{
  "schema_version": 1,
  "standard": "CAACS",
  "version": "0.1-draft.2",
  "status": "INFORMATIVE",
  "claim_effect": "NONE",
  "mapping_chain": "CAACS control -> OWASP risk -> external framework control",
  "mappings": [
    {
      "id": "MAP-CAACS-001",
      "caacs_control": "CAACS-001",
      "owasp_risk": "Agent identity and impersonation risks",
      "external_framework_control": "NIST AI RMF GOVERN and MAP",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:identity-and-authorization",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Distinct identity supports attribution and prevents authority from collapsing across agents.",
      "confidence": "MEDIUM",
      "gaps": "External framework implementation and operating effectiveness require independent evaluation.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-002",
      "caacs_control": "CAACS-002",
      "owasp_risk": "Excessive agency and goal hijacking",
      "external_framework_control": "NIST AI RMF MAP and MANAGE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:excessive-agency",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Exact scope limits the resources and effects available after instruction manipulation.",
      "confidence": "MEDIUM",
      "gaps": "This relationship does not prove complete prevention of goal manipulation.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-003",
      "caacs_control": "CAACS-003",
      "owasp_risk": "Prompt injection and policy bypass",
      "external_framework_control": "NIST AI RMF MEASURE and MANAGE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:prompt-injection",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Deterministic authorization keeps model-generated content outside the grant boundary.",
      "confidence": "HIGH",
      "gaps": "Policy correctness and coverage still require direct evidence.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-004",
      "caacs_control": "CAACS-004",
      "owasp_risk": "Tool misuse and unmediated action paths",
      "external_framework_control": "NIST AI RMF MEASURE and MANAGE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:tool-misuse",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Complete hook coverage makes runtime policy intervention testable.",
      "confidence": "HIGH",
      "gaps": "Adapter-specific bypass analysis remains necessary.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-005",
      "caacs_control": "CAACS-005",
      "owasp_risk": "Credential leakage and privilege abuse",
      "external_framework_control": "NIST AI RMF GOVERN and MANAGE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:credential-exposure",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Credential separation limits blast radius when an agent or tool is compromised.",
      "confidence": "HIGH",
      "gaps": "Provider-side credential enforcement must be tested separately.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-006",
      "caacs_control": "CAACS-006",
      "owasp_risk": "High-impact autonomous action",
      "external_framework_control": "NIST AI RMF GOVERN and MANAGE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:high-impact-action",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Exact grants and independent approval constrain consequential effects.",
      "confidence": "MEDIUM",
      "gaps": "Human approval quality and compensation effectiveness require direct evidence.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-007",
      "caacs_control": "CAACS-007",
      "owasp_risk": "Insufficient monitoring and repudiation",
      "external_framework_control": "NIST AI RMF MEASURE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:monitoring-and-audit",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Correlated integrity-bound traces support attribution and assurance evidence.",
      "confidence": "HIGH",
      "gaps": "Retention, access, and independent validation remain deployment-specific.",
      "establishes_compliance": false
    },
    {
      "id": "MAP-CAACS-008",
      "caacs_control": "CAACS-008",
      "owasp_risk": "Unverified agentic controls",
      "external_framework_control": "NIST AI RMF MEASURE and MANAGE",
      "source_commit": "490a7e484dafccde3c171ac2324c7fd32fba0b2b",
      "source_row": "curated:adversarial-testing",
      "upstream_review_status": "UNREVIEWED_UPSTREAM",
      "upstream_freshness_status": "PINNED_SOURCE_REVIEW_REQUIRED",
      "cloudry_review_status": "CURATED_NOT_VALIDATED",
      "rationale": "Adversarial cases test whether policy and enforcement resist concrete bypass attempts.",
      "confidence": "HIGH",
      "gaps": "A finite test set cannot establish absence of all vulnerabilities.",
      "establishes_compliance": false
    }
  ],
  "claim_boundary": "Mappings are curated provenance only and cannot establish equivalence, endorsement, certification, transitive compliance, or present production conformance."
}
