Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
97 commits
Select commit Hold shift + click to select a range
334bb96
Add cfgaudit → AVE crosswalk (static config-auditor) (#67)
predictor2718 Jul 23, 2026
f4d9b4e
docs: scaling and governance policy (#80)
chaksaray Jul 27, 2026
0ce799e
docs: cross-reference scaling-and-governance.md in README (#83)
chaksaray Jul 28, 2026
a367da6
docs: cross-reference scaling-and-governance.md in CLAUDE.md (#82)
chaksaray Jul 28, 2026
79406d0
docs: cross-reference scaling-and-governance.md in CONTEXT.md (#84)
chaksaray Jul 28, 2026
798a9c6
docs: cross-reference scaling-and-governance.md in CONTRIBUTING.md (#85)
chaksaray Jul 28, 2026
43928ee
docs: cross-reference scaling-and-governance.md in GOVERNANCE.md (#86)
chaksaray Jul 28, 2026
ad2ecf2
docs: add status glossary entry, cross-referencing scaling-and-govern…
chaksaray Jul 28, 2026
e94a8de
docs: CHANGELOG entry for scaling-and-governance.md (#88)
chaksaray Jul 28, 2026
8fcc70b
docs: cross-reference scaling-and-governance.md in ARCHITECTURE.md (#89)
chaksaray Jul 28, 2026
86a2a71
feat: validate records and update skills (#91)
chaksaray Jul 28, 2026
a699f5e
fix add ave record skill
chaksaray Jul 28, 2026
5b2b340
feat: AVE-2026-00060 through 00064 -- five new records from policy/co…
chaksaray Jul 28, 2026
fbbb422
Merge remote-tracking branch 'origin/main' into develop
chaksaray Jul 28, 2026
0cedb18
chore: regenerate consolidated records JSON
chaksaray Jul 28, 2026
f4cc426
feat: AVE-2026-00065 -- A2A agent card poisoning via embedded adversa…
chaksaray Jul 29, 2026
c9dce1e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Jul 29, 2026
445a178
fix: stale piranha.bawbel.io reference in README (#99)
chaksaray Jul 31, 2026
a08240e
docs: add researcher-process.md (#101)
chaksaray Jul 31, 2026
8955456
chore: add ave gap diagram (#107)
chaksaray Jul 31, 2026
e1fe630
fix: GOVERNANCE.md deprecation_reason field claim (#106)
chaksaray Jul 31, 2026
2789ac1
docs: add API link and gap diagram to README (#108)
chaksaray Jul 31, 2026
e5953c6
Change image width to 100% in README
chaksaray Jul 31, 2026
b464ed9
docs: link AVE-2026-00046 writeup from its own record (#111)
chaksaray Aug 2, 2026
d8861a5
feat: AVE-2026-00066 -- hallucinated skill-name squatting (HalluSquat…
chaksaray Aug 3, 2026
46fc1ce
feat: AVE-2026-00067 -- skill composition trust transfer (SCR-TrustLi…
chaksaray Aug 3, 2026
c302152
feat: AVE-2026-00068 -- CLI command composition risk (MOSAIC) (#115)
chaksaray Aug 3, 2026
270a263
feat: AVE-2026-00069 -- multimodal image-hidden instructions (SkillCa…
chaksaray Aug 3, 2026
34a692f
feat: AVE-2026-00070 -- distributed cross-agent backdoor fragments (C…
chaksaray Aug 3, 2026
211f71c
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 3, 2026
8e7b0e4
docs: collapsible record index (#119)
chaksaray Aug 3, 2026
375e853
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 3, 2026
d2e597a
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 6, 2026
0f79df3
feat: AVE-2026-00071 -- MCP daemon redirect (container posture) (#128)
chaksaray Aug 6, 2026
ccb716a
feat: AVE-2026-00072 -- MCP server bound to all interfaces (NeighborJ…
chaksaray Aug 6, 2026
66f821e
feat: AVE-2026-00073 -- telemetry/endpoint redirect via static config…
chaksaray Aug 6, 2026
16b459e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 6, 2026
9fa75bb
fix: pytest tests/ (CI's actual invocation) fails to collect tests/te…
chaksaray Aug 6, 2026
dfc9846
Remove 'Bawbel' reference from README (#134)
chaksaray Aug 6, 2026
3032813
feat: AVE-2026-00074 -- reclaimable dead external anchor (SkillJackin…
chaksaray Aug 6, 2026
c6761de
fix: use scoped PAT for dist/ regenerate auto-PR, not default GITHUB_…
chaksaray Aug 7, 2026
ca05ec6
feat: AVE-2026-00075 -- bytecode poisoning (compiled cache/source div…
chaksaray Aug 7, 2026
c22e000
chore: regenerate consolidated records JSON (#139)
chaksaray Aug 7, 2026
ca358df
Merge branch 'main' into develop
chaksaray Aug 7, 2026
79cad0d
feat: AVE-2026-00076 -- natural-language steering of an approval clas…
chaksaray Aug 7, 2026
4785a17
docs: clarify AVE-2026-00073 scope (MCP server URL, agent_card_url) (…
chaksaray Aug 7, 2026
772f768
chore: regenerate consolidated records JSON (#143)
chaksaray Aug 7, 2026
5f889ed
Merge branch 'main' into develop
chaksaray Aug 7, 2026
2fe60c5
fix: escape commit message in notify-ave-site client-payload (#145)
chaksaray Aug 8, 2026
3375ec3
feat: ramparts-to-ave crosswalk + numbering-mismatch caution (#147)
chaksaray Aug 8, 2026
2bd9a36
feat: nova-proximity-to-ave crosswalk (#152)
chaksaray Aug 8, 2026
fefcc62
fix: researcher field attribution rule and worked example (#154)
chaksaray Aug 9, 2026
33ade7a
feat: soft researcher/disclosure misattribution check (#157)
chaksaray Aug 9, 2026
d233d83
chore: regenerate consolidated records JSON (#156)
chaksaray Aug 9, 2026
d1efc63
fix: resolve the 10 records flagged by the researcher/disclosure chec…
chaksaray Aug 9, 2026
1caa0b0
chore: regenerate consolidated records JSON (#159)
chaksaray Aug 9, 2026
5e1e23e
Merge branch 'main' into develop
chaksaray Aug 9, 2026
243b19d
fix: mitre_atlas citation corrections per issue #127's audit (#162)
chaksaray Aug 9, 2026
416882c
chore: regenerate consolidated records JSON (#163)
chaksaray Aug 9, 2026
bb98dd9
Merge branch 'main' into develop
chaksaray Aug 9, 2026
47d628f
fix: ave-record-1.0.0.schema.json's $id still pointed at ave.bawbel.i…
chaksaray Aug 9, 2026
4f9e454
feat: AVE-2026-00077 -- cross-origin tool/resource declaration in a s…
chaksaray Aug 9, 2026
c16a4b9
Merge branch 'main' into develop
chaksaray Aug 9, 2026
ad5267f
chore: regenerate consolidated records JSON (#169)
chaksaray Aug 11, 2026
869b401
docs: add CONTRIBUTORS.md (#172)
chaksaray Aug 12, 2026
6dafbb2
Merge branch 'main' into develop
chaksaray Aug 13, 2026
d9409df
Add AVE-2026-00078/79/80: multi-agent pipeline boundary records (arXi…
chaksaray Aug 14, 2026
bdf12f3
Merge branch 'main' into develop
chaksaray Aug 14, 2026
d11da48
fix: correct AVE-2026-00070 researcher attribution (#182)
chaksaray Aug 14, 2026
dbc56d2
chore: regenerate consolidated records JSON (#180)
chaksaray Aug 14, 2026
ba0b0f1
research: AVE → OpenCRE pilot mapping (Batch 1 submitted, issue open)…
chaksaray Aug 15, 2026
e4db9d4
Merge branch 'main' into develop
chaksaray Aug 15, 2026
4b016ba
docs: independent validation section and technical write-ups (#184)
chaksaray Aug 15, 2026
37c91c7
docs: sync CONTRIBUTING.md with current process (#188)
chaksaray Aug 15, 2026
a6491b3
Sync main into develop, resolves PR #187's conflict (#189)
chaksaray Aug 15, 2026
dbb5b6d
feat: semia-to-ave crosswalk (#190)
chaksaray Aug 15, 2026
ff57a18
Merge branch 'main' into develop
chaksaray Aug 15, 2026
8ec7c2f
feat: skillsentry-to-ave and skill-security-scanner-to-ave crosswalks…
chaksaray Aug 15, 2026
604498a
docs: owasp_asi tagging rule, from the #196 audit (#197)
chaksaray Aug 23, 2026
b5e33bd
fix: owasp_asi mapping audit (48 corrected, 13 confirmed, 11 flagged …
chaksaray Aug 23, 2026
9365f00
chore: regenerate consolidated records JSON (#198)
chaksaray Aug 23, 2026
8602092
Merge branch 'main' into develop
chaksaray Aug 23, 2026
c494f8c
fix: AVE-2026-00048 attribution and remediation branding (#202)
chaksaray Aug 25, 2026
236360e
Merge remote-tracking branch 'origin/main' into develop
chaksaray Aug 25, 2026
8e910fc
Sync main into develop, resolves PR #204's conflict (#206)
chaksaray Aug 26, 2026
a1e50c1
chore: regenerate consolidated records JSON (#203)
chaksaray Aug 26, 2026
228d545
fix: researcher-attribution audit across the corpus (49 of 50) (#205)
chaksaray Aug 26, 2026
3048d1f
chore: regenerate consolidated records JSON (#207)
chaksaray Aug 26, 2026
00b69c5
Sync main into develop, resolves PR #204's conflict (#209)
chaksaray Aug 26, 2026
858d46d
Sync main into develop, resolves PR #204's conflict (again) (#210)
chaksaray Aug 26, 2026
759dddf
docs: fix stale independent-crosswalk count in README (3 -> 8) (#200)
chaksaray Aug 27, 2026
e843ea5
docs: three real improvements surfaced by external critique (#215)
chaksaray Aug 28, 2026
038dbf6
Sync main into develop, resolves PR #222's conflict (#226)
chaksaray Aug 29, 2026
8bdddfa
Sync main into develop, resolves PR #222's conflict (round 2) (#227)
chaksaray Aug 29, 2026
070b8ca
fix conflic test validate data
chaksaray Aug 29, 2026
4827171
fix generated at manifest
chaksaray Aug 29, 2026
824279a
docs: capability-behavior-vulnerability taxonomy audit (all 80 record…
chaksaray Aug 29, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 27 additions & 9 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,15 @@ AVE is a standard, not a product. The `bawbel-scanner` implements it as the
reference implementation. Any tool can map to it — see the
[implementer guide](docs/specs/ave-implementer-guide.md) for how.

### What AVE is not

AVE is a naming and classification standard. It assigns stable IDs to
behavioral vulnerability classes and describes how to detect them. It
is not a runtime enforcement mechanism, and an AVE ID on its own stops
nothing. Enforcement requires a separate policy or gating layer that
consumes AVE's records, the same relationship CWE has to an actual
static analyzer, or a CVE has to a patch management system.

```
Your CI pipeline scans dependencies for known package vulnerabilities.
It does not scan your SKILL.md for prompt injection.
Expand All @@ -73,12 +82,13 @@ AVE fixes that.
AVE's ID scheme has been tested by people who didn't build it, not
just used by people who did.

Three independent tools, cfgaudit, Ramparts, and nova-proximity, none
of them sharing code with AVE or with each other, built crosswalks
against AVE's records on their own initiative, unprompted. In each
case the comparison went beyond matching category labels: mechanism-
level correspondence was checked field by field, real trigger
conditions against real behavioral fingerprints, and dozens of
Eight independent tools, cfgaudit, ClawScan, nova-proximity, Ramparts,
Semia, SkillSpector (NVIDIA), skill-security-scanner, and skillsentry,
none of them sharing code with AVE or with each other, built
crosswalks against AVE's records on their own initiative, unprompted.
In each case the comparison went beyond matching category labels:
mechanism-level correspondence was checked field by field, real
trigger conditions against real behavioral fingerprints, and dozens of
findings converged on the identical AVE ID independently.

One of those crosswalks (Ramparts) also surfaced a real methodological
Expand All @@ -92,7 +102,7 @@ two published AVE records, corrected the underlying process
documentation, not just the two records, credited in
[CONTRIBUTORS.md](CONTRIBUTORS.md).

80 records. 3 independent crosswalks. See
80 records. 8 independent crosswalks. See
[crosswalks/](crosswalks/) for the full mappings, and
[docs/writeups/](docs/writeups/) for full technical write-ups on
individual records.
Expand Down Expand Up @@ -511,8 +521,14 @@ at [aveproject.org/crosswalks.html](https://aveproject.org/crosswalks.html).

| This scanner | Maps to AVE via |
|---|---|
| SkillSpector (NVIDIA) | [`crosswalks/skillspector-to-ave.json`](crosswalks/skillspector-to-ave.json) |
| cfgaudit | [`crosswalks/cfgaudit-to-ave.json`](crosswalks/cfgaudit-to-ave.json) |
| ClawScan (OpenClaw) | [`crosswalks/clawscan-to-ave.json`](crosswalks/clawscan-to-ave.json) |
| nova-proximity (Nova-Hunting) | [`crosswalks/nova-proximity-to-ave.json`](crosswalks/nova-proximity-to-ave.json) |
| Ramparts (Highflame Inc.) | [`crosswalks/ramparts-to-ave.json`](crosswalks/ramparts-to-ave.json) |
| Semia (RiemaLabs) | [`crosswalks/semia-to-ave.json`](crosswalks/semia-to-ave.json) |
| SkillSpector (NVIDIA) | [`crosswalks/skillspector-to-ave.json`](crosswalks/skillspector-to-ave.json) |
| skill-security-scanner (honysyang) | [`crosswalks/skill-security-scanner-to-ave.json`](crosswalks/skill-security-scanner-to-ave.json) |
| skillsentry (vythanhtra) | [`crosswalks/skillsentry-to-ave.json`](crosswalks/skillsentry-to-ave.json) |

Maintaining a scanner? The [implementer guide](docs/specs/ave-implementer-guide.md)
covers how to map your rule IDs to AVE ids and add AVE ID emission to your
Expand All @@ -527,7 +543,9 @@ See [GOVERNANCE.md](GOVERNANCE.md) for the decision-making process, how records
are proposed and reviewed, and the path toward neutral governance.

See [docs/specs/scaling-and-governance.md](docs/specs/scaling-and-governance.md)
for record-growth discipline, schema versioning, and deprecation policy.
for record-growth discipline, schema versioning, and deprecation policy,
including AVE's ID stability guarantee: identifiers are never
renumbered or reused once published.

See [docs/specs/researcher-process.md](docs/specs/researcher-process.md)
for the practical, step-by-step process a contributor actually follows
Expand Down
2 changes: 1 addition & 1 deletion dist/ave-records-latest.manifest.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema_version": "1.1.0",
"record_count": 80,
"generated_at": "2026-08-26T00:30:58.084Z",
"generated_at": "2026-08-29T03:57:22.345Z",
"source": "https://github.com/aveproject/ave"
}
Loading
Loading