fix(lexicon,docs): retract the claim that the guard's port cites severity.mjs
The guard asked twice which file:line carried it. Tracing it produced an uncomfortable answer: no file of ours measured it. The claim arrived from llm-security (coord 20260809T201048Z) and was written down here as a commons finding in three places. Measured against the guard's own tree: severity.mjs has never appeared in src/llm_ingestion_guard/injection_lexicon.json at any point in that file's history (git log -S: no commits), and at 0bf0729 - the commit our manifest pins - the only tree-wide occurrence is docs/PLAN.md:114, correctly about the report module. Their only lexicon source statement is the note at line 3, and it names injection-patterns.mjs. The right file. No detection data moves. hybrid severity is still high, still sourced to injection-patterns.mjs:274-281 at b0de0ca; severity.mjs still has zero occurrences of the four pattern arrays, re-measured today. Only the sentence about the other repository falls. Marked in place, not edited away. The claim survived review because it came bundled with a correct measurement of the same question - a wrong citation to a right value, which is exactly what the field it lived in was written to warn against. lexicon/injection-lexicon.json 0.5.0 -> 0.5.1 (provenance metadata only). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DWKkmKQBsWtrkod4MusUBC
This commit is contained in:
parent
0ffee85a4b
commit
f082a91995
3 changed files with 68 additions and 8 deletions
|
|
@ -1,5 +1,5 @@
|
|||
{
|
||||
"version": "0.5.0",
|
||||
"version": "0.5.1",
|
||||
"id": "injection-lexicon",
|
||||
"description": "Prompt-injection pattern lexicon: the four pattern families a detector matches against untrusted text, and the severity family each belongs to. Data only. The variant building that feeds these patterns (normalisation, homoglyph folding, rot13, unicode-tag escalation) and the buried-payload heuristic are engine behaviour and are deliberately NOT described here.",
|
||||
"owasp": "LLM01",
|
||||
|
|
@ -894,7 +894,8 @@
|
|||
"source_lines": "274-281",
|
||||
"source_commit": "b0de0ca6d86ce697f39669d177c2c2654c280128",
|
||||
"verified": "directly, by reading the module at the pinned commit",
|
||||
"not_from": "scanners/lib/severity.mjs, which was the first file asked about and which contains no injection-family severity at all - grep for CRITICAL_PATTERNS, HIGH_PATTERNS, MEDIUM_PATTERNS or HYBRID_PATTERNS there returns nothing. The Python guard's port carries the correct value but cites that file, so a consumer following its citation would find no answer. Recorded because a wrong citation to a right value is the harder defect to notice."
|
||||
"not_from": "scanners/lib/severity.mjs, which was the first file asked about and which contains no injection-family severity at all - grep for CRITICAL_PATTERNS, HIGH_PATTERNS, MEDIUM_PATTERNS or HYBRID_PATTERNS there returns nothing at the pinned commit. That part stands and was re-measured 2026-08-10.",
|
||||
"retracted_2026-08-10": "This field also said: 'The Python guard's port carries the correct value but cites that file, so a consumer following its citation would find no answer.' RETRACTED - it is false, and it was never measured here. It restated an assertion received from llm-security (coord message 20260809T201048Z) as if it were a commons finding. Measured against the guard's own tree: severity.mjs has never appeared in src/llm_ingestion_guard/injection_lexicon.json at any point in that file's history (git log -S returns no commits), and at 0bf0729 - the commit conformance/manifest.json pins - the only tree-wide occurrence is docs/PLAN.md:114, which correctly attributes the report module to output.mjs + severity.mjs and says nothing about injection-family severity. The guard's only source statement for the lexicon is the note field at injection_lexicon.json:3, and it cites injection-patterns.mjs - the right file. Kept rather than deleted because this repository's stated reason for recording the original claim was that a wrong citation to a right value is the harder defect to notice, and that turned out to describe this record itself."
|
||||
},
|
||||
"count": 8,
|
||||
"patterns": [
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue