Rubric: L-SECURITY
Lens: L-SECURITY ยท Density: D-MED ยท Axes: SEC, ROB
Criteria
- Trust boundaries (authn/authz, multi-tenant, network exposure).
- Input validation / output encoding.
- Secrets handling (not in repo; rotation; memory).
- Dependency/supply risk (lockfiles, known vuln process).
- Dangerous defaults (open bind, debug left on, permissive CORS).
- Agentic/tool surfaces if present: prompt/tool injection, confused deputy, forgeable acknowledgements.
Citations
| Work |
Point |
| OWASP ASVS |
Verification requirements by level |
| OWASP Top 10 |
Common web risks (when applicable) |
| NIST SSDF (SP 800-218) |
Secure software development practices |
| NIST SP 800-53 (select controls) |
Audit/auth concepts when systems are sensitive |
Pros / cons
| Pros |
Cons |
| Industry-standard vocabulary |
ASVS Level overreach on small CLIs โ state assumed level |
| Includes agentic abuse (modern) |
Easy to speculate threats without anchors โ require E2 paths |
Severity guidance
- Secrets in tree โ critical
- Missing auth on exposed network admin โ critical/high
- Theoretical threat without entry point โ info/low or retract