2026-00063, AVE-2026-00064: narrower fix, team name to
  individual name only, no re-attribution, their references describe
  a gap found during AVE's own crosswalk comparison, not a named
  external party's original analysis.

Every other record matching the old team-name pattern was checked
against its own references and left as-is where no single named
external source exists to credit instead.
Matches how this project already credits him elsewhere (issue #68,
AVE-2026-00073's own references field: "predictor2718 (cfgaudit
maintainer)"). No GitHub profile surname is available, so this uses
the real first name he has public with the handle for disambiguation.
@chaksaray
chaksaray merged commit fefcc62 into develop Aug 9, 2026
6 checks passed
@chaksaray
chaksaray deleted the fix/researcher-field-attribution-rule branch August 9, 2026 00:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant