feat(calibration): add calibration.json, marked transcribed-only
The risk-score tier constants, verdict thresholds, risk-band cutoffs and posture grade thresholds. Constants only — the log scaling and the if/else chains that consume them are engine and stay in the consumer. This file is the exception in this repository and is marked as such in its own verification block. Every other data file here was rebuilt from its commons JSON and diffed against an imported module. This one arrived as a human-written PROSE SUMMARY of severity.mjs, so there was nothing to import and nothing to diff. verified: false, with the two skipped checks named rather than a caveat attached to a pass. The consequence inverts this repository's central rule and the file says so: for every other file a disagreeing consumer is wrong; for this one, until the module arrives in executable form, a disagreement is not automatically the consumer's bug. What COULD be checked was: bands are contiguous and non-overlapping across 0-100, the BLOCK trigger (65) is exactly the Critical band floor, the WARNING trigger (15) is exactly the Medium band floor, and the per-tier reachable minima recompute exactly (80/48/20/4, exact because log2(2) is 1). Corrects README and the extraction plan in the same commit: both promised entropy floors, scan caps and disposition ranks. None arrived — 0 occurrences each across the whole dump. Named in the file under not_supplied so the absence is visible rather than inferred, and both rows now describe what is actually present. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FaYqid3mejFmd9ZHsiHgp3
This commit is contained in:
parent
dd6ae51d60
commit
8ee297c585
3 changed files with 210 additions and 2 deletions
|
|
@ -55,7 +55,7 @@ and keeping it that small is the point.
|
|||
| [`signatures/secret-egress.json`](signatures/secret-egress.json) | Credential and token shapes that must never leave a machine, in a portable regex dialect. |
|
||||
| [`signatures/malware-signatures.json`](signatures/malware-signatures.json) | Signature set for the malicious-code class (`SIG`). |
|
||||
| [`signatures/active-content.json`](signatures/active-content.json) | Active content that renders or fetches on its own — Markdown images, links, reference definitions and autolinks, `data:` URIs, active HTML. The EchoLeak class. |
|
||||
| [`calibration/calibration.json`](calibration/calibration.json) | The numbers a detector must not invent: entropy floors, scan caps, disposition ranks. |
|
||||
| [`calibration/calibration.json`](calibration/calibration.json) | The numbers a detector must not invent: risk-score tier constants, verdict thresholds, risk-band cutoffs, posture grade thresholds. Transcribed from a prose summary, not differentially verified — the file says so itself. |
|
||||
| [`mapping/owasp-map.json`](mapping/owasp-map.json) | Finding-id prefix → OWASP taxonomy entry (LLM / ASI / AST / MCP). |
|
||||
| [`schema/finding.schema.json`](schema/finding.schema.json) | **Normative.** The finding contract, plus the SARIF and JSONL output profiles. |
|
||||
| [`spec/decode-pipeline.md`](spec/decode-pipeline.md) | **Normative.** The decode order, in RFC 2119 language. Two runtimes that decode in different orders will disagree on identical input; this is the file that stops that. |
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue