← Origins
CrosswalkGlossaryMethodologyWhitepaper

ClawPath Risk

clawpath_risk

Static composition score for whether untrusted input can transit to privileged access and action/exfil sinks.

Decision Context

Evidence required: Structured posture describing input trust, sensitive capabilities, and sink channels. No runtime execution evidence is required.

Decision impact: High clawpath levels can trigger FREEZE; medium levels commonly trigger WARN based on accompanying conditions.

Linked CRABS Tags
CRABS-C70, CRABS-A70, CRABS-A71, CRABS-A73, CRABS-A74, CRABS-A72
Linked DAD Rules
DAD-CRT-62, DAD-CRT-63, DAD-WRN-62

External Aliases

  • Toxic flows
  • Toxic Flow Analysis

References