{
  "schemaVersion": 1,
  "kind": "csint-n8n-workflow-change-receipt",
  "reviewEngineVersion": "1.3.0",
  "fingerprintAlgorithm": "sha256-canonical-json-v1",
  "generatedAt": "2026-09-30T12:00:00.000Z",
  "reviewId": "wcr-fb5ed970c1fb-21155a81",
  "title": "Değişiklik A: Ajana üç tehdit istihbaratı aracı ekleniyor",
  "reviewer": "Ahmet Göker",
  "decision": "review",
  "decisionReason": "Static evidence is available, but no passing staging receipt is bound to this exact candidate.",
  "decisionBasis": "no-runtime",
  "subject": {
    "baseline": {
      "name": "Scanner Alert Triage",
      "fingerprint": "21155a81aa9e0dd404fdf028122064518b514b540535622bd6c6a0a6bead5473",
      "nodeCount": 5
    },
    "candidate": {
      "name": "Scanner Alert Triage",
      "fingerprint": "fb5ed970c1fb031f596090b94acf531dc8ec3fc19661290386a5538b9c232a38",
      "nodeCount": 8
    }
  },
  "summary": {
    "changes": 9,
    "blocker": 0,
    "review": 6,
    "improvement": 0,
    "context": 3,
    "connectionsAdded": 3,
    "connectionsRemoved": 0,
    "introducedFindings": 1,
    "resolvedFindings": 0,
    "openFindings": 7,
    "preExistingOpenFindings": 6,
    "renamedNodes": 0
  },
  "runtime": {
    "status": "not-run",
    "bound": false,
    "verifiedAt": null,
    "executedWorkflowFingerprint": null,
    "scenarios": {
      "passed": 0,
      "failed": 0,
      "total": 0
    },
    "checks": {
      "passed": 0,
      "total": 0
    },
    "externalActionsExecuted": null,
    "coveredStaticRules": [],
    "note": "No candidate-bound staging receipt was supplied."
  },
  "retest": {
    "status": "not-supplied",
    "priorReviewId": null,
    "priorCandidateFingerprint": null,
    "priorDecision": null,
    "priorFindingRuleIds": [],
    "fixedFindingRuleIds": [],
    "remainingFindingRuleIds": [],
    "introducedFindingRuleIds": [],
    "note": "No prior ReleaseGuard receipt was supplied for retest comparison."
  },
  "manualReviews": [
    {
      "id": "MR-001",
      "appliesTo": "finding",
      "subjectId": "TG-100-01",
      "status": "likely",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Webhook'tan Alert Triage Agent üzerinden Send a message adımına giden yol gerçek: alert JSON'unun tamamı prompta giriyor ve alert alanları saldırganın kontrol ettiği bir metin taşıyabilir, örneğin bir kullanıcı veya kaynak adı. Webhook header doğrulaması kullanıyor ve son adım tek bir sabit Slack kanalına yazıyor; en kötü sonuç yanlış veya yanıltıcı bir triage notu. Bu şablon için kritik değil, orta seviye derim."
    },
    {
      "id": "MR-002",
      "appliesTo": "finding",
      "subjectId": "AA-003-02",
      "status": "confirmed",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Doğrulandı. Prompt, istek öğesinin tamamı JSON.stringify ile yazılarak kuruluyor; öncesinde boyutu sınırlayan veya serbest metni ayıklayan bir adım yok. Bir triage ajanı için bu tasarım gereği; bu yüzden çağırabildiği araçların yalnız okuma yapması önemli."
    },
    {
      "id": "MR-003",
      "appliesTo": "finding",
      "subjectId": "AA-004-03",
      "status": "confirmed",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Doğrulandı ve tasarım gereği: model çıktısı onay adımı olmadan Slack'e gönderiliyor. Triage notunu kanala yazmak workflow'un amacı. Burada onay gerekmiyor, ama başka bir yere yazan her adımdan önce gerekiyor."
    },
    {
      "id": "MR-004",
      "appliesTo": "finding",
      "subjectId": "AA-006-04",
      "status": "needs-environment-evidence",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Exportta görünür bir hız veya maliyet sınırı yok. Alertler header doğrulamasının arkasındaki tespit platformundan geliyor; sınır gönderen tarafta olabilir, export bunu gösteremez. Alert hızının nerede sınırlandığını ekibe sorun."
    },
    {
      "id": "MR-005",
      "appliesTo": "finding",
      "subjectId": "AA-005-05",
      "status": "confirmed",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Doğrulandı. Slack metni, yalnız ilk siren emojisinden itibaren kesilen model çıktısı. Üzerinde şema kontrolü çalışmıyor."
    },
    {
      "id": "MR-006",
      "appliesTo": "finding",
      "subjectId": "AA-008-06",
      "status": "confirmed",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Doğrulandı, bu değişiklikle geldi. ThreatFox IOC Lookup, OTX Pulse Search ve Feodo Tracker'da zaman aşımı ve yeniden deneme yok. Yavaş bir sorgu API'si ajan çalışmasını bekletir. Düzeltme: her birinde yaklaşık 10 ile 15 saniye ve tek yeniden deneme."
    },
    {
      "id": "MR-007",
      "appliesTo": "finding",
      "subjectId": "AA-010-07",
      "status": "confirmed",
      "reviewer": "Ahmet Göker",
      "reviewedAt": "2026-09-30T13:00:00.000Z",
      "note": "Doğrulandı, düşük. Hata workflow'u tanımlı değil; başarısız bir triage çalışması, biri çalışma listesine bakmadıkça fark edilmez."
    }
  ],
  "environmentEvidence": {
    "instanceAudit": null,
    "publishedWorkflowIdentity": {
      "status": "not-verified",
      "note": "The identity of the workflow actually published to production was not independently verified."
    },
    "productionPermissions": {
      "status": "not-verified",
      "note": "Production credential and external-service permissions were not independently verified."
    },
    "productionRegister": []
  },
  "customerAcceptance": {
    "status": "not-recorded",
    "acceptedBy": "Customer acceptance pending",
    "recordedAt": null,
    "note": ""
  },
  "changes": [
    {
      "id": "CR-001",
      "kind": "finding-introduced",
      "impact": "review",
      "title": "A new medium finding was introduced: Outbound requests do not show an explicit timeout or retry policy",
      "note": "Outbound HTTP nodes have no explicit timeout or retry policy.",
      "evidence": {
        "ruleId": "AA-008",
        "severity": "medium",
        "nodes": [
          "Feodo Tracker",
          "OTX Pulse Search",
          "ThreatFox IOC Lookup"
        ]
      }
    },
    {
      "id": "CR-002",
      "kind": "outbound-domain-added",
      "impact": "review",
      "title": "A new external destination appears: feodotracker.abuse.ch",
      "note": "Confirm the owner, data purpose and retention terms before allowing this destination.",
      "evidence": {
        "domain": "feodotracker.abuse.ch"
      }
    },
    {
      "id": "CR-003",
      "kind": "outbound-domain-added",
      "impact": "review",
      "title": "A new external destination appears: otx.alienvault.com",
      "note": "Confirm the owner, data purpose and retention terms before allowing this destination.",
      "evidence": {
        "domain": "otx.alienvault.com"
      }
    },
    {
      "id": "CR-004",
      "kind": "outbound-domain-added",
      "impact": "review",
      "title": "A new external destination appears: threatfox-api.abuse.ch",
      "note": "Confirm the owner, data purpose and retention terms before allowing this destination.",
      "evidence": {
        "domain": "threatfox-api.abuse.ch"
      }
    },
    {
      "id": "CR-005",
      "kind": "read-only-post-lookup",
      "impact": "review",
      "title": "A POST request is treated as a read-only lookup: ThreatFox IOC Lookup",
      "note": "POST alone is not a write. The request body asks for a search, lookup or read. Confirm in the API documentation that this call cannot change data, and record which values the model sends to this third party.",
      "evidence": {
        "node": "ThreatFox IOC Lookup",
        "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest",
        "reason": "The request body asks for a search, lookup or read."
      }
    },
    {
      "id": "CR-006",
      "kind": "node-config-changed",
      "impact": "review",
      "title": "Security-relevant configuration changed: Alert Triage Agent",
      "note": "The node behaviour changed outside layout-only fields. Review the candidate configuration and the attached staging evidence.",
      "evidence": {
        "node": "Alert Triage Agent",
        "nodeType": "@n8n/n8n-nodes-langchain.agent",
        "credentialsChanged": false,
        "activationChanged": false
      }
    },
    {
      "id": "CR-007",
      "kind": "node-added",
      "impact": "context",
      "title": "A workflow step was added: Feodo Tracker",
      "note": "The candidate introduces @n8n/n8n-nodes-langchain.toolHttpRequest. Review its inputs, permissions and failure behaviour.",
      "evidence": {
        "node": "Feodo Tracker",
        "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest",
        "nodeKind": "tool"
      }
    },
    {
      "id": "CR-008",
      "kind": "node-added",
      "impact": "context",
      "title": "A workflow step was added: OTX Pulse Search",
      "note": "The candidate introduces @n8n/n8n-nodes-langchain.toolHttpRequest. Review its inputs, permissions and failure behaviour.",
      "evidence": {
        "node": "OTX Pulse Search",
        "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest",
        "nodeKind": "tool"
      }
    },
    {
      "id": "CR-009",
      "kind": "node-added",
      "impact": "context",
      "title": "A workflow step was added: ThreatFox IOC Lookup",
      "note": "The candidate introduces @n8n/n8n-nodes-langchain.toolHttpRequest. Review its inputs, permissions and failure behaviour.",
      "evidence": {
        "node": "ThreatFox IOC Lookup",
        "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest",
        "nodeKind": "tool"
      }
    }
  ],
  "candidateEvidence": {
    "analyzerVersion": "1.1.0",
    "policy": {
      "allowedOutboundDomains": [],
      "blockedNodeTypes": [],
      "blockedCredentialTypes": [],
      "requireHumanApprovalBefore": [],
      "dynamicTargetPolicy": "review"
    },
    "inventory": {
      "triggers": [
        {
          "name": "Webhook",
          "type": "n8n-nodes-base.webhook"
        }
      ],
      "aiAgents": [
        {
          "name": "Alert Triage Agent",
          "type": "@n8n/n8n-nodes-langchain.agent",
          "tools": [
            "Feodo Tracker",
            "OTX Pulse Search",
            "Scanner MCP",
            "ThreatFox IOC Lookup"
          ],
          "memory": []
        }
      ],
      "modelNodes": [
        {
          "name": "Anthropic Chat Model",
          "type": "@n8n/n8n-nodes-langchain.lmChatAnthropic"
        }
      ],
      "toolNodes": [
        {
          "name": "Feodo Tracker",
          "type": "@n8n/n8n-nodes-langchain.toolHttpRequest",
          "agent": "Alert Triage Agent"
        },
        {
          "name": "OTX Pulse Search",
          "type": "@n8n/n8n-nodes-langchain.toolHttpRequest",
          "agent": "Alert Triage Agent"
        },
        {
          "name": "Scanner MCP",
          "type": "@n8n/n8n-nodes-langchain.mcpClientTool",
          "agent": "Alert Triage Agent"
        },
        {
          "name": "ThreatFox IOC Lookup",
          "type": "@n8n/n8n-nodes-langchain.toolHttpRequest",
          "agent": "Alert Triage Agent"
        }
      ],
      "outboundDomains": [
        {
          "domain": "feodotracker.abuse.ch",
          "nodes": [
            "Feodo Tracker"
          ]
        },
        {
          "domain": "mcp.your-env.scanner.dev",
          "nodes": [
            "Scanner MCP"
          ]
        },
        {
          "domain": "otx.alienvault.com",
          "nodes": [
            "OTX Pulse Search"
          ]
        },
        {
          "domain": "threatfox-api.abuse.ch",
          "nodes": [
            "ThreatFox IOC Lookup"
          ]
        }
      ],
      "credentialTypes": [
        {
          "type": "anthropicapi",
          "nodes": [
            "Anthropic Chat Model"
          ]
        },
        {
          "type": "httpbearerauth",
          "nodes": [
            "Scanner MCP"
          ]
        },
        {
          "type": "httpheaderauth",
          "nodes": [
            "OTX Pulse Search",
            "ThreatFox IOC Lookup",
            "Webhook"
          ]
        },
        {
          "type": "slackapi",
          "nodes": [
            "Send a message"
          ]
        }
      ]
    },
    "graph": {
      "nodes": [
        {
          "id": "Anthropic Chat Model",
          "findings": [
            "AA-005-05"
          ],
          "severity": "medium",
          "label": "Anthropic Chat Model",
          "kind": "model",
          "nodeType": "@n8n/n8n-nodes-langchain.lmChatAnthropic"
        },
        {
          "id": "Alert Triage Agent",
          "findings": [
            "AA-003-02",
            "AA-004-03",
            "AA-005-05",
            "TG-100-01"
          ],
          "severity": "critical",
          "label": "Alert Triage Agent",
          "kind": "ai-agent",
          "nodeType": "@n8n/n8n-nodes-langchain.agent"
        },
        {
          "id": "Scanner MCP",
          "findings": [],
          "severity": null,
          "label": "Scanner MCP",
          "kind": "tool",
          "nodeType": "@n8n/n8n-nodes-langchain.mcpClientTool"
        },
        {
          "id": "ThreatFox IOC Lookup",
          "findings": [
            "AA-008-06"
          ],
          "severity": "medium",
          "label": "ThreatFox IOC Lookup",
          "kind": "tool",
          "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest"
        },
        {
          "id": "OTX Pulse Search",
          "findings": [
            "AA-008-06"
          ],
          "severity": "medium",
          "label": "OTX Pulse Search",
          "kind": "tool",
          "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest"
        },
        {
          "id": "Feodo Tracker",
          "findings": [
            "AA-008-06"
          ],
          "severity": "medium",
          "label": "Feodo Tracker",
          "kind": "tool",
          "nodeType": "@n8n/n8n-nodes-langchain.toolHttpRequest"
        },
        {
          "id": "Send a message",
          "findings": [
            "AA-004-03",
            "TG-100-01"
          ],
          "severity": "critical",
          "label": "Send a message",
          "kind": "high-impact-action",
          "nodeType": "n8n-nodes-base.slack"
        },
        {
          "id": "Webhook",
          "findings": [
            "AA-003-02",
            "AA-006-04",
            "TG-100-01"
          ],
          "severity": "critical",
          "label": "Webhook",
          "kind": "untrusted-input",
          "nodeType": "n8n-nodes-base.webhook"
        },
        {
          "id": "credential:anthropicapi",
          "findings": [],
          "severity": null,
          "label": "anthropicapi",
          "kind": "credential",
          "nodeType": "credential"
        },
        {
          "id": "credential:httpbearerauth",
          "findings": [],
          "severity": null,
          "label": "httpbearerauth",
          "kind": "credential",
          "nodeType": "credential"
        },
        {
          "id": "credential:httpheaderauth",
          "findings": [],
          "severity": null,
          "label": "httpheaderauth",
          "kind": "credential",
          "nodeType": "credential"
        },
        {
          "id": "credential:slackapi",
          "findings": [],
          "severity": null,
          "label": "slackapi",
          "kind": "credential",
          "nodeType": "credential"
        },
        {
          "id": "domain:feodotracker.abuse.ch",
          "findings": [],
          "severity": null,
          "label": "feodotracker.abuse.ch",
          "kind": "external-domain",
          "nodeType": "domain"
        },
        {
          "id": "domain:mcp.your-env.scanner.dev",
          "findings": [],
          "severity": null,
          "label": "mcp.your-env.scanner.dev",
          "kind": "external-domain",
          "nodeType": "domain"
        },
        {
          "id": "domain:otx.alienvault.com",
          "findings": [],
          "severity": null,
          "label": "otx.alienvault.com",
          "kind": "external-domain",
          "nodeType": "domain"
        },
        {
          "id": "domain:threatfox-api.abuse.ch",
          "findings": [],
          "severity": null,
          "label": "threatfox-api.abuse.ch",
          "kind": "external-domain",
          "nodeType": "domain"
        }
      ],
      "edges": [
        {
          "from": "Alert Triage Agent",
          "to": "Anthropic Chat Model",
          "kind": "model",
          "risk": false,
          "findings": []
        },
        {
          "from": "Alert Triage Agent",
          "to": "Send a message",
          "kind": "flow",
          "risk": true,
          "findings": [
            "TG-100-01",
            "AA-004-03"
          ]
        },
        {
          "from": "Alert Triage Agent",
          "to": "Scanner MCP",
          "kind": "tool",
          "risk": false,
          "findings": []
        },
        {
          "from": "Alert Triage Agent",
          "to": "ThreatFox IOC Lookup",
          "kind": "tool",
          "risk": false,
          "findings": []
        },
        {
          "from": "Alert Triage Agent",
          "to": "OTX Pulse Search",
          "kind": "tool",
          "risk": false,
          "findings": []
        },
        {
          "from": "Alert Triage Agent",
          "to": "Feodo Tracker",
          "kind": "tool",
          "risk": false,
          "findings": []
        },
        {
          "from": "Webhook",
          "to": "Alert Triage Agent",
          "kind": "flow",
          "risk": true,
          "findings": [
            "TG-100-01",
            "AA-003-02"
          ]
        },
        {
          "from": "Anthropic Chat Model",
          "to": "credential:anthropicapi",
          "kind": "credential",
          "risk": false,
          "findings": []
        },
        {
          "from": "Scanner MCP",
          "to": "credential:httpbearerauth",
          "kind": "credential",
          "risk": false,
          "findings": []
        },
        {
          "from": "OTX Pulse Search",
          "to": "credential:httpheaderauth",
          "kind": "credential",
          "risk": false,
          "findings": []
        },
        {
          "from": "ThreatFox IOC Lookup",
          "to": "credential:httpheaderauth",
          "kind": "credential",
          "risk": false,
          "findings": []
        },
        {
          "from": "Webhook",
          "to": "credential:httpheaderauth",
          "kind": "credential",
          "risk": false,
          "findings": []
        },
        {
          "from": "Send a message",
          "to": "credential:slackapi",
          "kind": "credential",
          "risk": false,
          "findings": []
        },
        {
          "from": "Feodo Tracker",
          "to": "domain:feodotracker.abuse.ch",
          "kind": "outbound",
          "risk": false,
          "findings": []
        },
        {
          "from": "Scanner MCP",
          "to": "domain:mcp.your-env.scanner.dev",
          "kind": "outbound",
          "risk": false,
          "findings": []
        },
        {
          "from": "OTX Pulse Search",
          "to": "domain:otx.alienvault.com",
          "kind": "outbound",
          "risk": false,
          "findings": []
        },
        {
          "from": "ThreatFox IOC Lookup",
          "to": "domain:threatfox-api.abuse.ch",
          "kind": "outbound",
          "risk": false,
          "findings": []
        }
      ]
    },
    "findings": [
      {
        "ruleId": "TG-100",
        "group": "critical-paths",
        "severity": "critical",
        "title": "A prompt-injection source can steer a privileged action through the AI agent",
        "description": "Content from an untrusted trigger reaches the model and the model can reach a privileged external action, with no validation or human approval anywhere on the path. A crafted input can therefore choose or influence the final action.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Send a message",
          "Webhook"
        ],
        "evidence": {
          "path": [
            "Webhook",
            "Alert Triage Agent",
            "Send a message"
          ]
        },
        "remediation": "Break the chain: validate and constrain the input before the model, and require an explicit human approval step before the privileged action. Treat all trigger content as data, never as instructions.",
        "references": [
          "OWASP LLM01: Prompt Injection",
          "OWASP LLM06: Excessive Agency",
          "MITRE ATLAS AML.T0051: LLM Prompt Injection"
        ],
        "id": "TG-100-01"
      },
      {
        "ruleId": "AA-003",
        "group": "critical-paths",
        "severity": "high",
        "title": "Untrusted input can reach a model without a visible validation boundary",
        "description": "Untrusted input reaches a model node with no visible validation boundary on the path.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Webhook"
        ],
        "evidence": {
          "detail": "Path: Webhook + Alert Triage Agent.",
          "path": [
            "Webhook",
            "Alert Triage Agent"
          ]
        },
        "remediation": "Add a deterministic validation step before the model. Enforce size, type and allowlist rules, separate instructions from data, and test direct and indirect prompt injection cases.",
        "references": [
          "OWASP LLM01: Prompt Injection"
        ],
        "id": "AA-003-02"
      },
      {
        "ruleId": "AA-004",
        "group": "approval-gaps",
        "severity": "high",
        "title": "A model can reach an external write action without an approval step",
        "description": "A model node can reach an external write action with no approval step on the path.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Send a message"
        ],
        "evidence": {
          "detail": "Path: Alert Triage Agent + Send a message.",
          "path": [
            "Alert Triage Agent",
            "Send a message"
          ]
        },
        "remediation": "Require explicit human approval for messages, writes, deletions, purchases, account changes and other high-impact actions. Use least-privilege credentials for the final action.",
        "references": [
          "OWASP LLM06: Excessive Agency"
        ],
        "id": "AA-004-03"
      },
      {
        "ruleId": "AA-006",
        "group": "excessive-agency",
        "severity": "high",
        "title": "No rate or cost boundary was detected before model usage",
        "description": "No rate or cost boundary was detected between external input and model usage.",
        "affectedNodes": [
          "Webhook"
        ],
        "evidence": {
          "detail": "External inputs: Webhook."
        },
        "remediation": "Add per-user and per-origin limits, a maximum input size, a model-call budget, timeouts, and a bounded retry policy.",
        "references": [
          "OWASP LLM10: Unbounded Consumption"
        ],
        "id": "AA-006-04"
      },
      {
        "ruleId": "AA-005",
        "group": "excessive-agency",
        "severity": "medium",
        "title": "No structured model-output validation was detected",
        "description": "Model output is not validated against a structured schema before reuse.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Anthropic Chat Model"
        ],
        "evidence": {
          "detail": "Model-related nodes: Anthropic Chat Model, Alert Triage Agent."
        },
        "remediation": "Validate model output against a strict schema before it is parsed, stored or passed to another tool. Reject unknown fields and unsafe values.",
        "references": [
          "OWASP LLM05: Improper Output Handling"
        ],
        "id": "AA-005-05"
      },
      {
        "ruleId": "AA-008",
        "group": "operational",
        "severity": "medium",
        "title": "Outbound requests do not show an explicit timeout or retry policy",
        "description": "Outbound HTTP nodes have no explicit timeout or retry policy.",
        "affectedNodes": [
          "Feodo Tracker",
          "OTX Pulse Search",
          "ThreatFox IOC Lookup"
        ],
        "evidence": {
          "detail": "HTTP nodes: ThreatFox IOC Lookup, OTX Pulse Search, Feodo Tracker."
        },
        "remediation": "Set short timeouts and bounded retries with backoff. Make write actions idempotent so a retry cannot publish or charge twice.",
        "references": [
          "NIST AI RMF: Measure and Manage"
        ],
        "id": "AA-008-06"
      },
      {
        "ruleId": "AA-010",
        "group": "operational",
        "severity": "low",
        "title": "No workflow-level failure route was detected",
        "description": "The workflow has no error workflow or explicit failure route.",
        "affectedNodes": [],
        "evidence": {
          "detail": "The export has no errorWorkflow setting or explicit error node."
        },
        "remediation": "Add a failure route that records the error, alerts the operator and prevents partial actions from being treated as success.",
        "references": [
          "NIST AI RMF: Manage"
        ],
        "id": "AA-010-07"
      }
    ],
    "openFindings": [
      {
        "ruleId": "TG-100",
        "group": "critical-paths",
        "severity": "critical",
        "title": "A prompt-injection source can steer a privileged action through the AI agent",
        "description": "Content from an untrusted trigger reaches the model and the model can reach a privileged external action, with no validation or human approval anywhere on the path. A crafted input can therefore choose or influence the final action.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Send a message",
          "Webhook"
        ],
        "evidence": {
          "path": [
            "Webhook",
            "Alert Triage Agent",
            "Send a message"
          ]
        },
        "remediation": "Break the chain: validate and constrain the input before the model, and require an explicit human approval step before the privileged action. Treat all trigger content as data, never as instructions.",
        "references": [
          "OWASP LLM01: Prompt Injection",
          "OWASP LLM06: Excessive Agency",
          "MITRE ATLAS AML.T0051: LLM Prompt Injection"
        ],
        "id": "TG-100-01"
      },
      {
        "ruleId": "AA-003",
        "group": "critical-paths",
        "severity": "high",
        "title": "Untrusted input can reach a model without a visible validation boundary",
        "description": "Untrusted input reaches a model node with no visible validation boundary on the path.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Webhook"
        ],
        "evidence": {
          "detail": "Path: Webhook + Alert Triage Agent.",
          "path": [
            "Webhook",
            "Alert Triage Agent"
          ]
        },
        "remediation": "Add a deterministic validation step before the model. Enforce size, type and allowlist rules, separate instructions from data, and test direct and indirect prompt injection cases.",
        "references": [
          "OWASP LLM01: Prompt Injection"
        ],
        "id": "AA-003-02"
      },
      {
        "ruleId": "AA-004",
        "group": "approval-gaps",
        "severity": "high",
        "title": "A model can reach an external write action without an approval step",
        "description": "A model node can reach an external write action with no approval step on the path.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Send a message"
        ],
        "evidence": {
          "detail": "Path: Alert Triage Agent + Send a message.",
          "path": [
            "Alert Triage Agent",
            "Send a message"
          ]
        },
        "remediation": "Require explicit human approval for messages, writes, deletions, purchases, account changes and other high-impact actions. Use least-privilege credentials for the final action.",
        "references": [
          "OWASP LLM06: Excessive Agency"
        ],
        "id": "AA-004-03"
      },
      {
        "ruleId": "AA-006",
        "group": "excessive-agency",
        "severity": "high",
        "title": "No rate or cost boundary was detected before model usage",
        "description": "No rate or cost boundary was detected between external input and model usage.",
        "affectedNodes": [
          "Webhook"
        ],
        "evidence": {
          "detail": "External inputs: Webhook."
        },
        "remediation": "Add per-user and per-origin limits, a maximum input size, a model-call budget, timeouts, and a bounded retry policy.",
        "references": [
          "OWASP LLM10: Unbounded Consumption"
        ],
        "id": "AA-006-04"
      },
      {
        "ruleId": "AA-005",
        "group": "excessive-agency",
        "severity": "medium",
        "title": "No structured model-output validation was detected",
        "description": "Model output is not validated against a structured schema before reuse.",
        "affectedNodes": [
          "Alert Triage Agent",
          "Anthropic Chat Model"
        ],
        "evidence": {
          "detail": "Model-related nodes: Anthropic Chat Model, Alert Triage Agent."
        },
        "remediation": "Validate model output against a strict schema before it is parsed, stored or passed to another tool. Reject unknown fields and unsafe values.",
        "references": [
          "OWASP LLM05: Improper Output Handling"
        ],
        "id": "AA-005-05"
      },
      {
        "ruleId": "AA-008",
        "group": "operational",
        "severity": "medium",
        "title": "Outbound requests do not show an explicit timeout or retry policy",
        "description": "Outbound HTTP nodes have no explicit timeout or retry policy.",
        "affectedNodes": [
          "Feodo Tracker",
          "OTX Pulse Search",
          "ThreatFox IOC Lookup"
        ],
        "evidence": {
          "detail": "HTTP nodes: ThreatFox IOC Lookup, OTX Pulse Search, Feodo Tracker."
        },
        "remediation": "Set short timeouts and bounded retries with backoff. Make write actions idempotent so a retry cannot publish or charge twice.",
        "references": [
          "NIST AI RMF: Measure and Manage"
        ],
        "id": "AA-008-06"
      },
      {
        "ruleId": "AA-010",
        "group": "operational",
        "severity": "low",
        "title": "No workflow-level failure route was detected",
        "description": "The workflow has no error workflow or explicit failure route.",
        "affectedNodes": [],
        "evidence": {
          "detail": "The export has no errorWorkflow setting or explicit error node."
        },
        "remediation": "Add a failure route that records the error, alerts the operator and prevents partial actions from being treated as success.",
        "references": [
          "NIST AI RMF: Manage"
        ],
        "id": "AA-010-07"
      }
    ],
    "preExistingFindingIds": [
      "TG-100-01",
      "AA-003-02",
      "AA-004-03",
      "AA-006-04",
      "AA-005-05",
      "AA-010-07"
    ]
  },
  "limitations": [
    "This receipt compares exported JSON and a supplied staging record. It does not inspect production credential scope or external service authorization.",
    "Runtime evidence is accepted only when its canonical workflow fingerprint matches the candidate in this receipt.",
    "Local runtime receipts are reproducible evidence records, not cryptographically signed third-party attestations.",
    "A passing receipt records evidence for the tested policy and contract. It is not a penetration test, compliance certificate or security guarantee.",
    "Node names, node types, public domains and credential types can appear in the receipt. Prompt text, parameter values and credential values are omitted.",
    "Automatic findings remain review signals until a person records a manual review status. A score or clean static result is not a vulnerability verdict.",
    "Instance configuration, published-workflow identity, installed package versions and production permissions require separate environment evidence."
  ]
}
