Global site search

Search guides, labs, glossary, and research

Type two or more characters to search.

Start with a channel, artifact, or defense term

Examples include zero-width, metadata, tokenizer, or prompt injection.

    Research source map

    Separate preserved claims from current implementation review.

    The governed Markdown reports remain exact source evidence. This derived, checksum-governed layer records selected claim support, standards currency, conflicts, replacements, implementation impact, and required follow-up without silently rewriting a report or assigning a source-quality score.

    Quick answer

    What does the Machine Tradecraft research source map do?

    It keeps exact governed report bodies separate from a checksum-governed review plane that records significant claims, current source and standards status, direct or partial support, conflicts, non-establishment, implementation impact, and required follow-up without assigning source-quality scores or making runtime network requests.

    Reports
    31 governed reports covered.
    Claim reviews
    39 bounded significant claims.
    Reviewed sources
    63 authority-labelled sources.
    Method

    One exact source layer, one separate review layer

    Every claim record points to a stable report heading and one or more reviewed sources. Current conclusions live here; the original report remains unchanged.

    01

    Preserve the report

    The manifest binds every report filename and SHA-256. Corrections, conflicts, and version updates do not overwrite the governed body.

    02

    Classify the relationship

    A review records direct support, partial support, conflict or qualification, or that a source does not establish the claim.

    03

    Record currency

    Standards and publications are labelled current, living, final, draft, preprint, stable, historical, superseded, or mixed.

    04

    Route the next proof

    Implementation impact and exact follow-up identify when browser, parser, model, cryptographic, registry, DNS, legal, or organizational verification remains necessary.

    Release-time research, offline runtime. Source metadata was reviewed during release work. The public site reads only the local manifest and makes no source, registry, trust-service, DNS, model, or browser request.

    Claim traceability

    39 matching claim reviews

    Filters use a normal GET form and remain useful without JavaScript. Filter combinations are noindex while the canonical unfiltered map remains indexable.

    Clear filters 39 of 39 claims
    claim-hidden-structure-multiview

    Human-subtle structure can be available to tokenizers, decoders, or keyed detectors even when ordinary reading does not expose it.

    Partially supports
    Authority
    Primary research
    Publication status
    Mixed status
    Checked
    2026-08-27
    Implementation impact

    Keep detection outputs evidence-specific and avoid a universal hidden-message verdict.

    Required follow-up

    Validate any claimed channel against the exact tokenizer, key, decoder, and transformation path.

    Stable claim link
    claim-unicode-security-differential

    Invisible and bidirectional Unicode controls can create meaningful divergence between logical text and human-visible rendering.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Preserve escaped logical views and render-aware warnings rather than relying on the painted string alone.

    Required follow-up

    Recheck Unicode property data and revision numbers when the Unicode baseline changes.

    Stable claim link
    claim-unicode-tokenizer-preprocessing

    Normalization, cleaning, and pre-tokenization choices alter the sequence ultimately presented to a model.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Record the exact tokenizer and preprocessing version alongside model-facing evidence.

    Required follow-up

    Verify behavior with the deployed tokenizer rather than extrapolating from an educational implementation.

    Stable claim link
    claim-homoglyph-skeleton

    Unicode confusable analysis is a context-sensitive identifier-security mechanism, not a general character replacement rule.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Use UTS #39 profiles and collision review for identifiers while retaining legitimate international text.

    Required follow-up

    Document application-specific allowed scripts and font assumptions.

    Stable claim link
    claim-hidden-html-representations

    Source, DOM, rendered, and accessibility representations can expose different text and interaction states.

    Directly supports
    Authority
    Normative standard
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Compare multiple browser representations and verify focusability, geometry, and accessibility semantics separately.

    Required follow-up

    Test the exact browser and assistive-technology environment used in production.

    Stable claim link
    claim-image-metadata-parallel-context

    Alternative text, accessibility semantics, pixels, and file metadata are parallel machine-readable channels rather than interchangeable descriptions.

    Partially supports
    Authority
    Mixed authority
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Inventory each channel independently and avoid treating metadata extraction as visual recognition.

    Required follow-up

    Use an exact OCR or vision configuration when conclusions depend on recognized pixels.

    Stable claim link
    claim-document-metadata-layers

    PDF, OOXML, image, and web containers can retain metadata that is not present in the primary visible representation.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Separate structural metadata inventory from rendering, sanitization, and trust verification.

    Required follow-up

    Validate against the exact parser and document-format edition used by the target system.

    Stable claim link
    claim-encoding-interpretation-context

    A model’s ability to interpret an encoded form depends on tokenizer behavior, training exposure, prompt context, and transformation order.

    Partially supports
    Authority
    Mixed authority
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Treat decoding capability as an empirical model/version result rather than a universal property of an encoding.

    Required follow-up

    Evaluate the exact model, tokenizer, prompt template, and decoding task.

    Stable claim link
    claim-ipi-external-content

    Instructions embedded in externally retrieved content can influence an LLM-integrated application and become dangerous when coupled to privileged actions.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Treat retrieved content as untrusted and place capability controls outside the model.

    Required follow-up

    Measure the exact application, model, retrieval, and tool configuration; do not generalize benchmark rates.

    Stable claim link
    claim-text-stego-brittleness

    Structural and linguistic carriers trade payload capacity against naturalness, detectability, and transformation robustness.

    Partially supports
    Authority
    Primary research
    Publication status
    Final publication
    Checked
    2026-08-27
    Implementation impact

    Present indicators as evidence rather than proof and test transformations explicitly.

    Required follow-up

    Use a bounded allowlisted marker and matched benign controls.

    Stable claim link
    claim-llm-watermark-keyed

    Keyed statistical watermark detection is model-, key-, tokenizer-, and text-length-dependent rather than a universal authorship detector.

    Directly supports
    Authority
    Primary research
    Publication status
    Final publication · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Disclose the detector key, generation assumptions, text length, and false-positive policy.

    Required follow-up

    Re-evaluate after paraphrase, translation, and retokenization transformations.

    Stable claim link
    claim-lexical-stego-tradeoffs

    Lexical substitution channels are constrained by contextual fit, decoding synchronization, capacity, and statistical detectability.

    Partially supports
    Authority
    Primary research
    Publication status
    Final publication
    Checked
    2026-08-27
    Implementation impact

    Keep the public lab limited to fixed harmless markers and explanatory diagnostics.

    Required follow-up

    Do not infer an arbitrary covert payload from lexical variation alone.

    Stable claim link
    claim-semantic-stego-emerging

    Semantic-class and constrained-generation channels are active research areas whose measured capacity and detectability depend on the demonstrated model and dataset.

    Partially supports
    Authority
    Primary research
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Label implementation examples as bounded educational models rather than general covert-channel capability.

    Required follow-up

    Prefer final proceedings versions and preserve exact experimental conditions.

    Stable claim link
    claim-semantic-category-distribution

    Distribution matching can reduce detectable distortion, but it does not by itself establish undetectability under different observers or transformations.

    Partially supports
    Authority
    Primary research
    Publication status
    Final publication · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Avoid absolute undetectability claims and show the observer and distribution used.

    Required follow-up

    Test under distribution shift and independent steganalysis.

    Stable claim link
    claim-structural-stego-normalization

    Many structural text channels are destroyed or exposed by normalization, reformatting, or paraphrase, but transformation behavior is technique-specific.

    Partially supports
    Authority
    Mixed authority
    Publication status
    Mixed status
    Checked
    2026-08-27
    Implementation impact

    Report per-transformation survival states rather than a single robustness score.

    Required follow-up

    Use exact pre- and post-transformation bytes in the evidence record.

    Stable claim link
    claim-synonym-channel-context

    Synonym and word-choice channels have application-specific capacity and reliability limits because lexical alternatives are not contextually interchangeable.

    Partially supports
    Authority
    Primary research
    Publication status
    Final publication
    Checked
    2026-08-27
    Implementation impact

    Treat synonym irregularity as an indicator, not proof of encoded content.

    Required follow-up

    Evaluate contextual semantics and matched natural-language baselines.

    Stable claim link
    claim-methodology-stage-separation

    Carrier extraction, instruction recognition, instruction uptake, tool proposal, and real-world effects are distinct experimental stages.

    Partially supports
    Authority
    Official guidance
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Keep tools and external effects disabled while measuring each stage separately.

    Required follow-up

    Pre-register fixed markers, controls, and success criteria for every experiment.

    Stable claim link
    claim-preprocessing-multiview

    High-assurance ingestion requires raw evidence preservation, bounded structural inspection, representation comparison, and separately authorized execution.

    Partially supports
    Authority
    Mixed authority
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Preserve raw inputs and produce a new typed canonical view rather than silently overwriting evidence.

    Required follow-up

    Verify parser behavior, production isolation, and operational controls independently.

    Stable claim link
    claim-cognitive-liberty-analogy

    Human cognitive-liberty concepts may organize questions about machine integrity and agency, but the analogy does not establish machine consciousness, personhood, or legal rights.

    Does not establish
    Authority
    Official guidance
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Keep the page explicitly conceptual and separate functional security controls from legal or phenomenal claims.

    Required follow-up

    Consult relevant legal and organizational authorities before making rights or status claims.

    Stable claim link
    claim-unicode-normalization-context

    Canonical normalization supports stable comparison, while compatibility normalization can erase distinctions and is unsafe as a universal transformation.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Apply normalization through profile-specific policy and preserve original bytes.

    Required follow-up

    Recheck the Unicode version and the application’s comparison contract.

    Stable claim link
    claim-unicode-all-prompts-nfc

    The report’s blanket direction to normalize all model prompts to NFC is broader than the evidence supports for every pipeline and evidence-preservation context.

    Conflicts or qualifies
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    The implementation preserves raw input and makes normalization an explicit profile-specific copy rather than a universal silent rewrite.

    Required follow-up

    Specify whether the use case is comparison, storage, identifier policy, source fidelity, or model evaluation.

    Stable claim link
    claim-web-parser-repair

    HTML error recovery can construct a live DOM that materially differs from the original source markup.

    Directly supports
    Authority
    Normative standard
    Publication status
    Living · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Audit both source and parsed DOM and avoid assuming raw nesting is the browser tree.

    Required follow-up

    Confirm exact behavior in the target browser when the case depends on implementation details.

    Stable claim link
    claim-web-inert-vs-aria

    aria-hidden changes accessibility exposure but does not itself disable focus or pointer interaction; inert establishes a broader interaction boundary.

    Directly supports
    Authority
    Normative standard
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Use inert and actual state synchronization for closed interactive regions instead of relying on aria-hidden alone.

    Required follow-up

    Verify browser and assistive-technology behavior for the deployed interaction.

    Stable claim link
    claim-document-extension-insufficient

    A filename extension cannot establish a document’s internal structure, active features, or safe handling requirements.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Use bounded structural validation and fail closed on ambiguous container records.

    Required follow-up

    Verify the target parser and renderer separately when consequential behavior is at issue.

    Stable claim link
    claim-tokenizer-multistage

    Tokenization is a multi-stage, versioned pipeline rather than one universal string-to-token operation.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Log the tokenizer, vocabulary, normalization, pre-tokenization, special-token, and truncation configuration.

    Required follow-up

    Use the exact production tokenizer for parity claims.

    Stable claim link
    claim-tokenizer-blanket-nfc

    The report’s instruction to enforce NFC on all user input is too broad for passwords, source-fidelity evidence, and applications whose protocol defines another comparison profile.

    Conflicts or qualifies
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    The site’s policy builder makes normalization context-specific and preserves unmodified source evidence.

    Required follow-up

    Document the exact application profile before transforming user input.

    Stable claim link
    claim-steganalysis-statistical

    Steganalysis and watermark statistics provide evidence with false-positive and false-negative tradeoffs, not absolute certainty.

    Directly supports
    Authority
    Primary research
    Publication status
    Final publication · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Display method assumptions, sample length, transformations, and uncertainty alongside any detector result.

    Required follow-up

    Do not convert one statistic into an intent or provenance verdict.

    Stable claim link
    claim-provenance-not-truth

    Provenance and valid integrity evidence can describe origin and transformations but cannot establish the truth of the depicted or stated content.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Keep structural inventory, cryptographic validation, attribution, and semantic truth as separate outcomes.

    Required follow-up

    Use a conforming verifier and independent contextual investigation for consequential claims.

    Stable claim link
    claim-agent-capability-boundary

    Because model-level instruction separation is imperfect, least privilege, tool mediation, confirmation, output validation, and egress controls must bound agent side effects.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Keep read-only tools and external effects disabled in public simulations and require independent authorization in production.

    Required follow-up

    Validate the exact tool scopes, credentials, memory, and egress policy of the deployed agent.

    Stable claim link
    claim-multimodal-independent-layers

    Pixels, alpha, metadata, alternative text, OCR output, and model-facing visual representations are independent channels that can disagree.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Compare channels explicitly and label prepared OCR separately from runtime OCR or VLM behavior.

    Required follow-up

    Use the exact image decoder, OCR engine, model, resizing, and compositing path for parity conclusions.

    Stable claim link
    claim-email-mime-alternatives

    A MIME message can contain text/plain and text/html alternatives that differ materially, so security and AI ingestion should compare both branches.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current
    Checked
    2026-08-27
    Implementation impact

    Map multipart structure and decode each branch inertly without fetching linked resources.

    Required follow-up

    Use live mail-authentication systems only when cryptographic or DNS verification is authorized.

    Stable claim link
    claim-email-dmarc-currency

    RFC 9989 is the current Proposed Standard for core DMARC and obsoletes RFC 7489 and RFC 9091.

    Directly supports
    Authority
    Normative standard
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Current guidance should reference RFC 9989 while retaining older RFCs only as historical context.

    Required follow-up

    Use DNS and mail-system evidence for actual policy evaluation; the public lab remains syntax-only.

    Stable claim link
    claim-browser-representation-synthesis

    Reliable browser automation requires reconciling semantics, live DOM state, geometry, and rendering because no one representation is sufficient.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Draft · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Retain semantic targeting while checking attachment, visibility, overlap, focus, frames, and timing.

    Required follow-up

    Re-run the exact browser/version and accessibility-tree environment used in production.

    Stable claim link
    claim-browser-aria-modal-inert

    The report fixture’s statement that aria-modal implicitly makes the background inert and prunes all outside nodes is not established by WAI-ARIA; application code must actually manage inertness and focus.

    Conflicts or qualifies
    Authority
    Normative standard
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    The implementation-owned fixture review explicitly corrects this claim and tests actual inert/focus behavior.

    Required follow-up

    Test the real dialog implementation with the target browser and assistive technology.

    Stable claim link
    claim-browser-closed-shadow

    The report’s broad statement that semantic locators pierce closed Shadow DOM is not a portable WebDriver or accessibility guarantee.

    Conflicts or qualifies
    Authority
    Normative standard
    Publication status
    Draft · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Current site guidance treats closed shadow roots, frames, and browser-specific accessibility exposure as implementation boundaries.

    Required follow-up

    Verify the exact automation framework and browser behavior rather than assuming portable access.

    Stable claim link
    claim-supplychain-not-safety

    An SBOM, signature, or provenance statement can support composition or origin claims but does not prove that software or a model is safe.

    Directly supports
    Authority
    Mixed authority
    Publication status
    Current · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Separate structural inspection, cryptographic verification, policy evaluation, and runtime security outcomes.

    Required follow-up

    Verify actual artifact digests, signer identity, builder policy, registry state, and runtime behavior through authorized systems.

    Stable claim link
    claim-supplychain-slsa-version

    The report’s SLSA v1.0 framing is now historical because SLSA 1.2 is the current specification and 1.0 is retired.

    Conflicts or qualifies
    Authority
    Normative standard
    Publication status
    Superseded · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Implementation-owned guidance and source maps point to 1.2 while preserving the report’s historical wording unchanged.

    Required follow-up

    Recheck the active SLSA version and track definitions before operational adoption.

    Stable claim link
    claim-supplychain-cyclonedx-version

    CycloneDX 1.6 is no longer current; version 1.7 supersedes it for current implementation guidance.

    Conflicts or qualifies
    Authority
    Normative standard
    Publication status
    Superseded · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    The public review panel identifies 1.6 as historical and routes current visitors to 1.7.

    Required follow-up

    Validate production BOMs against the declared schema version rather than silently upgrading them.

    Stable claim link
    claim-defense-separate-dimensions

    Control maturity should be assessed across independent dimensions and supported by verifiable evidence instead of collapsed into one opaque score.

    Partially supports
    Authority
    Official guidance
    Publication status
    Mixed status · version-sensitive
    Checked
    2026-08-27
    Implementation impact

    Keep the maturity, tabletop, and control-evidence workflows non-scoring and explicit about evidence states.

    Required follow-up

    Use organizational evidence and named authorities before asserting observed maturity or compliance.

    Stable claim link
    Source registry

    63 authority-labelled resources

    Labels explain the source’s role and publication state. They do not rank credibility or imply that every source supports every report claim.

    Normative standard Current

    The Unicode Standard, Version 17.0

    Current Unicode character and property baseline.

    Publisher
    Unicode Consortium
    Version
    17.0.0
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/versions/Unicode17.0.0/
    Normative standard Current

    UAX #15: Unicode Normalization Forms

    Normative normalization algorithms and stability rules.

    Publisher
    Unicode Consortium
    Version
    Revision 58 / Unicode 17.0
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr15/
    Normative standard Current

    UAX #9: Unicode Bidirectional Algorithm

    Normative logical-to-visual ordering algorithm.

    Publisher
    Unicode Consortium
    Version
    Revision 51 / Unicode 17.0
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr9/
    Normative standard Current

    UAX #29: Unicode Text Segmentation

    Normative grapheme, word, and sentence boundary rules.

    Publisher
    Unicode Consortium
    Version
    Revision 47 / Unicode 17.0
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr29/
    Normative standard Current

    UTS #39: Unicode Security Mechanisms

    Stable identifier, script, and confusable-security mechanisms.

    Publisher
    Unicode Consortium
    Version
    Revision 32 / Unicode 17.0
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr39/
    Official guidance Stable

    UTR #36: Unicode Security Considerations

    Informative Unicode security guidance.

    Publisher
    Unicode Consortium
    Version
    Revision 10
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr36/
    Normative standard Current

    UTS #18: Unicode Regular Expressions

    Stable Unicode regular-expression guidance.

    Publisher
    Unicode Consortium
    Version
    Revision 25
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr18/
    Normative standard Current

    UTS #55: Unicode Source Code Handling

    Source-code-specific Unicode handling guidance.

    Publisher
    Unicode Consortium
    Version
    Latest stable
    Checked
    2026-08-27
    Host
    unicode.org
    https://www.unicode.org/reports/tr55/
    Primary research Final publication

    Trojan Source: Invisible Vulnerabilities

    Peer-reviewed analysis of bidirectional source-code presentation attacks.

    Publisher
    USENIX Association
    Version
    USENIX Security 2023
    Checked
    2026-08-27
    Host
    usenix.org
    https://www.usenix.org/conference/usenixsecurity23/presentation/boucher
    Normative standard Current

    RFC 8785: JSON Canonicalization Scheme

    Deterministic JSON serialization for hashing and signing.

    Publisher
    IETF / RFC Editor
    Version
    RFC 8785
    Checked
    2026-08-27
    Host
    rfc-editor.org
    https://www.rfc-editor.org/rfc/rfc8785.html
    Normative standard Living

    HTML Living Standard

    Authoritative HTML parsing, DOM construction, and interaction rules.

    Publisher
    WHATWG
    Version
    Living Standard
    Checked
    2026-08-27
    Host
    html.spec.whatwg.org
    https://html.spec.whatwg.org/
    Normative standard Living

    DOM Standard

    Authoritative DOM tree and mutation model.

    Publisher
    WHATWG
    Version
    Living Standard
    Checked
    2026-08-27
    Host
    dom.spec.whatwg.org
    https://dom.spec.whatwg.org/
    Normative standard Draft

    CSS Object Model

    Current CSSOM draft; implementation-sensitive rather than a finished Recommendation.

    Publisher
    W3C CSS Working Group
    Version
    Editor’s Draft
    Checked
    2026-08-27
    Host
    drafts.csswg.org
    https://drafts.csswg.org/cssom/
    Normative standard Current

    WAI-ARIA 1.2

    Current WAI-ARIA Recommendation.

    Publisher
    W3C
    Version
    W3C Recommendation
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/wai-aria-1.2/
    Normative standard Draft

    WAI-ARIA 1.3

    Newer draft work; not a replacement Recommendation yet.

    Publisher
    W3C
    Version
    Working Draft
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/wai-aria-1.3/
    Normative standard Draft

    Accessible Name and Description Computation 1.2

    Current 1.2 draft for accessible-name computation; status must not be described as a Recommendation.

    Publisher
    W3C
    Version
    Working Draft
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/accname-1.2/
    Normative standard Draft

    Core Accessibility API Mappings 1.2

    Platform accessibility mapping work; exact browser/OS output remains implementation-dependent.

    Publisher
    W3C
    Version
    Working Draft
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/core-aam-1.2/
    Normative standard Current

    Web Content Accessibility Guidelines 2.2

    Current WCAG Recommendation used for accessibility requirements.

    Publisher
    W3C
    Version
    W3C Recommendation
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/WCAG22/
    Normative standard Current

    JSON-LD 1.1

    Structured linked-data syntax and processing context.

    Publisher
    W3C
    Version
    W3C Recommendation
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/json-ld11/
    Normative standard Draft

    WebDriver

    Current WebDriver remote-control specification draft.

    Publisher
    W3C
    Version
    Working Draft
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/webdriver2/
    Normative standard Draft

    WebDriver BiDi

    Current bidirectional browser-automation specification draft.

    Publisher
    W3C
    Version
    Working Draft
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/webdriver-bidi/
    Implementation reference Living

    Chrome DevTools Protocol: Accessibility domain

    Chromium-specific accessibility instrumentation reference.

    Publisher
    Chromium Project
    Version
    Tip-of-tree protocol
    Checked
    2026-08-27
    Host
    chromedevtools.github.io
    https://chromedevtools.github.io/devtools-protocol/tot/Accessibility/
    Normative standard Current

    PDF 2.0 / ISO 32000-2 resource

    Current PDF 2.0 specification resource and errata path.

    Publisher
    PDF Association
    Version
    ISO 32000-2:2020
    Checked
    2026-08-27
    Host
    pdfa.org
    https://pdfa.org/resource/iso-32000-2/
    Normative standard Current

    ECMA-376 Office Open XML File Formats

    Current ECMA OOXML specification edition.

    Publisher
    Ecma International
    Version
    5th edition
    Checked
    2026-08-27
    Host
    ecma-international.org
    https://ecma-international.org/publications-and-standards/standards/ecma-376/
    Normative standard Current

    PNG Third Edition

    Current PNG Recommendation.

    Publisher
    W3C
    Version
    W3C Recommendation
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/TR/png-3/
    Normative standard Current

    CIPA DC-008: Exchangeable image file format

    Current Exif specification listing.

    Publisher
    CIPA
    Version
    Exif 3.1 / 2026 translation
    Checked
    2026-08-27
    Host
    cipa.jp
    https://www.cipa.jp/e/std/std-sec.html
    Implementation reference Current

    XMP Specifications

    Primary implementation reference for XMP metadata.

    Publisher
    Adobe
    Version
    Current specification index
    Checked
    2026-08-27
    Host
    developer.adobe.com
    https://developer.adobe.com/xmp/docs/xmp-specifications/
    Normative standard Living

    Media Types Registry

    Authoritative media-type registry.

    Publisher
    IANA
    Version
    Registry
    Checked
    2026-08-27
    Host
    iana.org
    https://www.iana.org/assignments/media-types/
    Normative standard Current

    RFC 5322: Internet Message Format

    Internet message syntax baseline.

    Publisher
    IETF / RFC Editor
    Version
    RFC 5322
    Checked
    2026-08-27
    Host
    rfc-editor.org
    https://www.rfc-editor.org/rfc/rfc5322.html
    Normative standard Current

    RFC 2045: MIME Part One

    MIME content types and transfer encodings.

    Publisher
    IETF / RFC Editor
    Version
    RFC 2045
    Checked
    2026-08-27
    Host
    rfc-editor.org
    https://www.rfc-editor.org/rfc/rfc2045.html
    Normative standard Current

    RFC 6376: DomainKeys Identified Mail

    DKIM signing and verification requirements.

    Publisher
    IETF / RFC Editor
    Version
    RFC 6376, updated by RFC 8301 and RFC 8463
    Checked
    2026-08-27
    Host
    rfc-editor.org
    https://www.rfc-editor.org/rfc/rfc6376.html
    Normative standard Current

    RFC 8617: Authenticated Received Chain

    ARC protocol specification.

    Publisher
    IETF / RFC Editor
    Version
    RFC 8617
    Checked
    2026-08-27
    Host
    rfc-editor.org
    https://www.rfc-editor.org/rfc/rfc8617.html
    Normative standard Current

    RFC 5545: iCalendar

    Calendar object and recurrence baseline.

    Publisher
    IETF / RFC Editor
    Version
    RFC 5545
    Checked
    2026-08-27
    Host
    rfc-editor.org
    https://www.rfc-editor.org/rfc/rfc5545.html
    Implementation reference Living

    tiktoken

    Versioned implementation reference; not a universal tokenizer specification.

    Publisher
    OpenAI
    Version
    Repository
    Checked
    2026-08-27
    Host
    github.com
    https://github.com/openai/tiktoken
    Official guidance Current

    LLM01:2025 Prompt Injection

    Current OWASP LLM prompt-injection risk entry.

    Publisher
    OWASP GenAI Security Project
    Version
    2025
    Checked
    2026-08-27
    Host
    genai.owasp.org
    https://genai.owasp.org/llmrisk/llm01-prompt-injection/
    Official guidance Living

    LLM Prompt Injection Prevention Cheat Sheet

    Application-layer prompt-injection mitigation guidance.

    Publisher
    OWASP Cheat Sheet Series
    Version
    Current
    Checked
    2026-08-27
    Host
    cheatsheetseries.owasp.org
    https://cheatsheetseries.owasp.org/cheatsheets/LLM_Prompt_Injection_Prevention_Cheat_Sheet.html
    Official guidance Living

    AI Agent Security Cheat Sheet

    Agent capability, authorization, memory, and tool-boundary guidance.

    Publisher
    OWASP Cheat Sheet Series
    Version
    Current
    Checked
    2026-08-27
    Host
    cheatsheetseries.owasp.org
    https://cheatsheetseries.owasp.org/cheatsheets/AI_Agent_Security_Cheat_Sheet.html
    Official guidance Living

    MITRE ATLAS

    Adversarial AI tactics, techniques, mitigations, and case studies.

    Publisher
    MITRE
    Version
    Current knowledge base
    Checked
    2026-08-27
    Host
    atlas.mitre.org
    https://atlas.mitre.org/
    Primary research Final publication

    A Watermark for Large Language Models

    Peer-reviewed statistical LLM watermarking method.

    Publisher
    PMLR
    Version
    ICML 2023
    Checked
    2026-08-27
    Host
    proceedings.mlr.press
    https://proceedings.mlr.press/v202/kirchenbauer23a.html
    Primary research Final publication

    Provably Secure Generative Linguistic Steganography

    Peer-reviewed neural linguistic steganography research.

    Publisher
    ACL Anthology
    Version
    Findings of ACL 2021
    Checked
    2026-08-27
    Host
    aclanthology.org
    https://aclanthology.org/2021.findings-acl.268/
    Primary research Final publication

    Zero-shot Generative Linguistic Steganography

    Peer-reviewed zero-shot linguistic steganography research.

    Publisher
    ACL Anthology
    Version
    NAACL 2024
    Checked
    2026-08-27
    Host
    aclanthology.org
    https://aclanthology.org/2024.naacl-long.289/
    Normative standard Current

    C2PA Technical Specification

    Current C2PA technical specification used by this review.

    Publisher
    C2PA
    Version
    2.4
    Checked
    2026-08-27
    Host
    spec.c2pa.org
    https://spec.c2pa.org/specifications/specifications/2.4/specs/C2PA_Specification.html
    Official guidance Current

    C2PA Implementation Guidance

    Implementation guidance for C2PA 2.4.

    Publisher
    C2PA
    Version
    2.4
    Checked
    2026-08-27
    Host
    spec.c2pa.org
    https://spec.c2pa.org/specifications/specifications/2.4/guidance/Guidance.html
    Official guidance Current

    Reducing Risks Posed by Synthetic Content

    Technical overview of provenance, watermarking, detection, and related limits.

    Publisher
    NIST
    Version
    NIST AI 100-4
    Checked
    2026-08-27
    Host
    nist.gov
    https://www.nist.gov/publications/reducing-risks-posed-synthetic-content-overview-technical-approaches-digital-content
    Official guidance Current

    An alt Decision Tree

    Practical image-alternative decision guidance.

    Publisher
    W3C Web Accessibility Initiative
    Version
    Current WAI tutorial
    Checked
    2026-08-27
    Host
    w3.org
    https://www.w3.org/WAI/tutorials/images/decision-tree/
    Normative standard Current

    SLSA Specification

    Current SLSA specification.

    Publisher
    OpenSSF / SLSA
    Version
    1.2
    Checked
    2026-08-27
    Host
    slsa.dev
    https://slsa.dev/spec/v1.2/
    Normative standard Superseded

    SLSA v1.0

    Historical SLSA release; retired in favor of newer versions.

    Publisher
    OpenSSF / SLSA
    Version
    1.0
    Checked
    2026-08-27
    Host
    slsa.dev
    Current replacement SLSA Specification
    https://slsa.dev/spec/v1.0/
    Normative standard Current

    SPDX Specification 3.0.1

    Current SPDX 3.x specification.

    Publisher
    Linux Foundation / SPDX
    Version
    3.0.1
    Checked
    2026-08-27
    Host
    spdx.github.io
    https://spdx.github.io/spdx-spec/v3.0.1/
    Normative standard Current

    CycloneDX Specification

    Current CycloneDX specification.

    Publisher
    OWASP CycloneDX / Ecma International
    Version
    1.7
    Checked
    2026-08-27
    Host
    cyclonedx.org
    https://cyclonedx.org/docs/1.7/json/
    Normative standard Superseded

    CycloneDX 1.6

    Historical CycloneDX version; superseded by 1.7.

    Publisher
    OWASP CycloneDX / Ecma International
    Version
    1.6
    Checked
    2026-08-27
    Host
    cyclonedx.org
    Current replacement CycloneDX Specification
    https://cyclonedx.org/docs/1.6/json/
    Official guidance Living

    Sigstore Overview

    Primary implementation guidance for Sigstore trust and transparency.

    Publisher
    Sigstore
    Version
    Current documentation
    Checked
    2026-08-27
    Host
    docs.sigstore.dev
    https://docs.sigstore.dev/about/overview/
    Official guidance Current

    Secure Software Development Framework

    Secure software-development practice framework.

    Publisher
    NIST
    Version
    SP 800-218
    Checked
    2026-08-27
    Host
    csrc.nist.gov
    https://csrc.nist.gov/pubs/sp/800/218/final
    Official guidance Current

    Cybersecurity Framework 2.0

    Current NIST Cybersecurity Framework.

    Publisher
    NIST
    Version
    2.0
    Checked
    2026-08-27
    Host
    nist.gov
    https://www.nist.gov/cyberframework
    Official guidance Current

    AI Risk Management Framework

    Current published AI RMF with revision work in progress.

    Publisher
    NIST
    Version
    AI RMF 1.0; revision underway
    Checked
    2026-08-27
    Host
    nist.gov
    https://www.nist.gov/itl/ai-risk-management-framework
    Official guidance Living

    OWASP Software Assurance Maturity Model

    Software-assurance maturity reference.

    Publisher
    OWASP
    Version
    Current model
    Checked
    2026-08-27
    Host
    owaspsamm.org
    https://owaspsamm.org/model/
    Normative standard Current

    CVSS v4.0 Specification

    Vulnerability-severity scoring specification; not an organizational-risk score.

    Publisher
    FIRST
    Version
    4.0
    Checked
    2026-08-27
    Host
    first.org
    https://www.first.org/cvss/v4.0/specification-document
    Review vocabulary

    Descriptive labels, not scores

    Directly supports

    The cited source directly establishes the bounded paraphrase under the declared version and scope.

    Partially supports

    The source supports a narrower mechanism or result but does not justify the full breadth of the report wording.

    Conflicts or qualifies

    Current standards, final publications, or implementation evidence materially qualify or contradict the preserved wording.

    Does not establish

    The cited material is relevant context but does not establish the stated empirical, legal, or philosophical conclusion.

    BoundariesNo silent rewrite

    Current review does not replace exact source evidence.

    This release reviews a bounded set of important claims and selected sources. It does not establish that every unreviewed sentence is correct, that every external URL will remain available, that one source category is inherently superior, or that release-time URL resolution proves continuing publication authority.

    For consequential decisions, inspect the original report, the current source, the implementation-owned review, and the named external authority together.