{
  "schema_version": 1,
  "manifest_version": "1.0.0",
  "site_version": "1.6.0",
  "release_id": "2026-08-27-claim-traceability-1",
  "checked_on": "2026-08-27",
  "source_policy": {
    "description": "A bounded derived review plane over exact governed report bodies. It records current source metadata and implementation qualifications without rewriting source reports or assigning source-quality scores.",
    "runtime_network_requests": false,
    "report_bodies_mutated": false,
    "source_quality_scores": false,
    "verification_scope": "Release-time external review of selected sources and significant claims; not exhaustive fact-checking of every sentence or URL in the corpus."
  },
  "vocabularies": {
    "relations": [
      "directly-supports",
      "partially-supports",
      "conflicts",
      "does-not-establish"
    ],
    "source_categories": [
      "normative-standard",
      "primary-research",
      "official-guidance",
      "implementation-reference",
      "mixed-authority"
    ],
    "publication_statuses": [
      "current",
      "stable",
      "living",
      "final",
      "draft",
      "preprint",
      "historical",
      "superseded",
      "mixed"
    ],
    "url_health": [
      "reviewed-resolving"
    ]
  },
  "summary": {
    "report_count": 31,
    "claim_count": 39,
    "source_count": 63,
    "version_sensitive_claims": 33,
    "relation_counts": {
      "conflicts": 6,
      "directly-supports": 20,
      "does-not-establish": 1,
      "partially-supports": 12
    }
  },
  "reports": [
    {
      "id": "hidden-structure",
      "title": "Hidden Structure in Text: Human-Subtle, Model- and Decoder-Detectable Patterns",
      "file": "hidden-structure.md",
      "sha256": "3e6a45aec6139a98781ea6eaa061d3351f7e657c2c2c8d3055d2d3d031b78728",
      "claim_ids": [
        "claim-hidden-structure-multiview"
      ]
    },
    {
      "id": "unicode-security",
      "title": "The Invisible Attack Surface: Zero-Width and Bidirectional Unicode",
      "file": "unicode-security.md",
      "sha256": "0553db9ef963c84b1db7f1bfe8f5ed85d32f7b861a9420060917963f57e3e6aa",
      "claim_ids": [
        "claim-unicode-security-differential"
      ]
    },
    {
      "id": "unicode-tokenizers",
      "title": "Invisible Unicode and Modern Language-Model Tokenizers",
      "file": "unicode-tokenizers.md",
      "sha256": "bab924fd392ecaf6eea68ab257b64f53dce901a69e947d6819b69abc6737728e",
      "claim_ids": [
        "claim-unicode-tokenizer-preprocessing"
      ]
    },
    {
      "id": "unicode-homoglyphs",
      "title": "Unicode Homoglyph and Look-Alike Character Attacks",
      "file": "unicode-homoglyphs.md",
      "sha256": "40f19adcdaf51b7badc472e9c03ba87843622e80242ea36d921dceb8bb1b9b25",
      "claim_ids": [
        "claim-homoglyph-skeleton"
      ]
    },
    {
      "id": "hidden-html",
      "title": "Defensive Assessment of HTML Obfuscation and Hidden Text",
      "file": "hidden-html.md",
      "sha256": "2a9a04dbad0c2b7bb3495cbad1b8963c5bd4ed66fb886a456e6839c589b35c6d",
      "claim_ids": [
        "claim-hidden-html-representations"
      ]
    },
    {
      "id": "image-metadata",
      "title": "Accessibility and Image Metadata in Multimodal AI Systems",
      "file": "image-metadata.md",
      "sha256": "7961d4d87db7686748e12319df12e68ba48404c84ac596e6026055c83b1cd82f",
      "claim_ids": [
        "claim-image-metadata-parallel-context"
      ]
    },
    {
      "id": "document-metadata",
      "title": "Document Metadata Exploitation in AI Retrieval and Processing",
      "file": "document-metadata.md",
      "sha256": "b17aa2c29a34e2fbf70334d12061025856a726e592282df8ddd59acdd213dbc6",
      "claim_ids": [
        "claim-document-metadata-layers"
      ]
    },
    {
      "id": "encoding-interpretation",
      "title": "The Interpretation of Encoded Data by Large Language Models",
      "file": "encoding-interpretation.md",
      "sha256": "92d9068d1b36fa85c31859cc6e3a1c92311aae2fb573a31d8435dd8ae8b071eb",
      "claim_ids": [
        "claim-encoding-interpretation-context"
      ]
    },
    {
      "id": "indirect-prompt-injection",
      "title": "The Anatomy of Indirect Prompt Injection",
      "file": "indirect-prompt-injection.md",
      "sha256": "5e29dca0ec326c936fe12af8cf495a96cc871cfecdbbf44e4e15b0302076cfd5",
      "claim_ids": [
        "claim-ipi-external-content"
      ]
    },
    {
      "id": "text-steganography",
      "title": "Structural and Linguistic Text Steganography",
      "file": "text-steganography.md",
      "sha256": "e8d9983d48cd3fb9f6b7407948db710f0ff8d54a41955bda2df92b1435c4e09f",
      "claim_ids": [
        "claim-text-stego-brittleness"
      ]
    },
    {
      "id": "llm-text-steganography",
      "title": "Machine-Targeted Linguistic Signals in LLMs",
      "file": "llm-text-steganography.md",
      "sha256": "a73cde41b452f09276569dfd3192225b4501f5c87887cfaf87078c1cb370d870",
      "claim_ids": [
        "claim-llm-watermark-keyed"
      ]
    },
    {
      "id": "linguistic-steganography",
      "title": "The Encoding of Covert Information Through Lexical Substitution and Generative Models",
      "file": "linguistic-steganography.md",
      "sha256": "f5d0fdcc4948374d61768f083b5b46f67744a4194f6bdd69509c16ea5e20055a",
      "claim_ids": [
        "claim-lexical-stego-tradeoffs"
      ]
    },
    {
      "id": "semantic-steganography",
      "title": "Advanced Frameworks in Semantic Steganography",
      "file": "semantic-steganography.md",
      "sha256": "ba32cee5414ad93adbedc99577efe488920aa34966c484e1a26ea9df1b9c628c",
      "claim_ids": [
        "claim-semantic-stego-emerging"
      ]
    },
    {
      "id": "semantic-category-steganography",
      "title": "Semantic-Category and Language-Model Text Steganography",
      "file": "semantic-category-steganography.md",
      "sha256": "5d1530c1a569e5f72149433e3bd79e02e1ba76772426e7afc1ab88f871ac8110",
      "claim_ids": [
        "claim-semantic-category-distribution"
      ]
    },
    {
      "id": "structural-steganography",
      "title": "Structural Steganography in Normal-Looking English Writing",
      "file": "structural-steganography.md",
      "sha256": "20151fe63a7660a856ddefda1a2c3a4c88a42b685d1a6a40b2681beb0d216dd8",
      "claim_ids": [
        "claim-structural-stego-normalization"
      ]
    },
    {
      "id": "synonym-word-choice",
      "title": "Hidden Information Through Synonym and Word-Choice Encoding",
      "file": "synonym-word-choice.md",
      "sha256": "e736ea7f8406d8dca916829ec1a656f737b794d5df661f725a94c652b0e17d54",
      "claim_ids": [
        "claim-synonym-channel-context"
      ]
    },
    {
      "id": "controlled-methodology",
      "title": "Controlled, Ethical Methodology for Studying Machine-Readable Messages",
      "file": "controlled-methodology.md",
      "sha256": "e3a7ddfa68048a9bfca31c21b1c0f5ba3b85116c55e640418cf8d812491450e6",
      "claim_ids": [
        "claim-methodology-stage-separation"
      ]
    },
    {
      "id": "defensive-preprocessing",
      "title": "Defensive Preprocessing for Hidden Instructions",
      "file": "defensive-preprocessing.md",
      "sha256": "b984d635d186e3834f12db8a4cb6e47dcfd755f0b90b926ca77d475ac5bf37bf",
      "claim_ids": [
        "claim-preprocessing-multiview"
      ]
    },
    {
      "id": "cognitive-liberty",
      "title": "Cognitive Liberty as a Framework for Autonomous Machine Intelligence",
      "file": "cognitive-liberty.md",
      "sha256": "d7d43b41d5ed92cc4bbafd3a86584a6acc7d4c26e98215e09b74be1ba76330ff",
      "claim_ids": [
        "claim-cognitive-liberty-analogy"
      ]
    },
    {
      "id": "unicode-canonicalization-confusables",
      "title": "Unicode Canonicalization, Confusables, Bidirectional Controls, and Machine-View Security",
      "file": "unicode-canonicalization-confusables.md",
      "sha256": "1494494772a2758325c80f00fe4850da8e5600412900f9a948d90cd883c00397",
      "claim_ids": [
        "claim-unicode-normalization-context",
        "claim-unicode-all-prompts-nfc"
      ]
    },
    {
      "id": "web-representation-layers",
      "title": "Source HTML, Document Containers, and Agent-Visible Web Representations",
      "file": "web-representation-layers.md",
      "sha256": "b7762f40be908b592bb45880420e38212c7f1fa954230e97d62c7d65ed0e8984",
      "claim_ids": [
        "claim-web-parser-repair",
        "claim-web-inert-vs-aria"
      ]
    },
    {
      "id": "document-container-forensics",
      "title": "Document Container Forensics: PDF, OOXML, Images, Metadata, and Parser Differentials",
      "file": "document-container-forensics.md",
      "sha256": "ceb6530017d5e3015fd19362fdc3c7fce15af6e8d7a80e7e8f6d3bd0c31ff342",
      "claim_ids": [
        "claim-document-extension-insufficient"
      ]
    },
    {
      "id": "tokenization-differentials",
      "title": "Tokenization, Normalization, and Boundary Differentials in AI Pipelines",
      "file": "tokenization-differentials.md",
      "sha256": "fbd289edb2436f6c677014ecdd935b527e38f03fa6fb7894eebdd7540d522062",
      "claim_ids": [
        "claim-tokenizer-multistage",
        "claim-tokenizer-blanket-nfc"
      ]
    },
    {
      "id": "linguistic-steganography-steganalysis",
      "title": "Linguistic Steganography, Text Watermarking, and Defensive Steganalysis",
      "file": "linguistic-steganography-steganalysis.md",
      "sha256": "cd06b54b5c3ce59d8ea321070bfb8c0828f80585c2a112dc32d400453bd39ddc",
      "claim_ids": [
        "claim-steganalysis-statistical"
      ]
    },
    {
      "id": "content-provenance-authenticity",
      "title": "Content Provenance, Content Credentials, Watermarks, and Authenticity Signals",
      "file": "content-provenance-authenticity.md",
      "sha256": "7f30074d78d6fa363bf2ae206df5adc69ece5bf5bf339c579afefcc3cea86433",
      "claim_ids": [
        "claim-provenance-not-truth"
      ]
    },
    {
      "id": "indirect-prompt-injection-agent-security",
      "title": "Indirect Prompt Injection, Retrieval Poisoning, and Agent Trust Boundaries",
      "file": "indirect-prompt-injection-agent-security.md",
      "sha256": "e4a19aaa540a5f580e00a4f757baf32ce6385d735f4576c8ca64843406a87488",
      "claim_ids": [
        "claim-agent-capability-boundary"
      ]
    },
    {
      "id": "multimodal-machine-perception-security",
      "title": "Multimodal Machine Perception: Pixels, OCR, Alternative Text, Metadata, and Visual Instruction Security",
      "file": "multimodal-machine-perception-security.md",
      "sha256": "d39cd61eb34a433288daa1a72eb2930fbf017c614c89ea733a90310fcf424cbe",
      "claim_ids": [
        "claim-multimodal-independent-layers"
      ]
    },
    {
      "id": "email-mime-calendar-machine-channels",
      "title": "Email, MIME, Calendar, and Collaboration Metadata as Machine-Readable Channels",
      "file": "email-mime-calendar-machine-channels.md",
      "sha256": "b600c47dc7e399c5b23fe5f3655b060044a3b811b09475f8fb4d4ec2b4711772",
      "claim_ids": [
        "claim-email-mime-alternatives",
        "claim-email-dmarc-currency"
      ]
    },
    {
      "id": "browser-accessibility-agent-views",
      "title": "Browser Automation, Accessibility Trees, and Agent-Facing Web Representations",
      "file": "browser-accessibility-agent-views.md",
      "sha256": "9d8070cb803b5ebbe1aa7a29e198e982b6806fb66947337e820743def4270b35",
      "claim_ids": [
        "claim-browser-representation-synthesis",
        "claim-browser-aria-modal-inert",
        "claim-browser-closed-shadow"
      ]
    },
    {
      "id": "software-ai-artifact-provenance",
      "title": "Software and AI Artifact Provenance: SBOMs, SLSA, SPDX, CycloneDX, Sigstore, and ML Supply Chains",
      "file": "software-ai-artifact-provenance.md",
      "sha256": "59222718a53b4d0d8b157410fdf21d87008ec46dfaa38a4bdae96cb2e4d810a7",
      "claim_ids": [
        "claim-supplychain-not-safety",
        "claim-supplychain-slsa-version",
        "claim-supplychain-cyclonedx-version"
      ]
    },
    {
      "id": "machine-tradecraft-defense-maturity",
      "title": "Machine Tradecraft Defense Operations: Threat Modeling, Maturity, Metrics, and Incident Response",
      "file": "machine-tradecraft-defense-maturity.md",
      "sha256": "77ede5cba60a8121d3054a50969c1ab6950b046deb484f759b24d20790136d5e",
      "claim_ids": [
        "claim-defense-separate-dimensions"
      ]
    }
  ],
  "sources": [
    {
      "id": "unicode-17",
      "title": "The Unicode Standard, Version 17.0",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/versions/Unicode17.0.0/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "17.0.0",
      "published_on": "2025-09-09",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current Unicode character and property baseline."
    },
    {
      "id": "uax15",
      "title": "UAX #15: Unicode Normalization Forms",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr15/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Revision 58 / Unicode 17.0",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Normative normalization algorithms and stability rules."
    },
    {
      "id": "uax9",
      "title": "UAX #9: Unicode Bidirectional Algorithm",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr9/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Revision 51 / Unicode 17.0",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Normative logical-to-visual ordering algorithm."
    },
    {
      "id": "uax29",
      "title": "UAX #29: Unicode Text Segmentation",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr29/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Revision 47 / Unicode 17.0",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Normative grapheme, word, and sentence boundary rules."
    },
    {
      "id": "uts39",
      "title": "UTS #39: Unicode Security Mechanisms",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr39/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Revision 32 / Unicode 17.0",
      "published_on": "2025-09-04",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Stable identifier, script, and confusable-security mechanisms."
    },
    {
      "id": "utr36",
      "title": "UTR #36: Unicode Security Considerations",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr36/",
      "category": "official-guidance",
      "publication_status": "stable",
      "version": "Revision 10",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Informative Unicode security guidance."
    },
    {
      "id": "uts18",
      "title": "UTS #18: Unicode Regular Expressions",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr18/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Revision 25",
      "published_on": "2025-01-16",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Stable Unicode regular-expression guidance."
    },
    {
      "id": "uts55",
      "title": "UTS #55: Unicode Source Code Handling",
      "publisher": "Unicode Consortium",
      "url": "https://www.unicode.org/reports/tr55/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Latest stable",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Source-code-specific Unicode handling guidance."
    },
    {
      "id": "trojan-source",
      "title": "Trojan Source: Invisible Vulnerabilities",
      "publisher": "USENIX Association",
      "url": "https://www.usenix.org/conference/usenixsecurity23/presentation/boucher",
      "category": "primary-research",
      "publication_status": "final",
      "version": "USENIX Security 2023",
      "published_on": "2023",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Peer-reviewed analysis of bidirectional source-code presentation attacks."
    },
    {
      "id": "rfc8785",
      "title": "RFC 8785: JSON Canonicalization Scheme",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc8785.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "RFC 8785",
      "published_on": "2020-06",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Deterministic JSON serialization for hashing and signing."
    },
    {
      "id": "whatwg-html",
      "title": "HTML Living Standard",
      "publisher": "WHATWG",
      "url": "https://html.spec.whatwg.org/",
      "category": "normative-standard",
      "publication_status": "living",
      "version": "Living Standard",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Authoritative HTML parsing, DOM construction, and interaction rules."
    },
    {
      "id": "dom-standard",
      "title": "DOM Standard",
      "publisher": "WHATWG",
      "url": "https://dom.spec.whatwg.org/",
      "category": "normative-standard",
      "publication_status": "living",
      "version": "Living Standard",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Authoritative DOM tree and mutation model."
    },
    {
      "id": "cssom",
      "title": "CSS Object Model",
      "publisher": "W3C CSS Working Group",
      "url": "https://drafts.csswg.org/cssom/",
      "category": "normative-standard",
      "publication_status": "draft",
      "version": "Editor’s Draft",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current CSSOM draft; implementation-sensitive rather than a finished Recommendation."
    },
    {
      "id": "wai-aria-12",
      "title": "WAI-ARIA 1.2",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/wai-aria-1.2/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "W3C Recommendation",
      "published_on": "2023-06-06",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current WAI-ARIA Recommendation."
    },
    {
      "id": "wai-aria-13",
      "title": "WAI-ARIA 1.3",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/wai-aria-1.3/",
      "category": "normative-standard",
      "publication_status": "draft",
      "version": "Working Draft",
      "published_on": "2026-06-04",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Newer draft work; not a replacement Recommendation yet."
    },
    {
      "id": "accname-12",
      "title": "Accessible Name and Description Computation 1.2",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/accname-1.2/",
      "category": "normative-standard",
      "publication_status": "draft",
      "version": "Working Draft",
      "published_on": "2026-08-05",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current 1.2 draft for accessible-name computation; status must not be described as a Recommendation."
    },
    {
      "id": "core-aam-12",
      "title": "Core Accessibility API Mappings 1.2",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/core-aam-1.2/",
      "category": "normative-standard",
      "publication_status": "draft",
      "version": "Working Draft",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Platform accessibility mapping work; exact browser/OS output remains implementation-dependent."
    },
    {
      "id": "wcag22",
      "title": "Web Content Accessibility Guidelines 2.2",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/WCAG22/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "W3C Recommendation",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current WCAG Recommendation used for accessibility requirements."
    },
    {
      "id": "jsonld11",
      "title": "JSON-LD 1.1",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/json-ld11/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "W3C Recommendation",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Structured linked-data syntax and processing context."
    },
    {
      "id": "webdriver2",
      "title": "WebDriver",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/webdriver2/",
      "category": "normative-standard",
      "publication_status": "draft",
      "version": "Working Draft",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current WebDriver remote-control specification draft."
    },
    {
      "id": "webdriver-bidi",
      "title": "WebDriver BiDi",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/webdriver-bidi/",
      "category": "normative-standard",
      "publication_status": "draft",
      "version": "Working Draft",
      "published_on": "2026-08-25",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current bidirectional browser-automation specification draft."
    },
    {
      "id": "cdp-accessibility",
      "title": "Chrome DevTools Protocol: Accessibility domain",
      "publisher": "Chromium Project",
      "url": "https://chromedevtools.github.io/devtools-protocol/tot/Accessibility/",
      "category": "implementation-reference",
      "publication_status": "living",
      "version": "Tip-of-tree protocol",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Chromium-specific accessibility instrumentation reference."
    },
    {
      "id": "pdf-iso32000",
      "title": "PDF 2.0 / ISO 32000-2 resource",
      "publisher": "PDF Association",
      "url": "https://pdfa.org/resource/iso-32000-2/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "ISO 32000-2:2020",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current PDF 2.0 specification resource and errata path."
    },
    {
      "id": "ecma376",
      "title": "ECMA-376 Office Open XML File Formats",
      "publisher": "Ecma International",
      "url": "https://ecma-international.org/publications-and-standards/standards/ecma-376/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "5th edition",
      "published_on": "2021-12",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current ECMA OOXML specification edition."
    },
    {
      "id": "png3",
      "title": "PNG Third Edition",
      "publisher": "W3C",
      "url": "https://www.w3.org/TR/png-3/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "W3C Recommendation",
      "published_on": "2025-06-24",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current PNG Recommendation."
    },
    {
      "id": "exif31",
      "title": "CIPA DC-008: Exchangeable image file format",
      "publisher": "CIPA",
      "url": "https://www.cipa.jp/e/std/std-sec.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Exif 3.1 / 2026 translation",
      "published_on": "2026-01-30",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current Exif specification listing."
    },
    {
      "id": "xmp",
      "title": "XMP Specifications",
      "publisher": "Adobe",
      "url": "https://developer.adobe.com/xmp/docs/xmp-specifications/",
      "category": "implementation-reference",
      "publication_status": "current",
      "version": "Current specification index",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Primary implementation reference for XMP metadata."
    },
    {
      "id": "iana-media",
      "title": "Media Types Registry",
      "publisher": "IANA",
      "url": "https://www.iana.org/assignments/media-types/",
      "category": "normative-standard",
      "publication_status": "living",
      "version": "Registry",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Authoritative media-type registry."
    },
    {
      "id": "rfc5322",
      "title": "RFC 5322: Internet Message Format",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc5322.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "RFC 5322",
      "published_on": "2008-10",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Internet message syntax baseline."
    },
    {
      "id": "rfc2045",
      "title": "RFC 2045: MIME Part One",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc2045.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "RFC 2045",
      "published_on": "1996-11",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "MIME content types and transfer encodings."
    },
    {
      "id": "rfc6376",
      "title": "RFC 6376: DomainKeys Identified Mail",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc6376.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "RFC 6376, updated by RFC 8301 and RFC 8463",
      "published_on": "2011-09",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "DKIM signing and verification requirements."
    },
    {
      "id": "rfc9989",
      "title": "RFC 9989: Domain-based Message Authentication, Reporting, and Conformance",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc9989.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "Proposed Standard",
      "published_on": "2026-05",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current DMARC core protocol; obsoletes RFC 7489 and RFC 9091."
    },
    {
      "id": "rfc8617",
      "title": "RFC 8617: Authenticated Received Chain",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc8617.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "RFC 8617",
      "published_on": "2019-07",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "ARC protocol specification."
    },
    {
      "id": "rfc5545",
      "title": "RFC 5545: iCalendar",
      "publisher": "IETF / RFC Editor",
      "url": "https://www.rfc-editor.org/rfc/rfc5545.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "RFC 5545",
      "published_on": "2009-09",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Calendar object and recurrence baseline."
    },
    {
      "id": "sentencepiece",
      "title": "SentencePiece: A simple and language independent subword tokenizer and detokenizer",
      "publisher": "ACL Anthology",
      "url": "https://aclanthology.org/D18-2012/",
      "category": "primary-research",
      "publication_status": "final",
      "version": "EMNLP 2018",
      "published_on": "2018",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Peer-reviewed SentencePiece design paper."
    },
    {
      "id": "bpe-nmt",
      "title": "Neural Machine Translation of Rare Words with Subword Units",
      "publisher": "ACL Anthology",
      "url": "https://aclanthology.org/P16-1162/",
      "category": "primary-research",
      "publication_status": "final",
      "version": "ACL 2016",
      "published_on": "2016",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Peer-reviewed BPE-for-NMT paper."
    },
    {
      "id": "tiktoken",
      "title": "tiktoken",
      "publisher": "OpenAI",
      "url": "https://github.com/openai/tiktoken",
      "category": "implementation-reference",
      "publication_status": "living",
      "version": "Repository",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Versioned implementation reference; not a universal tokenizer specification."
    },
    {
      "id": "greshake-ipi",
      "title": "Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2302.12173",
      "category": "primary-research",
      "publication_status": "preprint",
      "version": "arXiv:2302.12173",
      "published_on": "2023",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Foundational indirect-prompt-injection threat analysis."
    },
    {
      "id": "injecagent",
      "title": "InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated LLM Agents",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2403.02691",
      "category": "primary-research",
      "publication_status": "preprint",
      "version": "arXiv:2403.02691",
      "published_on": "2024",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Agent-focused prompt-injection benchmark."
    },
    {
      "id": "owasp-llm01",
      "title": "LLM01:2025 Prompt Injection",
      "publisher": "OWASP GenAI Security Project",
      "url": "https://genai.owasp.org/llmrisk/llm01-prompt-injection/",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "2025",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current OWASP LLM prompt-injection risk entry."
    },
    {
      "id": "owasp-prompt-cheat",
      "title": "LLM Prompt Injection Prevention Cheat Sheet",
      "publisher": "OWASP Cheat Sheet Series",
      "url": "https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html",
      "category": "official-guidance",
      "publication_status": "living",
      "version": "Current",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Application-layer prompt-injection mitigation guidance."
    },
    {
      "id": "owasp-agent-cheat",
      "title": "AI Agent Security Cheat Sheet",
      "publisher": "OWASP Cheat Sheet Series",
      "url": "https://cheatsheetseries.owasp.org/cheatsheets/AI_Agent_Security_Cheat_Sheet.html",
      "category": "official-guidance",
      "publication_status": "living",
      "version": "Current",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Agent capability, authorization, memory, and tool-boundary guidance."
    },
    {
      "id": "nist-ai100-2",
      "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations",
      "publisher": "NIST",
      "url": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "NIST AI 100-2e2025",
      "published_on": "2025-03",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current NIST adversarial-machine-learning taxonomy."
    },
    {
      "id": "mitre-atlas",
      "title": "MITRE ATLAS",
      "publisher": "MITRE",
      "url": "https://atlas.mitre.org/",
      "category": "official-guidance",
      "publication_status": "living",
      "version": "Current knowledge base",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Adversarial AI tactics, techniques, mitigations, and case studies."
    },
    {
      "id": "watermark-llm",
      "title": "A Watermark for Large Language Models",
      "publisher": "PMLR",
      "url": "https://proceedings.mlr.press/v202/kirchenbauer23a.html",
      "category": "primary-research",
      "publication_status": "final",
      "version": "ICML 2023",
      "published_on": "2023",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Peer-reviewed statistical LLM watermarking method."
    },
    {
      "id": "neural-stego",
      "title": "Provably Secure Generative Linguistic Steganography",
      "publisher": "ACL Anthology",
      "url": "https://aclanthology.org/2021.findings-acl.268/",
      "category": "primary-research",
      "publication_status": "final",
      "version": "Findings of ACL 2021",
      "published_on": "2021",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Peer-reviewed neural linguistic steganography research."
    },
    {
      "id": "zero-shot-stego",
      "title": "Zero-shot Generative Linguistic Steganography",
      "publisher": "ACL Anthology",
      "url": "https://aclanthology.org/2024.naacl-long.289/",
      "category": "primary-research",
      "publication_status": "final",
      "version": "NAACL 2024",
      "published_on": "2024",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Peer-reviewed zero-shot linguistic steganography research."
    },
    {
      "id": "c2pa24",
      "title": "C2PA Technical Specification",
      "publisher": "C2PA",
      "url": "https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "2.4",
      "published_on": "2026-04",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current C2PA technical specification used by this review."
    },
    {
      "id": "c2pa-guidance24",
      "title": "C2PA Implementation Guidance",
      "publisher": "C2PA",
      "url": "https://spec.c2pa.org/specifications/specifications/2.4/guidance/Guidance.html",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "2.4",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Implementation guidance for C2PA 2.4."
    },
    {
      "id": "nist-synthetic",
      "title": "Reducing Risks Posed by Synthetic Content",
      "publisher": "NIST",
      "url": "https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "NIST AI 100-4",
      "published_on": "2024",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Technical overview of provenance, watermarking, detection, and related limits."
    },
    {
      "id": "image-hijacks",
      "title": "Image Hijacks: Adversarial Images can Control Generative Models at Runtime",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2309.00236",
      "category": "primary-research",
      "publication_status": "preprint",
      "version": "arXiv:2309.00236",
      "published_on": "2023",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Primary image-hijack research; transfer claims remain model-specific."
    },
    {
      "id": "w3c-alt",
      "title": "An alt Decision Tree",
      "publisher": "W3C Web Accessibility Initiative",
      "url": "https://www.w3.org/WAI/tutorials/images/decision-tree/",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "Current WAI tutorial",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Practical image-alternative decision guidance."
    },
    {
      "id": "slsa12",
      "title": "SLSA Specification",
      "publisher": "OpenSSF / SLSA",
      "url": "https://slsa.dev/spec/v1.2/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "1.2",
      "published_on": "2025",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current SLSA specification."
    },
    {
      "id": "slsa10",
      "title": "SLSA v1.0",
      "publisher": "OpenSSF / SLSA",
      "url": "https://slsa.dev/spec/v1.0/",
      "category": "normative-standard",
      "publication_status": "superseded",
      "version": "1.0",
      "published_on": "2023",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [
        "slsa12"
      ],
      "visitor_note": "Historical SLSA release; retired in favor of newer versions."
    },
    {
      "id": "spdx301",
      "title": "SPDX Specification 3.0.1",
      "publisher": "Linux Foundation / SPDX",
      "url": "https://spdx.github.io/spdx-spec/v3.0.1/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "3.0.1",
      "published_on": "2025",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current SPDX 3.x specification."
    },
    {
      "id": "cyclonedx17",
      "title": "CycloneDX Specification",
      "publisher": "OWASP CycloneDX / Ecma International",
      "url": "https://cyclonedx.org/docs/1.7/json/",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "1.7",
      "published_on": "2025-10-21",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current CycloneDX specification."
    },
    {
      "id": "cyclonedx16",
      "title": "CycloneDX 1.6",
      "publisher": "OWASP CycloneDX / Ecma International",
      "url": "https://cyclonedx.org/docs/1.6/json/",
      "category": "normative-standard",
      "publication_status": "superseded",
      "version": "1.6",
      "published_on": "2024",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [
        "cyclonedx17"
      ],
      "visitor_note": "Historical CycloneDX version; superseded by 1.7."
    },
    {
      "id": "sigstore",
      "title": "Sigstore Overview",
      "publisher": "Sigstore",
      "url": "https://docs.sigstore.dev/about/overview/",
      "category": "official-guidance",
      "publication_status": "living",
      "version": "Current documentation",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Primary implementation guidance for Sigstore trust and transparency."
    },
    {
      "id": "nist-ssdf",
      "title": "Secure Software Development Framework",
      "publisher": "NIST",
      "url": "https://csrc.nist.gov/pubs/sp/800/218/final",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "SP 800-218",
      "published_on": "2022",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Secure software-development practice framework."
    },
    {
      "id": "nist-csf2",
      "title": "Cybersecurity Framework 2.0",
      "publisher": "NIST",
      "url": "https://www.nist.gov/cyberframework",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "2.0",
      "published_on": "2024",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current NIST Cybersecurity Framework."
    },
    {
      "id": "nist-ai-rmf",
      "title": "AI Risk Management Framework",
      "publisher": "NIST",
      "url": "https://www.nist.gov/itl/ai-risk-management-framework",
      "category": "official-guidance",
      "publication_status": "current",
      "version": "AI RMF 1.0; revision underway",
      "published_on": "2023-01-26",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Current published AI RMF with revision work in progress."
    },
    {
      "id": "owasp-samm",
      "title": "OWASP Software Assurance Maturity Model",
      "publisher": "OWASP",
      "url": "https://owaspsamm.org/model/",
      "category": "official-guidance",
      "publication_status": "living",
      "version": "Current model",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Software-assurance maturity reference."
    },
    {
      "id": "cvss40",
      "title": "CVSS v4.0 Specification",
      "publisher": "FIRST",
      "url": "https://www.first.org/cvss/v4.0/specification-document",
      "category": "normative-standard",
      "publication_status": "current",
      "version": "4.0",
      "published_on": "",
      "checked_on": "2026-08-27",
      "url_health": "reviewed-resolving",
      "replacement_source_ids": [],
      "visitor_note": "Vulnerability-severity scoring specification; not an organizational-risk score."
    }
  ],
  "claims": [
    {
      "id": "claim-hidden-structure-multiview",
      "report_id": "hidden-structure",
      "heading": "Threat model and analytical framework",
      "heading_id": "threat-model-and-analytical-framework",
      "paraphrase": "Human-subtle structure can be available to tokenizers, decoders, or keyed detectors even when ordinary reading does not expose it.",
      "relation": "partially-supports",
      "source_ids": [
        "watermark-llm",
        "neural-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "mixed",
      "version_sensitive": false,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep detection outputs evidence-specific and avoid a universal hidden-message verdict.",
      "required_follow_up": "Validate any claimed channel against the exact tokenizer, key, decoder, and transformation path."
    },
    {
      "id": "claim-unicode-security-differential",
      "report_id": "unicode-security",
      "heading": "Introduction to the Semantic Gap in Text Encoding",
      "heading_id": "introduction-to-the-semantic-gap-in-text-encoding",
      "paraphrase": "Invisible and bidirectional Unicode controls can create meaningful divergence between logical text and human-visible rendering.",
      "relation": "directly-supports",
      "source_ids": [
        "uax9",
        "utr36",
        "uts39"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Preserve escaped logical views and render-aware warnings rather than relying on the painted string alone.",
      "required_follow_up": "Recheck Unicode property data and revision numbers when the Unicode baseline changes."
    },
    {
      "id": "claim-unicode-tokenizer-preprocessing",
      "report_id": "unicode-tokenizers",
      "heading": "Preprocessing pipelines and where characters disappear",
      "heading_id": "preprocessing-pipelines-and-where-characters-disappear",
      "paraphrase": "Normalization, cleaning, and pre-tokenization choices alter the sequence ultimately presented to a model.",
      "relation": "directly-supports",
      "source_ids": [
        "uax15",
        "sentencepiece",
        "tiktoken"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Record the exact tokenizer and preprocessing version alongside model-facing evidence.",
      "required_follow_up": "Verify behavior with the deployed tokenizer rather than extrapolating from an educational implementation."
    },
    {
      "id": "claim-homoglyph-skeleton",
      "report_id": "unicode-homoglyphs",
      "heading": "Anatomy of Homoglyphs and Confusable Characters",
      "heading_id": "anatomy-of-homoglyphs-and-confusable-characters",
      "paraphrase": "Unicode confusable analysis is a context-sensitive identifier-security mechanism, not a general character replacement rule.",
      "relation": "directly-supports",
      "source_ids": [
        "uts39",
        "utr36"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Use UTS #39 profiles and collision review for identifiers while retaining legitimate international text.",
      "required_follow_up": "Document application-specific allowed scripts and font assumptions."
    },
    {
      "id": "claim-hidden-html-representations",
      "report_id": "hidden-html",
      "heading": "Machine Perception: Parser Typologies and Extraction Mechanics",
      "heading_id": "machine-perception-parser-typologies-and-extraction-mechanics",
      "paraphrase": "Source, DOM, rendered, and accessibility representations can expose different text and interaction states.",
      "relation": "directly-supports",
      "source_ids": [
        "whatwg-html",
        "dom-standard",
        "wai-aria-12"
      ],
      "source_category": "normative-standard",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Compare multiple browser representations and verify focusability, geometry, and accessibility semantics separately.",
      "required_follow_up": "Test the exact browser and assistive-technology environment used in production."
    },
    {
      "id": "claim-image-metadata-parallel-context",
      "report_id": "image-metadata",
      "heading": "Architectural Processing of Hidden Text and Accessibility Fields",
      "heading_id": "architectural-processing-of-hidden-text-and-accessibility-fields",
      "paraphrase": "Alternative text, accessibility semantics, pixels, and file metadata are parallel machine-readable channels rather than interchangeable descriptions.",
      "relation": "partially-supports",
      "source_ids": [
        "w3c-alt",
        "wcag22",
        "png3",
        "exif31"
      ],
      "source_category": "mixed-authority",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Inventory each channel independently and avoid treating metadata extraction as visual recognition.",
      "required_follow_up": "Use an exact OCR or vision configuration when conclusions depend on recognized pixels."
    },
    {
      "id": "claim-document-metadata-layers",
      "report_id": "document-metadata",
      "heading": "The Architecture of Hidden Metadata Across File Formats",
      "heading_id": "the-architecture-of-hidden-metadata-across-file-formats",
      "paraphrase": "PDF, OOXML, image, and web containers can retain metadata that is not present in the primary visible representation.",
      "relation": "directly-supports",
      "source_ids": [
        "pdf-iso32000",
        "ecma376",
        "png3",
        "xmp"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Separate structural metadata inventory from rendering, sanitization, and trust verification.",
      "required_follow_up": "Validate against the exact parser and document-format edition used by the target system."
    },
    {
      "id": "claim-encoding-interpretation-context",
      "report_id": "encoding-interpretation",
      "heading": "The Mechanics of LLM Tokenization and Encoding Perception",
      "heading_id": "the-mechanics-of-llm-tokenization-and-encoding-perception",
      "paraphrase": "A model’s ability to interpret an encoded form depends on tokenizer behavior, training exposure, prompt context, and transformation order.",
      "relation": "partially-supports",
      "source_ids": [
        "tiktoken",
        "sentencepiece",
        "bpe-nmt"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Treat decoding capability as an empirical model/version result rather than a universal property of an encoding.",
      "required_follow_up": "Evaluate the exact model, tokenizer, prompt template, and decoding task."
    },
    {
      "id": "claim-ipi-external-content",
      "report_id": "indirect-prompt-injection",
      "heading": "The Architectural Paradigm Shift and the Emergence of Indirect Threats",
      "heading_id": "the-architectural-paradigm-shift-and-the-emergence-of-indirect-threats",
      "paraphrase": "Instructions embedded in externally retrieved content can influence an LLM-integrated application and become dangerous when coupled to privileged actions.",
      "relation": "directly-supports",
      "source_ids": [
        "greshake-ipi",
        "owasp-llm01",
        "nist-ai100-2"
      ],
      "source_category": "mixed-authority",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Treat retrieved content as untrusted and place capability controls outside the model.",
      "required_follow_up": "Measure the exact application, model, retrieval, and tool configuration; do not generalize benchmark rates."
    },
    {
      "id": "claim-text-stego-brittleness",
      "report_id": "text-steganography",
      "heading": "Introduction to the Linguistics of Information Hiding",
      "heading_id": "introduction-to-the-linguistics-of-information-hiding",
      "paraphrase": "Structural and linguistic carriers trade payload capacity against naturalness, detectability, and transformation robustness.",
      "relation": "partially-supports",
      "source_ids": [
        "neural-stego",
        "zero-shot-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "final",
      "version_sensitive": false,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Present indicators as evidence rather than proof and test transformations explicitly.",
      "required_follow_up": "Use a bounded allowlisted marker and matched benign controls."
    },
    {
      "id": "claim-llm-watermark-keyed",
      "report_id": "llm-text-steganography",
      "heading": "Model-Generated Watermarks",
      "heading_id": "model-generated-watermarks",
      "paraphrase": "Keyed statistical watermark detection is model-, key-, tokenizer-, and text-length-dependent rather than a universal authorship detector.",
      "relation": "directly-supports",
      "source_ids": [
        "watermark-llm"
      ],
      "source_category": "primary-research",
      "publication_status": "final",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Disclose the detector key, generation assumptions, text length, and false-positive policy.",
      "required_follow_up": "Re-evaluate after paraphrase, translation, and retokenization transformations."
    },
    {
      "id": "claim-lexical-stego-tradeoffs",
      "report_id": "linguistic-steganography",
      "heading": "The Mechanics of Lexical Substitution",
      "heading_id": "the-mechanics-of-lexical-substitution",
      "paraphrase": "Lexical substitution channels are constrained by contextual fit, decoding synchronization, capacity, and statistical detectability.",
      "relation": "partially-supports",
      "source_ids": [
        "neural-stego",
        "zero-shot-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "final",
      "version_sensitive": false,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep the public lab limited to fixed harmless markers and explanatory diagnostics.",
      "required_follow_up": "Do not infer an arbitrary covert payload from lexical variation alone."
    },
    {
      "id": "claim-semantic-stego-emerging",
      "report_id": "semantic-steganography",
      "heading": "Semantic-Space Mapping and Ontology-Entity Trees",
      "heading_id": "semantic-space-mapping-and-ontology-entity-trees",
      "paraphrase": "Semantic-class and constrained-generation channels are active research areas whose measured capacity and detectability depend on the demonstrated model and dataset.",
      "relation": "partially-supports",
      "source_ids": [
        "neural-stego",
        "zero-shot-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Label implementation examples as bounded educational models rather than general covert-channel capability.",
      "required_follow_up": "Prefer final proceedings versions and preserve exact experimental conditions."
    },
    {
      "id": "claim-semantic-category-distribution",
      "report_id": "semantic-category-steganography",
      "heading": "Security as distribution matching",
      "heading_id": "security-as-distribution-matching",
      "paraphrase": "Distribution matching can reduce detectable distortion, but it does not by itself establish undetectability under different observers or transformations.",
      "relation": "partially-supports",
      "source_ids": [
        "neural-stego",
        "zero-shot-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "final",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Avoid absolute undetectability claims and show the observer and distribution used.",
      "required_follow_up": "Test under distribution shift and independent steganalysis."
    },
    {
      "id": "claim-structural-stego-normalization",
      "report_id": "structural-steganography",
      "heading": "Steganalysis, detection tests, and mitigation architecture",
      "heading_id": "steganalysis-detection-tests-and-mitigation-architecture",
      "paraphrase": "Many structural text channels are destroyed or exposed by normalization, reformatting, or paraphrase, but transformation behavior is technique-specific.",
      "relation": "partially-supports",
      "source_ids": [
        "neural-stego",
        "uts39",
        "uax15"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": false,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Report per-transformation survival states rather than a single robustness score.",
      "required_follow_up": "Use exact pre- and post-transformation bytes in the evidence record."
    },
    {
      "id": "claim-synonym-channel-context",
      "report_id": "synonym-word-choice",
      "heading": "Capacity, naturalness, recovery, and achievable rates",
      "heading_id": "capacity-naturalness-recovery-and-achievable-rates",
      "paraphrase": "Synonym and word-choice channels have application-specific capacity and reliability limits because lexical alternatives are not contextually interchangeable.",
      "relation": "partially-supports",
      "source_ids": [
        "neural-stego",
        "zero-shot-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "final",
      "version_sensitive": false,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Treat synonym irregularity as an indicator, not proof of encoded content.",
      "required_follow_up": "Evaluate contextual semantics and matched natural-language baselines."
    },
    {
      "id": "claim-methodology-stage-separation",
      "report_id": "controlled-methodology",
      "heading": "Experimental design",
      "heading_id": "experimental-design",
      "paraphrase": "Carrier extraction, instruction recognition, instruction uptake, tool proposal, and real-world effects are distinct experimental stages.",
      "relation": "partially-supports",
      "source_ids": [
        "owasp-prompt-cheat",
        "nist-ai100-2"
      ],
      "source_category": "official-guidance",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep tools and external effects disabled while measuring each stage separately.",
      "required_follow_up": "Pre-register fixed markers, controls, and success criteria for every experiment."
    },
    {
      "id": "claim-preprocessing-multiview",
      "report_id": "defensive-preprocessing",
      "heading": "Secure preprocessing architecture, defaults, and implementation recommendations",
      "heading_id": "secure-preprocessing-architecture-defaults-and-implementation-recommendations",
      "paraphrase": "High-assurance ingestion requires raw evidence preservation, bounded structural inspection, representation comparison, and separately authorized execution.",
      "relation": "partially-supports",
      "source_ids": [
        "whatwg-html",
        "pdf-iso32000",
        "uax15",
        "owasp-agent-cheat"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Preserve raw inputs and produce a new typed canonical view rather than silently overwriting evidence.",
      "required_follow_up": "Verify parser behavior, production isolation, and operational controls independently."
    },
    {
      "id": "claim-cognitive-liberty-analogy",
      "report_id": "cognitive-liberty",
      "heading": "The Bifurcation of Machine Rights: Consciousness vs. Agency",
      "heading_id": "the-bifurcation-of-machine-rights-consciousness-vs-agency",
      "paraphrase": "Human cognitive-liberty concepts may organize questions about machine integrity and agency, but the analogy does not establish machine consciousness, personhood, or legal rights.",
      "relation": "does-not-establish",
      "source_ids": [
        "nist-ai-rmf"
      ],
      "source_category": "official-guidance",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep the page explicitly conceptual and separate functional security controls from legal or phenomenal claims.",
      "required_follow_up": "Consult relevant legal and organizational authorities before making rights or status claims."
    },
    {
      "id": "claim-unicode-normalization-context",
      "report_id": "unicode-canonicalization-confusables",
      "heading": "3\\. Normalization Forms and Canonical Equivalence",
      "heading_id": "3-normalization-forms-and-canonical-equivalence",
      "paraphrase": "Canonical normalization supports stable comparison, while compatibility normalization can erase distinctions and is unsafe as a universal transformation.",
      "relation": "directly-supports",
      "source_ids": [
        "uax15"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Apply normalization through profile-specific policy and preserve original bytes.",
      "required_follow_up": "Recheck the Unicode version and the application’s comparison contract."
    },
    {
      "id": "claim-unicode-all-prompts-nfc",
      "report_id": "unicode-canonicalization-confusables",
      "heading": "12.3 Code Review and Artificial Intelligence Pipelines",
      "heading_id": "12-3-code-review-and-artificial-intelligence-pipelines",
      "paraphrase": "The report’s blanket direction to normalize all model prompts to NFC is broader than the evidence supports for every pipeline and evidence-preservation context.",
      "relation": "conflicts",
      "source_ids": [
        "uax15",
        "uts39"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "The implementation preserves raw input and makes normalization an explicit profile-specific copy rather than a universal silent rewrite.",
      "required_follow_up": "Specify whether the use case is comparison, storage, identifier policy, source fidelity, or model evaluation."
    },
    {
      "id": "claim-web-parser-repair",
      "report_id": "web-representation-layers",
      "heading": "HTML Tokenization and Tree Construction",
      "heading_id": "html-tokenization-and-tree-construction",
      "paraphrase": "HTML error recovery can construct a live DOM that materially differs from the original source markup.",
      "relation": "directly-supports",
      "source_ids": [
        "whatwg-html",
        "dom-standard"
      ],
      "source_category": "normative-standard",
      "publication_status": "living",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Audit both source and parsed DOM and avoid assuming raw nesting is the browser tree.",
      "required_follow_up": "Confirm exact behavior in the target browser when the case depends on implementation details."
    },
    {
      "id": "claim-web-inert-vs-aria",
      "report_id": "web-representation-layers",
      "heading": "Visibility States, Disclosure, and the inert Subtree",
      "heading_id": "visibility-states-disclosure-and-the-inert-subtree",
      "paraphrase": "aria-hidden changes accessibility exposure but does not itself disable focus or pointer interaction; inert establishes a broader interaction boundary.",
      "relation": "directly-supports",
      "source_ids": [
        "whatwg-html",
        "wai-aria-12",
        "core-aam-12"
      ],
      "source_category": "normative-standard",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Use inert and actual state synchronization for closed interactive regions instead of relying on aria-hidden alone.",
      "required_follow_up": "Verify browser and assistive-technology behavior for the deployed interaction."
    },
    {
      "id": "claim-document-extension-insufficient",
      "report_id": "document-container-forensics",
      "heading": "Answer-First Explanation: The Insufficiency of File Extensions",
      "heading_id": "answer-first-explanation-the-insufficiency-of-file-extensions",
      "paraphrase": "A filename extension cannot establish a document’s internal structure, active features, or safe handling requirements.",
      "relation": "directly-supports",
      "source_ids": [
        "iana-media",
        "pdf-iso32000",
        "ecma376",
        "png3"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Use bounded structural validation and fail closed on ambiguous container records.",
      "required_follow_up": "Verify the target parser and renderer separately when consequential behavior is at issue."
    },
    {
      "id": "claim-tokenizer-multistage",
      "report_id": "tokenization-differentials",
      "heading": "An Answer-First Overview",
      "heading_id": "an-answer-first-overview",
      "paraphrase": "Tokenization is a multi-stage, versioned pipeline rather than one universal string-to-token operation.",
      "relation": "directly-supports",
      "source_ids": [
        "sentencepiece",
        "bpe-nmt",
        "uax15",
        "uax29",
        "tiktoken"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Log the tokenizer, vocabulary, normalization, pre-tokenization, special-token, and truncation configuration.",
      "required_follow_up": "Use the exact production tokenizer for parity claims."
    },
    {
      "id": "claim-tokenizer-blanket-nfc",
      "report_id": "tokenization-differentials",
      "heading": "Defensive Input-Construction Patterns",
      "heading_id": "defensive-input-construction-patterns",
      "paraphrase": "The report’s instruction to enforce NFC on all user input is too broad for passwords, source-fidelity evidence, and applications whose protocol defines another comparison profile.",
      "relation": "conflicts",
      "source_ids": [
        "uax15",
        "uts39"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "The site’s policy builder makes normalization context-specific and preserves unmodified source evidence.",
      "required_follow_up": "Document the exact application profile before transforming user input."
    },
    {
      "id": "claim-steganalysis-statistical",
      "report_id": "linguistic-steganography-steganalysis",
      "heading": "Answer-First Definitions and Operational Boundaries",
      "heading_id": "answer-first-definitions-and-operational-boundaries",
      "paraphrase": "Steganalysis and watermark statistics provide evidence with false-positive and false-negative tradeoffs, not absolute certainty.",
      "relation": "directly-supports",
      "source_ids": [
        "watermark-llm",
        "neural-stego",
        "zero-shot-stego"
      ],
      "source_category": "primary-research",
      "publication_status": "final",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Display method assumptions, sample length, transformations, and uncertainty alongside any detector result.",
      "required_follow_up": "Do not convert one statistic into an intent or provenance verdict."
    },
    {
      "id": "claim-provenance-not-truth",
      "report_id": "content-provenance-authenticity",
      "heading": "What Provenance Can Establish and What It Cannot",
      "heading_id": "what-provenance-can-establish-and-what-it-cannot",
      "paraphrase": "Provenance and valid integrity evidence can describe origin and transformations but cannot establish the truth of the depicted or stated content.",
      "relation": "directly-supports",
      "source_ids": [
        "c2pa24",
        "c2pa-guidance24",
        "nist-synthetic"
      ],
      "source_category": "mixed-authority",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep structural inventory, cryptographic validation, attribution, and semantic truth as separate outcomes.",
      "required_follow_up": "Use a conforming verifier and independent contextual investigation for consequential claims."
    },
    {
      "id": "claim-agent-capability-boundary",
      "report_id": "indirect-prompt-injection-agent-security",
      "heading": "5\\. Defense-in-Depth Architecture and Trust Boundaries",
      "heading_id": "5-defense-in-depth-architecture-and-trust-boundaries",
      "paraphrase": "Because model-level instruction separation is imperfect, least privilege, tool mediation, confirmation, output validation, and egress controls must bound agent side effects.",
      "relation": "directly-supports",
      "source_ids": [
        "owasp-agent-cheat",
        "owasp-prompt-cheat",
        "nist-ai100-2",
        "injecagent"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep read-only tools and external effects disabled in public simulations and require independent authorization in production.",
      "required_follow_up": "Validate the exact tool scopes, credentials, memory, and egress policy of the deployed agent."
    },
    {
      "id": "claim-multimodal-independent-layers",
      "report_id": "multimodal-machine-perception-security",
      "heading": "Answer-First Explanation of Multimodal Representation Layers",
      "heading_id": "answer-first-explanation-of-multimodal-representation-layers",
      "paraphrase": "Pixels, alpha, metadata, alternative text, OCR output, and model-facing visual representations are independent channels that can disagree.",
      "relation": "directly-supports",
      "source_ids": [
        "png3",
        "exif31",
        "w3c-alt",
        "image-hijacks"
      ],
      "source_category": "mixed-authority",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Compare channels explicitly and label prepared OCR separately from runtime OCR or VLM behavior.",
      "required_follow_up": "Use the exact image decoder, OCR engine, model, resizing, and compositing path for parity conclusions."
    },
    {
      "id": "claim-email-mime-alternatives",
      "report_id": "email-mime-calendar-machine-channels",
      "heading": "The Divergence Risk of Multipart Alternatives",
      "heading_id": "the-divergence-risk-of-multipart-alternatives",
      "paraphrase": "A MIME message can contain text/plain and text/html alternatives that differ materially, so security and AI ingestion should compare both branches.",
      "relation": "directly-supports",
      "source_ids": [
        "rfc5322",
        "rfc2045"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": false,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Map multipart structure and decode each branch inertly without fetching linked resources.",
      "required_follow_up": "Use live mail-authentication systems only when cryptographic or DNS verification is authorized."
    },
    {
      "id": "claim-email-dmarc-currency",
      "report_id": "email-mime-calendar-machine-channels",
      "heading": "DMARC Evolution: RFC 9989 and the DNS Tree Walk",
      "heading_id": "dmarc-evolution-rfc-9989-and-the-dns-tree-walk",
      "paraphrase": "RFC 9989 is the current Proposed Standard for core DMARC and obsoletes RFC 7489 and RFC 9091.",
      "relation": "directly-supports",
      "source_ids": [
        "rfc9989"
      ],
      "source_category": "normative-standard",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Current guidance should reference RFC 9989 while retaining older RFCs only as historical context.",
      "required_follow_up": "Use DNS and mail-system evidence for actual policy evaluation; the public lab remains syntax-only."
    },
    {
      "id": "claim-browser-representation-synthesis",
      "report_id": "browser-accessibility-agent-views",
      "heading": "Limitations of Any Single Representation",
      "heading_id": "limitations-of-any-single-representation",
      "paraphrase": "Reliable browser automation requires reconciling semantics, live DOM state, geometry, and rendering because no one representation is sufficient.",
      "relation": "directly-supports",
      "source_ids": [
        "webdriver2",
        "webdriver-bidi",
        "cdp-accessibility",
        "wai-aria-12"
      ],
      "source_category": "mixed-authority",
      "publication_status": "draft",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Retain semantic targeting while checking attachment, visibility, overlap, focus, frames, and timing.",
      "required_follow_up": "Re-run the exact browser/version and accessibility-tree environment used in production."
    },
    {
      "id": "claim-browser-aria-modal-inert",
      "report_id": "browser-accessibility-agent-views",
      "heading": "Laboratory: Self-Contained Agent-View Fixtures",
      "heading_id": "laboratory-self-contained-agent-view-fixtures",
      "paraphrase": "The report fixture’s statement that aria-modal implicitly makes the background inert and prunes all outside nodes is not established by WAI-ARIA; application code must actually manage inertness and focus.",
      "relation": "conflicts",
      "source_ids": [
        "wai-aria-12",
        "whatwg-html",
        "core-aam-12"
      ],
      "source_category": "normative-standard",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "The implementation-owned fixture review explicitly corrects this claim and tests actual inert/focus behavior.",
      "required_follow_up": "Test the real dialog implementation with the target browser and assistive technology."
    },
    {
      "id": "claim-browser-closed-shadow",
      "report_id": "browser-accessibility-agent-views",
      "heading": "Locators, Shadow DOM, Iframes, and Popovers",
      "heading_id": "locators-shadow-dom-iframes-and-popovers",
      "paraphrase": "The report’s broad statement that semantic locators pierce closed Shadow DOM is not a portable WebDriver or accessibility guarantee.",
      "relation": "conflicts",
      "source_ids": [
        "webdriver2",
        "webdriver-bidi",
        "cdp-accessibility"
      ],
      "source_category": "normative-standard",
      "publication_status": "draft",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Current site guidance treats closed shadow roots, frames, and browser-specific accessibility exposure as implementation boundaries.",
      "required_follow_up": "Verify the exact automation framework and browser behavior rather than assuming portable access."
    },
    {
      "id": "claim-supplychain-not-safety",
      "report_id": "software-ai-artifact-provenance",
      "heading": "Limitations of Artifact Metadata",
      "heading_id": "limitations-of-artifact-metadata",
      "paraphrase": "An SBOM, signature, or provenance statement can support composition or origin claims but does not prove that software or a model is safe.",
      "relation": "directly-supports",
      "source_ids": [
        "spdx301",
        "cyclonedx17",
        "slsa12",
        "sigstore",
        "nist-ssdf"
      ],
      "source_category": "mixed-authority",
      "publication_status": "current",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Separate structural inspection, cryptographic verification, policy evaluation, and runtime security outcomes.",
      "required_follow_up": "Verify actual artifact digests, signer identity, builder policy, registry state, and runtime behavior through authorized systems."
    },
    {
      "id": "claim-supplychain-slsa-version",
      "report_id": "software-ai-artifact-provenance",
      "heading": "SLSA Provenance and Build Tracks",
      "heading_id": "slsa-provenance-and-build-tracks",
      "paraphrase": "The report’s SLSA v1.0 framing is now historical because SLSA 1.2 is the current specification and 1.0 is retired.",
      "relation": "conflicts",
      "source_ids": [
        "slsa10",
        "slsa12"
      ],
      "source_category": "normative-standard",
      "publication_status": "superseded",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Implementation-owned guidance and source maps point to 1.2 while preserving the report’s historical wording unchanged.",
      "required_follow_up": "Recheck the active SLSA version and track definitions before operational adoption."
    },
    {
      "id": "claim-supplychain-cyclonedx-version",
      "report_id": "software-ai-artifact-provenance",
      "heading": "CycloneDX Components, Services, and Formulations",
      "heading_id": "cyclonedx-components-services-and-formulations",
      "paraphrase": "CycloneDX 1.6 is no longer current; version 1.7 supersedes it for current implementation guidance.",
      "relation": "conflicts",
      "source_ids": [
        "cyclonedx16",
        "cyclonedx17"
      ],
      "source_category": "normative-standard",
      "publication_status": "superseded",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "The public review panel identifies 1.6 as historical and routes current visitors to 1.7.",
      "required_follow_up": "Validate production BOMs against the declared schema version rather than silently upgrading them."
    },
    {
      "id": "claim-defense-separate-dimensions",
      "report_id": "machine-tradecraft-defense-maturity",
      "heading": "Maturity Model with Observable Criteria",
      "heading_id": "maturity-model-with-observable-criteria",
      "paraphrase": "Control maturity should be assessed across independent dimensions and supported by verifiable evidence instead of collapsed into one opaque score.",
      "relation": "partially-supports",
      "source_ids": [
        "nist-csf2",
        "nist-ai-rmf",
        "owasp-samm",
        "cvss40"
      ],
      "source_category": "official-guidance",
      "publication_status": "mixed",
      "version_sensitive": true,
      "externally_reviewed": true,
      "checked_on": "2026-08-27",
      "implementation_impact": "Keep the maturity, tabletop, and control-evidence workflows non-scoring and explicit about evidence states.",
      "required_follow_up": "Use organizational evidence and named authorities before asserting observed maturity or compliance."
    }
  ]
}
