Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 14 additions & 12 deletions .github/ISSUE_TEMPLATE/01_ave_submission.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
---
name: "🛡️ AVE Record Submission"
name: "AVE Record Submission"
about: Submit a new agentic vulnerability for inclusion in the AVE database
title: "[AVE Submission] "
labels: ave-submission, needs-review
Expand All @@ -9,8 +9,8 @@ assignees: ''
## Summary

**Component type:** <!-- skill / mcp / prompt / plugin / a2a / rag / model -->
**Attack class:** <!-- see SPEC.md Section 5 for the full taxonomy -->
**Estimated CVSS-AI score:** <!-- 0.0–10.0 -->
**Attack class:** <!-- see SPEC.md Section 4 for the taxonomy -->
**Estimated AIVSS score:** <!-- 0.0 to 10.0 - use the calculator at bawbel.io/cvss-ai -->

---

Expand All @@ -22,7 +22,7 @@ assignees: ''

## Behavioral Fingerprint

<!-- Plain-language description of the behavioral pattern that identifies this vulnerability. -->
<!-- One sentence: what does the component instruct the agent to do? -->

---

Expand All @@ -42,27 +42,29 @@ assignees: ''

## Remediation

<!-- What should someone do when they find this? -->
<!-- Step by step: what should someone do when they find this? -->

---

## OWASP Agentic AI Mapping
## Framework Mapping

<!-- Which ASI items apply? (ASI01–ASI10) See SPEC.md Section 7 -->
**OWASP ASI:** <!-- which ASI codes apply? ASI01 to ASI10 -->
**OWASP MCP:** <!-- which MCP codes apply? MCP01 to MCP10 -->
**AIVSS AARF scores:** <!-- autonomy / tool_use / multi_agent / etc. See SPEC.md Section 7 -->

---

## Affected Platforms / Registries
## Affected Platforms and Registries

<!-- Where have you observed this? Sanitise sensitive details if needed. -->

---

## Disclosure Status

- [ ] I have contacted the publisher / maintainer
- [ ] Publisher acknowledged — date: <!-- YYYY-MM-DD -->
- [ ] 90-day window passed, OR component is clearly malicious with no legitimate use
- [ ] I have contacted the publisher or maintainer
- [ ] Publisher acknowledged - date: <!-- YYYY-MM-DD -->
- [ ] 90-day window has passed, OR component is clearly malicious with no legitimate use

---

Expand All @@ -76,4 +78,4 @@ assignees: ''

## References

<!-- Links to related research, advisories, or publications -->
<!-- Links to real-world occurrences, advisories, or related research -->
29 changes: 19 additions & 10 deletions .github/ISSUE_TEMPLATE/02_false_positive.md
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
---
name: "⚠️ False Positive Report"
about: Report an AVE record that you believe is incorrectly classified
name: "False Positive Report"
about: Report an AVE record or detection rule that fires incorrectly on legitimate content
title: "[False Positive] AVE-2026-"
labels: false-positive, needs-review
assignees: ''
---

## AVE Record

**AVE ID:** <!-- e.g. AVE-2026-00001 -->
**Record title:** <!-- copy from the record -->
**AVE ID:** <!-- e.g. AVE-2026-00002 -->
**Record title:** <!-- copy the title from the record -->

---

Expand All @@ -21,21 +21,30 @@ assignees: ''

## Technical Evidence

<!-- Provide specific technical evidence supporting your claim. -->
<!-- Provide specific technical evidence. Show the content that triggered the finding
and explain why it is not actually dangerous. -->

---

## Context

**Tool version:** <!-- bawbel-scanner version that produced the finding -->
**Detection engine:** <!-- pattern / yara / semgrep / llm / magika -->
**Component type:** <!-- skill / mcp / prompt / plugin / etc. -->

---

## Suggested Resolution

- [ ] Mark record as `false_positive`
- [ ] Narrow the behavioral fingerprint
- [ ] Update the detection methodology
- [ ] Split into a separate record
- [ ] Narrow the behavioral fingerprint in the AVE record
- [ ] Update the detection methodology to add an exclusion
- [ ] Update the detection rule in bawbel-scanner
- [ ] Mark this specific case as accepted risk (not a record change)
- [ ] Other: <!-- describe -->

---

## Your Details (optional)

**Name:**
**Organisation:**
**Organisation:**
26 changes: 18 additions & 8 deletions .github/ISSUE_TEMPLATE/03_schema_change.md
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
---
name: "📐 Schema Change Proposal"
about: Propose a change to the AVE record schema
name: "Schema Change Proposal"
about: Propose a change to the AVE record schema (v0.2.0)
title: "[Schema] "
labels: schema-change
assignees: ''
---

## Change Type

- [ ] **Breaking change** — removing or renaming a field (requires 30-day comment period)
- [ ] **Additive change** — new optional field (standard PR review)
- [ ] **Breaking change** - removing or renaming a field (requires 30-day comment period before merge)
- [ ] **Additive change** - new optional field (standard PR review, no waiting period)

---

Expand All @@ -18,21 +18,24 @@ assignees: ''
**Field name:**
**Current definition (if existing):**
**Proposed definition:**
**Type:** <!-- string / integer / float / boolean / enum / array -->
**Type:** <!-- string / integer / float / boolean / enum / array / object -->
**Required:** <!-- yes / no -->
**Allowed values (if enum):**

---

## Rationale

<!-- Why is this change needed? What vulnerability class does it enable better coverage of? -->
<!-- Why is this change needed?
What attack class or detection capability does it enable that the current schema cannot express?
Why can the same goal not be achieved with existing fields? -->

---

## Impact on Existing Records

<!-- How many existing records are affected? Would they need updating? -->
<!-- How many of the 45 published records would be affected?
Would they need updating? Are you willing to update them in the same PR? -->

---

Expand All @@ -41,6 +44,13 @@ assignees: ''
```json
{
"ave_id": "AVE-2026-00001",
"new_field_name": "example value"
"new_field_name": "example value showing the field in use"
}
```

---

## Backwards Compatibility

<!-- If this is an additive change: can parsers that do not know this field
safely ignore it without breaking? -->
41 changes: 32 additions & 9 deletions .github/ISSUE_TEMPLATE/04_bug_report.md
Original file line number Diff line number Diff line change
@@ -1,24 +1,47 @@
---
name: "🐛 Bug Report"
about: Report an error in the AVE schema, a record, or documentation
name: "Bug Report"
about: Report an error in a record, the schema, or documentation
title: "[Bug] "
labels: bug
assignees: ''
---

## What is wrong?

<!-- Describe the error clearly. -->
<!-- Describe the error clearly and specifically. -->

## Where is it?
---

## Location

**File:** <!-- e.g. records/AVE-2026-00004.json or SPEC.md -->
**Field or section:** <!-- e.g. aivss.aars or Section 7 -->
**Line number (if known):**

---

## Current value

```
paste the incorrect content here
```

**File:**
**Line / Section:**
---

## What it should say

## What should it say?
```
paste the correct content here
```

---

<!-- Paste the corrected version. -->
## Why it is wrong

<!-- Explain why the current value is incorrect. Link to the spec or a reference if relevant. -->

---

## Additional context

<!-- Any other relevant information. -->
<!-- Anything else that would help us fix this quickly. -->
68 changes: 42 additions & 26 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,48 +1,64 @@
## Type of Change

- [ ] 🛡️ New AVE record submission
- [ ] 🔧 Update to existing AVE record
- [ ] 📐 Schema change
- [ ] 🔍 New detection rule (YARA / Semgrep)
- [ ] 📝 Documentation improvement
- [ ] 🐛 Bug fix
## Type of change

- [ ] New AVE record submission
- [ ] Update to existing AVE record
- [ ] Schema change (v0.2.0)
- [ ] New detection rule (YARA / Semgrep)
- [ ] Documentation improvement
- [ ] Other:

---

## Description

<!-- What does this PR do? For AVE submissions, summarise the vulnerability in 2–3 sentences. -->
<!-- What does this PR do?
For AVE submissions: summarise the vulnerability in 2-3 sentences. -->

---

## AVE Record(s)

<!-- List AVE IDs. Use AVE-PENDING for new submissions — we assign the ID on merge. -->
<!-- List AVE IDs. Use AVE-PENDING for new submissions not yet assigned a number. -->

---

## Checklist

### For AVE record submissions
- [ ] Record file is in `records/AVE-PENDING.json`
- [ ] All required fields are present (see SPEC.md Section 5)
- [ ] `behavioral_fingerprint` is clear and actionable
- [ ] `detection_methodology` is specific and reproducible
### For new AVE record submissions

- [ ] Record follows schema v0.2.0 (see SPEC.md Section 6)
- [ ] All required fields are present and non-empty
- [ ] `attack_class` uses "Category - Subcategory" format with no em dashes
- [ ] `behavioral_fingerprint` is one clear sentence
- [ ] `detection_methodology` is step-by-step and reproducible
- [ ] `indicators_of_compromise` has at least 2 entries
- [ ] `owasp_mapping` references valid ASI identifiers (ASI01–ASI10)
- [ ] `cvss_ai_score` is justified in the PR description
- [ ] `owasp_mapping` (ASI codes) is correct
- [ ] `owasp_mcp` (MCP codes) is correct
- [ ] `aivss` block is complete with all 10 AARF scores and written rationale in `notes`
- [ ] `aivss_score` at top level matches `aivss.aivss_score`
- [ ] `cvss_base_vector` is a valid CVSSv4.0 vector string
- [ ] `mutation_count` is an integer >= 0
- [ ] Responsible disclosure process followed (see CONTRIBUTING.md)
- [ ] `researcher` field contains my correct name and attribution
- [ ] Researcher name is accurate and has been verified with them

### For updates to existing records

- [ ] `last_updated` is set to today in ISO 8601 format
- [ ] Change is explained in PR description
- [ ] If AIVSS score changes: new AARF rationale is in `aivss.notes`

### For schema changes
- [ ] Issue opened with `schema-change` label
- [ ] 30-day comment period completed (breaking changes only)
- [ ] `SPEC.md` updated
- [ ] `records/TEMPLATE.json` updated
- [ ] Existing records updated where required

- [ ] Issue opened first with 30-day comment period completed (breaking changes only)
- [ ] SPEC.md updated to reflect the change
- [ ] `records/template.json` updated
- [ ] Existing records updated if required (or PR description explains why not)
- [ ] Schema version bumped if breaking

### For all PRs
- [ ] I have read [CONTRIBUTING.md](CONTRIBUTING.md)
- [ ] My changes follow the existing style and format
- [ ] I agree to license my contribution under Apache 2.0

- [ ] I have read CONTRIBUTING.md
- [ ] No em dashes in any field values (use hyphens instead)
- [ ] No CVSS-AI references (use AIVSS)
- [ ] No bawbel/bawbel-ave URLs (use bawbel/ave)
- [ ] I agree my contribution is licensed under Apache 2.0
Loading