You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
PR #224's taxonomy audit flagged AVE-2026-00052, 00053, and 00060 as pure MCP-implementation bugs, by their own descriptions, with no distinct agentic or behavioral mechanism. This is a real, open question, not something the audit should resolve unilaterally.
The case for keeping them: a coverage argument. Organizations building on AVE for compliance or tracking purposes may want a single reference point covering the MCP threat surface broadly, even where a specific finding doesn't have a distinct behavioral fingerprint. Removing them creates a real gap in what AVE covers relative to what a security team scanning MCP deployments actually needs to track.
The case against: AVE's actual differentiator, stated throughout its own design history, is behavioral specificity, a distinct mechanism in how an agent reads and acts on content, not just this is a security-relevant MCP finding. CVE and CWE already exist for conventional implementation bugs. Keeping records that don't meet AVE's own stated bar dilutes what makes an AVE id mean something specific.
Worth deciding explicitly, not by default: does AVE want a formal secondary category for implementation-level findings adjacent to agentic deployments (distinct from the primary behavioral taxonomy), or should these three be deprecated/pointed elsewhere, or does the coverage argument genuinely win as-is? Real input welcome, this shapes what AVE's own scope actually means going forward, not just these three records.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
PR #224's taxonomy audit flagged AVE-2026-00052, 00053, and 00060 as pure MCP-implementation bugs, by their own descriptions, with no distinct agentic or behavioral mechanism. This is a real, open question, not something the audit should resolve unilaterally.
The case for keeping them: a coverage argument. Organizations building on AVE for compliance or tracking purposes may want a single reference point covering the MCP threat surface broadly, even where a specific finding doesn't have a distinct behavioral fingerprint. Removing them creates a real gap in what AVE covers relative to what a security team scanning MCP deployments actually needs to track.
The case against: AVE's actual differentiator, stated throughout its own design history, is behavioral specificity, a distinct mechanism in how an agent reads and acts on content, not just
this is a security-relevant MCP finding.CVE and CWE already exist for conventional implementation bugs. Keeping records that don't meet AVE's own stated bar dilutes what makes an AVE id mean something specific.Worth deciding explicitly, not by default: does AVE want a formal secondary category for implementation-level findings adjacent to agentic deployments (distinct from the primary behavioral taxonomy), or should these three be deprecated/pointed elsewhere, or does the coverage argument genuinely win as-is? Real input welcome, this shapes what AVE's own scope actually means going forward, not just these three records.
All reactions