Skip to content

docs: owasp_asi tagging rule, from the #196 audit - #197

Merged
chaksaray merged 1 commit into
developfrom
docs/owasp-asi-tagging-rule
Aug 23, 2026
Merged

chaksaray merged 1 commit into
developfrom
docs/owasp-asi-tagging-rule

Conversation

@chaksaray

Copy link
Copy Markdown
Contributor

Writes the two systemic mistagging patterns found in #196 into researcher-process.md and add-ave-record/SKILL.md, so the next record drafted doesn't reproduce the same mistake at the individual-record level. Same treatment already applied to the researcher-field attribution rule.

Also corrects a wrong claim already sitting in both docs (from issue #179, discovered while writing this up — genuinely unrelated to #196 otherwise): both docs previously stated OWASP's Agentic Security Initiative 'really' uses T1-T17 and that the corpus's ASI01-ASI10 numbering (used by ~65+ records and the schema's own regex) was fabricated. It isn't. Issue #179 fetched OWASP's 'Agentic AI – Threats and Mitigations' PDF (T1-T17) and found zero ASI0 matches, but never found the separate, also-current 'OWASP Top 10 for Agentic Applications 2026' document, which uses ASI01-ASI10 as its own category IDs and whose own Appendix A formally cross-maps T1-T17 as the more granular, subordinate taxonomy the ASI framework references — not a competing scheme. Full correction posted on issue #179 directly. PR #196's corrections stand on the correct scheme; no schema or corpus rework needed as a result of this.

Schema's own owasp_asi field description (schema/ave-record-1.1.0.schema.json) deliberately left untouched — it's a frozen, versioned file per CLAUDE.md's hard rule, and any pointer addition belongs in the next version bump (already tracked in #178), not retrofitted here.

Found via the corpus audit in #196 (48 of 70 tagged records
corrected). Same treatment as the researcher-attribution rule: written
into both researcher-process.md (full explanation) and
add-ave-record/SKILL.md (the version a live drafting session actually
has in front of it), not left discoverable only in commit history.

Also corrects a wrong claim already sitting in both docs (from issue
#179): that OWASP's Agentic Security Initiative 'really' uses
T1-T17 and the corpus's ASI01-ASI10 numbering is fabricated. It isn't
— issue #179 fetched OWASP's 'Agentic AI - Threats and Mitigations'
PDF (T1-T17) and found no ASI0 matches, but never found the separate,
also-current 'OWASP Top 10 for Agentic Applications 2026' document,
which uses ASI01-ASI10 as its own category IDs and whose own Appendix
A formally cross-maps T1-T17 as the more granular, subordinate
taxonomy the ASI framework references. Corrected on issue #179's own
thread; PR #196's corrections stand on the right scheme. Left the
wrong bullet's location as-is rather than deleting it, since the
corrected version is a better instance of the same underlying lesson:
a single fetched PDF isn't automatically the primary source when a
framework's publisher maintains more than one document.
@chaksaray
chaksaray merged commit 604498a into develop Aug 23, 2026
6 checks passed
@chaksaray
chaksaray deleted the docs/owasp-asi-tagging-rule branch August 23, 2026 08:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant