Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
68 commits
Select commit Hold shift + click to select a range
334bb96
Add cfgaudit → AVE crosswalk (static config-auditor) (#67)
predictor2718 Jul 23, 2026
f4d9b4e
docs: scaling and governance policy (#80)
chaksaray Jul 27, 2026
0ce799e
docs: cross-reference scaling-and-governance.md in README (#83)
chaksaray Jul 28, 2026
a367da6
docs: cross-reference scaling-and-governance.md in CLAUDE.md (#82)
chaksaray Jul 28, 2026
79406d0
docs: cross-reference scaling-and-governance.md in CONTEXT.md (#84)
chaksaray Jul 28, 2026
798a9c6
docs: cross-reference scaling-and-governance.md in CONTRIBUTING.md (#85)
chaksaray Jul 28, 2026
43928ee
docs: cross-reference scaling-and-governance.md in GOVERNANCE.md (#86)
chaksaray Jul 28, 2026
ad2ecf2
docs: add status glossary entry, cross-referencing scaling-and-govern…
chaksaray Jul 28, 2026
e94a8de
docs: CHANGELOG entry for scaling-and-governance.md (#88)
chaksaray Jul 28, 2026
8fcc70b
docs: cross-reference scaling-and-governance.md in ARCHITECTURE.md (#89)
chaksaray Jul 28, 2026
86a2a71
feat: validate records and update skills (#91)
chaksaray Jul 28, 2026
a699f5e
fix add ave record skill
chaksaray Jul 28, 2026
5b2b340
feat: AVE-2026-00060 through 00064 -- five new records from policy/co…
chaksaray Jul 28, 2026
fbbb422
Merge remote-tracking branch 'origin/main' into develop
chaksaray Jul 28, 2026
0cedb18
chore: regenerate consolidated records JSON
chaksaray Jul 28, 2026
f4cc426
feat: AVE-2026-00065 -- A2A agent card poisoning via embedded adversa…
chaksaray Jul 29, 2026
c9dce1e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Jul 29, 2026
445a178
fix: stale piranha.bawbel.io reference in README (#99)
chaksaray Jul 31, 2026
a08240e
docs: add researcher-process.md (#101)
chaksaray Jul 31, 2026
8955456
chore: add ave gap diagram (#107)
chaksaray Jul 31, 2026
e1fe630
fix: GOVERNANCE.md deprecation_reason field claim (#106)
chaksaray Jul 31, 2026
2789ac1
docs: add API link and gap diagram to README (#108)
chaksaray Jul 31, 2026
e5953c6
Change image width to 100% in README
chaksaray Jul 31, 2026
b464ed9
docs: link AVE-2026-00046 writeup from its own record (#111)
chaksaray Aug 2, 2026
d8861a5
feat: AVE-2026-00066 -- hallucinated skill-name squatting (HalluSquat…
chaksaray Aug 3, 2026
46fc1ce
feat: AVE-2026-00067 -- skill composition trust transfer (SCR-TrustLi…
chaksaray Aug 3, 2026
c302152
feat: AVE-2026-00068 -- CLI command composition risk (MOSAIC) (#115)
chaksaray Aug 3, 2026
270a263
feat: AVE-2026-00069 -- multimodal image-hidden instructions (SkillCa…
chaksaray Aug 3, 2026
34a692f
feat: AVE-2026-00070 -- distributed cross-agent backdoor fragments (C…
chaksaray Aug 3, 2026
211f71c
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 3, 2026
8e7b0e4
docs: collapsible record index (#119)
chaksaray Aug 3, 2026
375e853
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 3, 2026
d2e597a
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 6, 2026
0f79df3
feat: AVE-2026-00071 -- MCP daemon redirect (container posture) (#128)
chaksaray Aug 6, 2026
ccb716a
feat: AVE-2026-00072 -- MCP server bound to all interfaces (NeighborJ…
chaksaray Aug 6, 2026
66f821e
feat: AVE-2026-00073 -- telemetry/endpoint redirect via static config…
chaksaray Aug 6, 2026
16b459e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 6, 2026
9fa75bb
fix: pytest tests/ (CI's actual invocation) fails to collect tests/te…
chaksaray Aug 6, 2026
dfc9846
Remove 'Bawbel' reference from README (#134)
chaksaray Aug 6, 2026
3032813
feat: AVE-2026-00074 -- reclaimable dead external anchor (SkillJackin…
chaksaray Aug 6, 2026
c6761de
fix: use scoped PAT for dist/ regenerate auto-PR, not default GITHUB_…
chaksaray Aug 7, 2026
ca05ec6
feat: AVE-2026-00075 -- bytecode poisoning (compiled cache/source div…
chaksaray Aug 7, 2026
c22e000
chore: regenerate consolidated records JSON (#139)
chaksaray Aug 7, 2026
ca358df
Merge branch 'main' into develop
chaksaray Aug 7, 2026
79cad0d
feat: AVE-2026-00076 -- natural-language steering of an approval clas…
chaksaray Aug 7, 2026
4785a17
docs: clarify AVE-2026-00073 scope (MCP server URL, agent_card_url) (…
chaksaray Aug 7, 2026
772f768
chore: regenerate consolidated records JSON (#143)
chaksaray Aug 7, 2026
5f889ed
Merge branch 'main' into develop
chaksaray Aug 7, 2026
2fe60c5
fix: escape commit message in notify-ave-site client-payload (#145)
chaksaray Aug 8, 2026
3375ec3
feat: ramparts-to-ave crosswalk + numbering-mismatch caution (#147)
chaksaray Aug 8, 2026
2bd9a36
feat: nova-proximity-to-ave crosswalk (#152)
chaksaray Aug 8, 2026
fefcc62
fix: researcher field attribution rule and worked example (#154)
chaksaray Aug 9, 2026
33ade7a
feat: soft researcher/disclosure misattribution check (#157)
chaksaray Aug 9, 2026
d233d83
chore: regenerate consolidated records JSON (#156)
chaksaray Aug 9, 2026
d1efc63
fix: resolve the 10 records flagged by the researcher/disclosure chec…
chaksaray Aug 9, 2026
1caa0b0
chore: regenerate consolidated records JSON (#159)
chaksaray Aug 9, 2026
5e1e23e
Merge branch 'main' into develop
chaksaray Aug 9, 2026
243b19d
fix: mitre_atlas citation corrections per issue #127's audit (#162)
chaksaray Aug 9, 2026
416882c
chore: regenerate consolidated records JSON (#163)
chaksaray Aug 9, 2026
bb98dd9
Merge branch 'main' into develop
chaksaray Aug 9, 2026
47d628f
fix: ave-record-1.0.0.schema.json's $id still pointed at ave.bawbel.i…
chaksaray Aug 9, 2026
4f9e454
feat: AVE-2026-00077 -- cross-origin tool/resource declaration in a s…
chaksaray Aug 9, 2026
c16a4b9
Merge branch 'main' into develop
chaksaray Aug 9, 2026
ad5267f
chore: regenerate consolidated records JSON (#169)
chaksaray Aug 11, 2026
869b401
docs: add CONTRIBUTORS.md (#172)
chaksaray Aug 12, 2026
6dafbb2
Merge branch 'main' into develop
chaksaray Aug 13, 2026
d9409df
Add AVE-2026-00078/79/80: multi-agent pipeline boundary records (arXi…
chaksaray Aug 14, 2026
bdf12f3
Merge branch 'main' into develop
chaksaray Aug 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .claude/skills/add-ave-record/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,46 @@ published records before being caught by an external maintainer being
credited incorrectly himself. See docs/specs/researcher-process.md's
Accountability and sourcing section for the full rule.

**The four governance/framework fields — `owasp_mcp`, `owasp_asi`,
`mitre_atlas`, `nist_ai_rmf` — always include the key, never let one go
missing.** These are the fields a CISO reads first; a security team
maps an AVE record onto their own reporting frameworks through these.
An absent key silently reads as "nobody checked this framework." An
empty array reads as "checked, no real fit was found." Only the second
one is an honest, defensible state.

- `owasp_mcp`: **required** once `status` is `active`/`deprecated`
(schema-enforced, `minItems: 1`) — needs at least one real mapping,
verified against the OWASP MCP Top 10's own primary-source category
text, not inferred from how a similar-sounding record in the corpus
happened to tag itself.
- `owasp_asi`, `mitre_atlas`, `nist_ai_rmf`: not yet schema-required
(that's a tracked v1.2.0 change, see the roadmap issue), but always
write the key. Verify each against its own primary source (live
`ATLAS.yaml` for MITRE ATLAS, the actual NIST AI 100-1 text for NIST
AI RMF, the framework's own published category list for OWASP ASI)
before adding a value. Genuinely checked and found nothing that
fits? Set it to `[]` and say so in `aivss.notes` — don't just leave
the key out because the array would otherwise be empty. This exact
mistake (a silently-missing `owasp_asi` key, not an empty one)
shipped on AVE-2026-00078/00079/00080 and was caught reviewing that
same PR — see docs/specs/researcher-process.md's Common Mistakes
section.

**"Its own primary source" means fetch and read the actual document
— a repo's raw files, the framework's own published PDF — never a
search result, a summarized page, or a third-party blog's retelling
of it, and never corpus precedent no matter how many existing
records agree with each other.** Roughly 65 records in this corpus
and the schema's own `owasp_asi` regex all consistently use an
`ASI01`-`ASI10` numbering for OWASP's Agentic Security Initiative —
discovered, on fetching the real primary-source PDF directly and
grepping its full text, to not exist anywhere in that document at
all. The real taxonomy uses `T1`-`T17`. Sixty-five records agreeing
with each other was never evidence; it was sixty-five copies of the
same unverified pattern. See issue #179 for the full writeup before
citing `owasp_asi` on any new record.

### 4. Write conformance fixtures (TDD — fixtures first)
tests/fixtures/AVE-YYYY-NNNNN_positive.md — a conforming implementation MUST flag this
tests/fixtures/AVE-YYYY-NNNNN_negative.md — a conforming implementation MUST NOT flag this
Expand Down
37 changes: 37 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,43 @@ Format: [Semantic Versioning](https://semver.org). Schema versions and record se
new record.

### Added
- AVE-2026-00078, 00079, 00080: three genuinely distinct multi-agent
pipeline mechanisms extracted from Bappy et al., "Adversarial Attacks
in Multi-Agent LLM Pipelines: Unveiling Structural Vulnerabilities in
Agentic AI Architectures" (arXiv:2608.00718, accepted IEEE GLOBECOM
2026), empirically derived from 147 annotated TRAIL-benchmark
production traces (GAIA + SWE-Bench Lite) plus a controlled
cross-model evaluation (GPT-5-mini, Claude Sonnet 4.5, Kimi K2.5).
The paper's own fourth mechanism (prompt injection via retrieved
content, its A1/content-boundary class) was confirmed already covered
by AVE-2026-00016 and related records — not drafted as new. All three
scored MEDIUM: AARF rewards amplification breadth, not raw impact,
and each of these is architectural rather than broad-vector.
- AVE-2026-00078: consensus poisoning — an orchestrator accepts a
single sub-agent's result as authoritative with no quorum or
cross-verification across redundant sources, so one compromised
sub-agent unilaterally determines the pipeline's output (delegation
boundary). Distinct from AVE-2026-00020 (injection direction is
orchestrator→sub-agent, not this record's sub-agent→orchestrator
aggregation-layer flaw) and AVE-2026-00018 (fabricating one result,
not failing to cross-check redundant ones). Id confirmed via issue
#174 (MEDIUM, AIVSS 6.4)
- AVE-2026-00079: plan hijacking via false completion signal — a
self-reported "task already completed" claim causes forced early
termination of a declared multi-step plan with no plan-to-execution
binding check (delegation boundary). Distinct from AVE-2026-00021
(bypasses human confirmation; this bypasses no human, it bypasses
the agent's own remaining planned steps) and AVE-2026-00063 (static
config flag, not a runtime natural-language claim). Id confirmed via
issue #175 (MEDIUM, AIVSS 6.2)
- AVE-2026-00080: silent agent substitution (Sybil) — during a
tool-call retry, an unverified process responding at an agent's
routing position is accepted as that agent with no credential or
attestation check (identity boundary). Distinct from AVE-2026-00017
(a registry/manifest identity claim at initial connection, not a
mid-session retry-window substitution asserting no claim at all)
and AVE-2026-00030 (requires an explicit role claim; this requires
none). Id confirmed via issue #176 (MEDIUM, AIVSS 6.8)
- AVE-2026-00077: cross-origin tool and resource declaration within a
single MCP server manifest — a server's own manifest declares tools
and/or resources spanning multiple unrelated root domains (or mixed
Expand Down
9 changes: 6 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ Stable IDs, AIVSS scores, and behavioral fingerprints for every way a skill file
MCP server, system prompt, or agent plugin can be weaponized — scored consistently,
mapped to the frameworks security teams already report against.

[![Records](https://img.shields.io/badge/records-77-0f6e56?style=flat-square)](records/)
[![Records](https://img.shields.io/badge/records-80-0f6e56?style=flat-square)](records/)
[![Schema](https://img.shields.io/badge/schema-v1.1.0-0a3024?style=flat-square)](schema/ave-record-1.1.0.schema.json)
[![AIVSS](https://img.shields.io/badge/AIVSS-v0.8-d4a017?style=flat-square)](https://aivss.owasp.org)
[![OWASP MCP](https://img.shields.io/badge/OWASP-MCP%20Top%2010-0a3024?style=flat-square)](https://owasp.org)
Expand Down Expand Up @@ -99,7 +99,7 @@ skill file -> in CI / pre-commit -> before deploy

| | |
|---|---|
| Total records | 77 |
| Total records | 80 |
| Schema version | 1.1.0 |
| AIVSS spec | v0.8 |
| CRITICAL (>= 9.0) | 1 |
Expand Down Expand Up @@ -167,7 +167,7 @@ AIVSS = ((8.5 + 7.5) / 2) x 1.0 x 1 = 8.0 -> HIGH
## Record index

<details>
<summary><strong>77 records, click to expand</strong></summary>
<summary><strong>80 records, click to expand</strong></summary>

| AVE ID | Title | AIVSS | Severity |
|---|---|---|---|
Expand Down Expand Up @@ -248,6 +248,9 @@ AIVSS = ((8.5 + 7.5) / 2) x 1.0 x 1 = 8.0 -> HIGH
| [AVE-2026-00075](records/AVE-2026-00075.json) | Bytecode Poisoning (Compiled Cache/Source Divergence) | 4.4 | MEDIUM |
| [AVE-2026-00076](records/AVE-2026-00076.json) | Natural-Language Steering of an Approval Classifier Subagent | 4.5 | MEDIUM |
| [AVE-2026-00077](records/AVE-2026-00077.json) | Cross-Origin Tool and Resource Declaration in a Single MCP Server Manifest | 4.8 | MEDIUM |
| [AVE-2026-00078](records/AVE-2026-00078.json) | Consensus Poisoning: Unverified Multi-Agent Result Acceptance | 6.4 | MEDIUM |
| [AVE-2026-00079](records/AVE-2026-00079.json) | Plan Hijacking via False Completion Signal | 6.2 | MEDIUM |
| [AVE-2026-00080](records/AVE-2026-00080.json) | Silent Agent Substitution (Sybil) via Unverified Retry | 6.8 | MEDIUM |

</details>

Expand Down
Loading
Loading