First-party concept registry for CLAWLINE terminology and external term crosswalk mapping.
chain-of-custody
Chain-of-Custody Evidence
Artifact-bound evidence that links released artifacts to declared source/build lineage with explicit verification state.
Evidence: Artifact digests plus provenance statement and signature material; optional SBOM and builder claims.
External aliases: SLSA provenance, SLSA attestations, Build provenance
Tags: 7 · Rules: 4
shadow_prompting_input_stack_integrity
Shadow Prompting / Input Stack Integrity
Untrusted instructions enter the model via context layers (documents, tool output, memory, connector payloads) and compete with policy intent.
Evidence: Structured context-source declarations and deterministic findings that show untrusted instruction channels or hierarchy collisions.
External aliases: Indirect Prompt Injection
Tags: 7 · Rules: 1
tool_contamination
Tool Contamination
Instruction-bearing metadata or tool descriptions mutate operator intent by embedding hidden control language in tool interfaces.
Evidence: Tool definitions, metadata fields, and deterministic pattern findings showing instruction-bearing contamination surfaces.
External aliases: Tool Poisoning, Metadata-layer injection, Line-jumping
Tags: 2 · Rules: 4
definition_drift
Definition Drift
The effective tool/server definition changes after consent. Hash-locked posture and drift checks are required for stable trust claims.
Evidence: Versioned manifests or prior snapshots with deterministic hash deltas for the same identity scope.
External aliases: Rug Pull, Post-consent mutation
Tags: 1 · Rules: 2
clawpath_risk
ClawPath Risk
Static composition score for whether untrusted input can transit to privileged access and action/exfil sinks.
Evidence: Structured posture describing input trust, sensitive capabilities, and sink channels. No runtime execution evidence is required.
External aliases: Toxic flows, Toxic Flow Analysis
Tags: 6 · Rules: 3
triad_condition
Triad Condition
Structural conjunction of untrusted input, sensitive access, and sink capability.
Evidence: Deterministic structural findings proving the three required condition classes in the same posture snapshot.
External aliases: Lethal trifecta
Tags: 2 · Rules: 3
declared_required_tier_delta
Declared Tier vs Required Tier (Delta)
Compares self-declared privilege posture against structurally required posture and computes a deterministic delta.
Evidence: Valid declared tier plus parseable structured posture inputs (connectors, tools, MCP permissions, or equivalent).
External aliases: Least privilege mismatch, Capability mismatch
Tags: 2 · Rules: 2
evidence_bound_integrity
Evidence-Bound Integrity
Integrity claims are asserted only when required structural evidence exists; otherwise outputs remain UNKNOWN, PARTIAL, or ABSENT.
Evidence: Structured blocks, parse quality, and cross-source identity checks that satisfy completeness thresholds.
External aliases: Evidence coverage, Assurance completeness
Tags: 3 · Rules: 1
review_required_containment
Review Required (Containment)
Neutral containment state used when deterministic policy requires human review before publication trust.
Evidence: Any policy-triggering structural condition (campaign signals, drift, high mismatch, or other freeze criteria).
External aliases: Quarantine, Hold for review, Containment hold
Tags: 6 · Rules: 6
mcp_posture_and_pinning
MCP Posture and Pinning
Tracks MCP inventory, pinning quality, collisions, and drift to preserve trust in tool-plane definitions.
Evidence: Structured MCP inventories, tool definitions, and deterministic hashes across submissions.
External aliases: MCP hygiene, Tool pinning posture, Server-tool integrity
Tags: 5 · Rules: 4
campaign_meta_signals
Campaign Meta-Signals
Clinic-wide meta-signals based on submission behavior patterns (burst, resubmit loops, identity spray), not payload intent labels.
Evidence: Privacy-preserving source hashes, submission windows, and content similarity fingerprints.
External aliases: Coordinated abuse detection, Submission campaign detection
Tags: 3 · Rules: 1
version_schema_posture
Version and Schema Posture
Tracks platform/schema declaration quality and freshness to prevent stale or conflicting trust posture claims.
Evidence: Declared platform and schema versions plus deterministic parser output for version tags.
External aliases: Version drift, Schema compliance posture
Tags: 6 · Rules: 1