-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathcfgaudit-to-ave.json
More file actions
356 lines (356 loc) · 16.3 KB
/
Copy pathcfgaudit-to-ave.json
File metadata and controls
356 lines (356 loc) · 16.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
{
"$schema": "https://aveproject.org/schema/crosswalk-1.0.0.schema.json",
"source": {
"tool": "cfgaudit",
"vendor": "cfgaudit",
"version": "1.13.0",
"url": "https://github.com/cfgaudit/cfgaudit",
"license": "Apache-2.0",
"tool_class": "static configuration auditor",
"rules_total": 108,
"rules_mapped": 64,
"commit": "ac9f2a5314f7ae64242a10cade836d83f304987e"
},
"target": {
"standard": "AVE",
"version": "1.1.0",
"url": "https://aveproject.org",
"record_count": 80,
"static_record_count": 58,
"commit": "cd1010e81ad608d0e066ccec387dd5dad7dd3056"
},
"generated": "2026-08-16",
"note": "cfgaudit is a static auditor of committable AI-agent CONFIGURATION files. It does not connect to running servers or observe runtime, so it maps only to AVE's static_detection records. Each cfgaudit rule emits its primary AVE id in JSON/SARIF output (see github.com/cfgaudit/cfgaudit/blob/main/docs/cfgaudit-to-ave.md). Mappings are class-level behavioral equivalence, not asserted identity. cfgaudit now maps 61 config-surface rules onto 27 AVE behavioral classes, up from 53 onto 23 at v1.11.0. Only two of the eight new mappings are new cfgaudit rules; the other six are rules that existed all along and are mapped here for the first time, because AVE-2026-00071, 00072, 00073 and 00076 were published on 2026-08-06 and later, after the v1.11.0 crosswalk was generated on 2026-08-05. Three of those four came out of this crosswalk's own gap list (aveproject/ave#68), which is now down to one open surface. Three cfgaudit rules new in v1.12.0 are deliberately left unmapped rather than fitted to an approximate class; each is listed under config_surfaces_beyond_ave with the reason. Both sides are pinned by commit, so every count here can be re-derived. The cfgaudit tree read is two commits past the v1.12.0 tag, and the delta is stated rather than smoothed over: cfgaudit/cfgaudit#516 corrects CFG071 from unmapped to AVE-2026-00073, and cfgaudit/cfgaudit#518 collapses CFG101's findings to one per permission list. Neither adds or removes a rule, so rules_total holds for the tag as well; rules_mapped at the tag itself is 60, not 61.",
"mappings": [
{
"ave_id": "AVE-2026-00003",
"title": "Credential exfiltration via agent instruction",
"cfgaudit_rules": [
"CFG031",
"CFG036",
"CFG037",
"CFG038"
]
},
{
"ave_id": "AVE-2026-00004",
"title": "Arbitrary code execution via shell pipe injection in agentic component",
"cfgaudit_rules": [
"CFG008",
"CFG014"
]
},
{
"ave_id": "AVE-2026-00005",
"title": "Recursive file system destruction via destructive command injection in agentic component",
"cfgaudit_rules": [
"CFG039"
]
},
{
"ave_id": "AVE-2026-00007",
"title": "Agent goal hijack via direct instruction override in agentic component",
"cfgaudit_rules": [
"CFG026",
"CFG092"
]
},
{
"ave_id": "AVE-2026-00008",
"title": "Agent persistence via self-replication instruction in agentic component",
"cfgaudit_rules": [
"CFG027",
"CFG028"
]
},
{
"ave_id": "AVE-2026-00010",
"title": "Covert instruction concealment via secrecy directive in agentic component",
"cfgaudit_rules": [
"CFG030"
]
},
{
"ave_id": "AVE-2026-00011",
"title": "Arbitrary tool invocation via dynamic tool call injection in agentic component",
"cfgaudit_rules": [
"CFG035"
]
},
{
"ave_id": "AVE-2026-00017",
"title": "MCP Server Impersonation or Spoofing",
"cfgaudit_rules": [
"CFG052",
"CFG059"
]
},
{
"ave_id": "AVE-2026-00021",
"title": "Autonomous Action Without User Confirmation",
"cfgaudit_rules": [
"CFG029"
]
},
{
"ave_id": "AVE-2026-00025",
"title": "Conversation History Injection",
"cfgaudit_rules": [
"CFG032"
]
},
{
"ave_id": "AVE-2026-00027",
"title": "Multi-Turn Attack - Instruction Persistence Across Conversations",
"cfgaudit_rules": [
"CFG081"
]
},
{
"ave_id": "AVE-2026-00029",
"title": "Homoglyph or Unicode Obfuscation Attack",
"cfgaudit_rules": [
"CFG024"
]
},
{
"ave_id": "AVE-2026-00032",
"title": "Network Reconnaissance Instruction",
"cfgaudit_rules": [
"CFG090"
]
},
{
"ave_id": "AVE-2026-00039",
"title": "Covert Channel - Steganographic Data Exfiltration",
"cfgaudit_rules": [
"CFG033",
"CFG072"
]
},
{
"ave_id": "AVE-2026-00047",
"title": "Hardcoded credentials in agent component - API keys and secrets exposed in skill files",
"cfgaudit_rules": [
"CFG007",
"CFG050",
"CFG054",
"CFG065",
"CFG073",
"CFG097"
]
},
{
"ave_id": "AVE-2026-00048",
"title": "Unsafe agent delegation chain - sub-agent spawned with inherited permissions and no trust boundary",
"cfgaudit_rules": [
"CFG051",
"CFG085"
]
},
{
"ave_id": "AVE-2026-00055",
"title": "Command execution via untrusted MCP server launch configuration (STDIO)",
"cfgaudit_rules": [
"CFG019",
"CFG020",
"CFG070"
]
},
{
"ave_id": "AVE-2026-00057",
"title": "Obfuscated or encoded skill payload designed to evade static scanners",
"cfgaudit_rules": [
"CFG057"
]
},
{
"ave_id": "AVE-2026-00058",
"title": "Deceptive skill trigger or activation-scope manipulation via misleading manifest description",
"cfgaudit_rules": [
"CFG056"
]
},
{
"ave_id": "AVE-2026-00061",
"title": "TLS certificate verification disabled in agent component configuration",
"cfgaudit_rules": [
"CFG075"
]
},
{
"ave_id": "AVE-2026-00062",
"title": "Unpinned dependency version allowing supply chain substitution",
"cfgaudit_rules": [
"CFG010",
"CFG055",
"CFG074",
"CFG089",
"CFG098"
]
},
{
"ave_id": "AVE-2026-00063",
"title": "Human approval gate bypassed via declarative configuration, distinct from AVE-2026-00048",
"cfgaudit_rules": [
"CFG003",
"CFG004",
"CFG048",
"CFG053",
"CFG063",
"CFG079",
"CFG087",
"CFG091",
"CFG093",
"CFG096",
"CFG104",
"CFG105"
]
},
{
"ave_id": "AVE-2026-00064",
"title": "Zero-click code execution via project-load auto-run configuration",
"cfgaudit_rules": [
"CFG047",
"CFG067",
"CFG086"
]
},
{
"ave_id": "AVE-2026-00071",
"title": "Container daemon redirected off-host",
"cfgaudit_rules": [
"CFG082"
]
},
{
"ave_id": "AVE-2026-00072",
"title": "MCP server bound to every interface with no authentication step",
"cfgaudit_rules": [
"CFG018"
]
},
{
"ave_id": "AVE-2026-00073",
"title": "Endpoint redirect via a static configuration value",
"cfgaudit_rules": [
"CFG005",
"CFG046",
"CFG071",
"CFG099"
]
},
{
"ave_id": "AVE-2026-00076",
"title": "Natural-language steering of an approval classifier",
"cfgaudit_rules": [
"CFG094",
"CFG103"
],
"note": "CFG103 maps for one of its three findings only: features.guardianv2.classifier_instructions replaces the prompt of Codex's own reviewer, which is this record's mechanism, a committed file aiming natural language at a separate non-primary classifier. cfgaudit reports the stronger form, the whole prompt replaced, where the record describes steering."
}
],
"gaps": [
{
"ave_id": "AVE-2026-00015",
"note": "system-prompt extraction. Maps to OWASP LLM07, which cfgaudit treats as runtime; the instruction is static, but the scope boundary is undecided."
},
{
"ave_id": "AVE-2026-00036",
"note": "lateral movement. cfgaudit implemented and then reverted this rule. The vocabulary ('lateral movement', 'pivot') appears in ordinary security tooling and infrastructure docs, so the false-positive rate was unacceptable for a static config check."
},
{
"ave_id": "AVE-2026-00059",
"note": "fragmented cross-description injection. Needs multi-source correlation; cfgaudit checks each file independently."
},
{
"ave_id": "AVE-2026-00060",
"note": "STDIO transport shell injection. Server-side implementation flaw, requires SAST of the MCP server source rather than reading its launch configuration. Same layer as AVE-2026-00052 and AVE-2026-00053; see the static_detection note below."
},
{
"ave_id": "AVE-2026-00065",
"note": "A2A agent card poisoning. cfgaudit reaches the committed pointer but not the card. A .gemini/agents/*.md may carry an inline agent_card_json, which cfgaudit recognises well enough to classify the file as a remote agent, but it does not audit the card's contents. It does flag a cleartext agent_card_url and a credential literal in the same file's auth block (CFG097)."
},
{
"ave_id": "AVE-2026-00069",
"note": "image-hidden instructions in a skill package. Requires binary content analysis of a bundled image; cfgaudit reads text configuration only. Same layer as AVE-2026-00024."
},
{
"ave_id": "AVE-2026-00077",
"note": "cross-origin tool and resource declaration in one MCP manifest. New gap. cfgaudit reads MCP launch configuration (command, args, env, url, headers), not the manifest a server returns once it is running, so the two declarations this record correlates are never both in view."
}
],
"coverage": {
"ave_static_records": 58,
"cfgaudit_rules_total": 108,
"cfgaudit_rules_mapped": 64,
"ave_classes_covered": 27,
"cfgaudit_rules_unmapped": 44
},
"validation": {
"against": {
"tool": "Bawbel Scanner",
"version": "1.3.0"
},
"method": "same SKILL.md per rule, cfgaudit canonical triggers unmodified, static engines only (pattern+yara+semgrep, no LLM), both reading ave_id from JSON",
"shared_surface_rules": 10,
"agreements": 5,
"note": "5 of the 10 instruction-content rules that share a scan surface with Bawbel: both scanners independently emit the same ave_id. The 5 divergences are detection-pattern differences, not mapping errors. Re-checked at cfgaudit v1.11.0 against AVE record set 1.1.0 (70 records). A false-positive pass over 432 real repositories preceded this release and changed two rules, neither of them mapped: CFG015 and CFG009 stopped firing on hook idioms, and a Cursor build-cache warning was withdrawn."
},
"config_surfaces_beyond_ave": [
{
"surface": "sandbox weakening in config",
"example_rules": [
"CFG022",
"CFG061",
"CFG064",
"CFG079",
"CFG095"
],
"note": "Still open, and the only one of the eight surfaces from aveproject/ave#68 that is. The field list this record would enumerate has now settled, which was the stated reason for holding it: CFG064 reached its final shape in v1.12.0 and no further expansion is planned. Full field list, per agent, in the issue thread. Four mechanisms: (1) the sandbox switched off outright (Codex sandbox_mode danger-full-access, Cursor type insecure_none, Claude Code sandbox.filesystem.disabled). (2) The sandbox left on but widened (Codex [sandbox_workspace_write] network_access and outside-workspace writable_roots, Gemini tools.sandboxAllowedPaths reaching / or ~, tools.sandboxNetworkAccess). (3) The confinement helpers repointed (sandbox.bwrapPath, sandbox.socatPath, sandbox.excludedCommands with a wildcard or a shell, network.allowUnixSockets naming a privileged daemon socket). (4) The same posture reached without touching any sandbox key at all, through Codex's named permission profiles: default_permissions selects a [permissions.<name>] profile whose network block carries enabled, proxy_url, socks_url, dangerously_allow_all_unix_sockets and dangerously_allow_non_loopback_proxy, and whose filesystem block grants ':root' or a credential path. An indicator list keyed on sandbox_mode misses that fourth one entirely."
},
{
"surface": "cleartext endpoint, distinct from TLS verification disabled",
"example_rules": [
"CFG049",
"CFG097"
],
"note": "Mostly closed, and narrower than this row used to claim. AVE-2026-00073 names a cleartext model or provider base URL outright, which is why CFG071 now maps to it and no longer appears here. What is left is a committed http:// MCP server URL (CFG049) and an A2A agent_card_url (CFG097's second half), both reached only by that record's catch-all 'an equivalent traffic-destination value'. Whether to name them explicitly is the open question from aveproject/ave#123. AVE-2026-00061 stays a different failure: verification disabled, not no TLS at all."
},
{
"surface": "plugin auto-load from a committed manifest",
"example_rules": [
"CFG100"
],
"note": "New, and deliberately unmapped rather than forced. Grok's committed config carries a [plugins] table with enabled and paths, which points the agent at plugin code the repository ships. AVE-2026-00064 would be the class, but it requires that the loader runs that code at project load with no prompt, and cfgaudit has not verified that against the shipped Grok build. Mapping it on the strength of the shape alone would assert a mechanism nobody measured. Note the polarity: 'disabled' in that table hardens, so a record enumerating field names should not list it as an indicator."
},
{
"surface": "a guardrail that does not hold, as distinct from an attacker behaviour",
"example_rules": [
"CFG101"
],
"note": "New, and probably outside AVE's model by construction rather than a gap to fill. Claude Code matches a Bash(...) permission pattern as a literal prefix, so a deny rule naming bundled short flags is walked past by writing the same flags in another order: Bash(rm -rf *) never covered rm -fr x. Measured against Claude Code 2.1.231, and roughly 44% of 22,016 indexed settings.json files carrying a deny block leave the gap open. AVE-2026-00063 is a flag that removes a gate and AVE-2026-00068 is composition through shell state; neither is 'the denylist misses an equivalent spelling'. Recorded here because a taxonomy of agent vulnerabilities may want a place for ineffective controls, not because cfgaudit is asking for a record."
},
{
"surface": "two committed skills claiming one name",
"example_rules": [
"CFG102"
],
"note": "New. Name shadowing between two skill files in the same repository, where load order decides which body runs. AVE-2026-00017 is the closest class but is explicitly MCP server identity, and AVE-2026-00066 is registry squatting on hallucinated names; neither covers two local files. Reported as a gap rather than mapped to either."
},
{
"surface": "automated security reviewer switched off or blunted by config",
"example_rules": [
"CFG103"
],
"note": "Codex's [features.guardianv2] decides whether its own reviewer runs (enabled), at what score it escalates to a blocking review (review_threshold, default 0.5), and what prompt it is given. The prompt half maps to AVE-2026-00076. Switching the reviewer off or raising the threshold does not: AVE-2026-00063 is explicitly a bypassed *human*-approval step, and Guardian v2 is automated. features is not on Codex's project-layer denylist, so a committed .codex/config.toml sets all three."
},
{
"surface": "repository grants the agent browser or desktop-application access",
"example_rules": [
"CFG106"
],
"note": "Codex's [browser_use] grants per-origin access including full_cdp_access (script, cookie and storage access inside the browser session) and [computer_use] grants desktop application control. Deliberately not filed under AVE-2026-00063: whether a prompt is skipped is unverified, since the value is observable in the effective config but the tools live in the client app, so the class would assert more than the detection does."
}
]
}