docs: owasp_asi tagging rule, from the #196 audit - #197
Merged
Merged
Conversation
Found via the corpus audit in #196 (48 of 70 tagged records corrected). Same treatment as the researcher-attribution rule: written into both researcher-process.md (full explanation) and add-ave-record/SKILL.md (the version a live drafting session actually has in front of it), not left discoverable only in commit history. Also corrects a wrong claim already sitting in both docs (from issue #179): that OWASP's Agentic Security Initiative 'really' uses T1-T17 and the corpus's ASI01-ASI10 numbering is fabricated. It isn't — issue #179 fetched OWASP's 'Agentic AI - Threats and Mitigations' PDF (T1-T17) and found no ASI0 matches, but never found the separate, also-current 'OWASP Top 10 for Agentic Applications 2026' document, which uses ASI01-ASI10 as its own category IDs and whose own Appendix A formally cross-maps T1-T17 as the more granular, subordinate taxonomy the ASI framework references. Corrected on issue #179's own thread; PR #196's corrections stand on the right scheme. Left the wrong bullet's location as-is rather than deleting it, since the corrected version is a better instance of the same underlying lesson: a single fetched PDF isn't automatically the primary source when a framework's publisher maintains more than one document.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Writes the two systemic mistagging patterns found in #196 into researcher-process.md and add-ave-record/SKILL.md, so the next record drafted doesn't reproduce the same mistake at the individual-record level. Same treatment already applied to the researcher-field attribution rule.
Also corrects a wrong claim already sitting in both docs (from issue #179, discovered while writing this up — genuinely unrelated to #196 otherwise): both docs previously stated OWASP's Agentic Security Initiative 'really' uses
T1-T17and that the corpus'sASI01-ASI10numbering (used by ~65+ records and the schema's own regex) was fabricated. It isn't. Issue #179 fetched OWASP's 'Agentic AI – Threats and Mitigations' PDF (T1-T17) and found zeroASI0matches, but never found the separate, also-current 'OWASP Top 10 for Agentic Applications 2026' document, which usesASI01-ASI10as its own category IDs and whose own Appendix A formally cross-mapsT1-T17as the more granular, subordinate taxonomy the ASI framework references — not a competing scheme. Full correction posted on issue #179 directly. PR #196's corrections stand on the correct scheme; no schema or corpus rework needed as a result of this.Schema's own
owasp_asifield description (schema/ave-record-1.1.0.schema.json) deliberately left untouched — it's a frozen, versioned file per CLAUDE.md's hard rule, and any pointer addition belongs in the next version bump (already tracked in #178), not retrofitted here.