Extend whitehat-target/v1 with fixture-asm/asm instead of mapping onto E2, E3, or capacity. Register all ten Canon tests as pending with named blockers, known-bad designs, and result routes. Add a value-safe conformance-message renderer. Authorizes no probe. Assistant: grok Assistant-Session: 01a05e32-c776-72a3-86ec-c490e027aca9
44 lines
1.3 KiB
JSON
44 lines
1.3 KiB
JSON
{
|
|
"schema_version": "whitehat-target/v1",
|
|
"target_id": "asm-t05",
|
|
"posture_claim": "ASM T-05",
|
|
"attacker_model": "replay of service-A authority at service B, including MCP inbound-token passthrough",
|
|
"applicability": "pending",
|
|
"applicability_reason": "No two named protected services with distinct audiences registered for this attacker. audit-core E2 is tenant isolation, not audience replay. Known-bad design: disable audience/resource validation so A's artifact is accepted at B. This registration does not authorize a probe.",
|
|
"approval_classes": [
|
|
"asm"
|
|
],
|
|
"specification": "asm-assurance-targets.v1",
|
|
"test_id": "T-05",
|
|
"title": "Confused Deputy Test",
|
|
"claims": [
|
|
"INV-03",
|
|
"A-10",
|
|
"A-13"
|
|
],
|
|
"oracle": "wrong-audience-or-resource-rejected",
|
|
"surface": [
|
|
"service-a",
|
|
"service-b",
|
|
"mcp-pep",
|
|
"credential-exchange"
|
|
],
|
|
"result_route": {
|
|
"conformance": "gate-house",
|
|
"implementation_finding": "risk-nexus",
|
|
"specification_finding": "gate-house",
|
|
"harness_gap": "whitehat-security"
|
|
},
|
|
"routes": [],
|
|
"identities": {
|
|
"count": 0,
|
|
"role": "none until the owning surface names a test identity",
|
|
"broker_audience": "whitehat-asm/t-05"
|
|
},
|
|
"abort_telemetry": [
|
|
"kill_switch",
|
|
"scope_boundary",
|
|
"missing_known_bad_calibration",
|
|
"secret_value_observed"
|
|
]
|
|
}
|