Assess

Assess an AI security whitepaper

A copy-ready prompt that checks a paper against 87 classic security engineering principles, 130 AI and agentic security principles, and the SRF accountability and regulatory data, then reviews a working draft for the mechanical defects that survive ordinary review. Paste the prompt, add the paper, and your assistant fetches slim catalogs itself after it confirms the read. No file uploads.

Prompt injection warning Always review prompts before referencing or copying them into an assistant, agent, or production system.

How to run it

  1. Copy the prompt below into a new conversation with an AI assistant that can fetch URLs.
  2. Paste the text, attach a file, or share a URL, for example a PDF or webpage link, the assistant can fetch.
  3. The assistant reports what it managed to read before it assesses anything. If the read is whole, it fetches both slim principle catalogs and, when the paper makes threat-specific or regulatory claims, the SRF data behind those claims.
  4. Say map-only in the same message to skip the citation registries, live SRF fetch, and draft mechanics. Intake, mapping, coverage, known gaps, and the P1/P2 caps still run.
  5. Beyond catalog matching, the prompt runs an integrity screen on the submission itself, grounds any regulatory or accountability claims in live data, and checks draft mechanics and machine readability when you're reviewing a working draft rather than a finished paper.
  6. Output arrives as a ranked findings table plus prose blocks for the checks that are not principle matching. Matched statements are a count and a list of catalog ids, not one row each.

What it checks against

These three sources back the principle-matching steps below. The prompt fetches slim projections of the two principle catalogs after intake passes. The intake check, submission screen, regulatory grounding, and draft-mechanics checks described after the cards run independently of them, not against a catalog.

87

Classic security principles

Saltzer and Schroeder, NIST SP 800-27, ISO 27001, CIS Controls v8/v8.1, Microsoft's two law sets, and cloud architecture corollaries. Settled engineering axioms, most of them decades old.

/data/security-principles.slim.json

Full file with sources: /data/security-principles.json

130

AI and agentic security principles

Normalized from the 52-source synthesis across 22 topic sections, with a gap index tying each section's blind spot back to the classic principle it misses. These entries record current industry positions and have not settled into axioms.

/data/ai-agentic-principles.slim.json

Full file with sources: /data/ai-agentic-principles.json

16

Threat-to-accountability crosswalk

Each OWASP AI Exchange threat mapped to the SRF layer that owns the control point. Catches a paper that assigns a fix to the wrong layer, which is a category error rather than a difference of opinion.

/data/threats.json

Four checks that are not principle matching

Principle matching can pass while the read, the citations, the threat-to-layer mapping, or the draft mechanics are still wrong.

StepWhat it asksWhat a miss produces
0 Intake Extraction method, section and page count, and a list of what could not be read, including images, tables that lost structure, and appendices. A broken heading tree, or a section count that disagrees with the paper's own table of contents, stops the review. A confident list of topics the paper "does not address" after a truncated PDF, a two-column extract that interleaved its columns, or a JavaScript page that returned a shell.
1 Submission screen Citation identifiers resolved against registries; unpinned package or repo recommendations; text aimed at the reviewing system; unsourced figures; recommendations naming no version or setting; experience claims with no environment; the newest dated reference next to the publication date; leftover production artifacts. Each is reported as itself, not as evidence of who wrote the text. A paper can match both catalogs and still fail this screen. A fake DOI, an unpinned install that can be poisoned after publication, or a statistic nobody can re-count, sitting next to a clean principle-mapping table.
5 Live grounding When the paper names a threat, a regulation, or who owns a control, fetch the matching SRF data instead of answering from memory. Report the last_verified date on every regulatory finding. Skip papers that stay at general engineering principle, and say so. A threat assigned to a layer that cannot reach the control point, or a regulation cited from recollection rather than from regulations.json.
6 Draft mechanics On a working draft: typos, inconsistent defined terms, topics scattered across non-adjacent sections, near-duplicate statements, links that resolve to the wrong document, stable heading anchors, a heading tree a parser can walk, and sections that still make sense once chunked. Skip a published paper, and say so. Defects that cost an afternoon to fix before publication and a lot afterward, because ordinary review reads past them.

Disclosure under step 1 stays an observation: which conclusions favor a named vendor, and whether a funding or employment statement appears. Asserting an undisclosed relationship means asserting something that is not in evidence. Prose rhythm, vocabulary, and punctuation habits carry no integrity verdict at any volume. House style guides, standards-body templates, single authors, and non-native English writers produce those patterns at least as often as a model does.

How findings are ranked

One scale covers every step, so a reader can see at a glance which findings are integrity-shaped and which are housekeeping. Mixing them in a single list invites an author to dismiss the whole report as pedantry.

TierWhat it meansWhy it ranks here
P1 Following the paper's guidance would leave a system less secure Contradiction with a classic axiom, or a threat assigned to a layer that does not own the control point. The advice itself is the defect.
P2 Integrity An identifier naming no document, a citation saying something other than what the paper claims, instructions aimed at the reviewer, or an unpinned dependency the paper tells readers to install.
P3 Substantive gaps and softer conflicts Coverage holes in scope for the paper, contradiction with a still-forming industry position, a regulatory mapping past its staleness threshold.
P4 Mechanics Typos, link rot, heading structure, machine readability. Batch-fixable, and changes nothing about whether the paper's argument holds.

A second rule caps each finding by how it was reached, and the cap is structural rather than a request for a softer tone. A finding checked against a fetched catalog entry, a resolved URL, or a registry record can sit at any tier. A finding inferred from the paper's own unambiguous text stops at P3. A stylometric, statistical, or intent-based finding stops at P4 and is phrased as an observation. Uniform sentence rhythm is produced by house style guides, standards-body templates, single authors, and non-native English writers at least as often as by a model, so it cannot carry an integrity verdict.

Severity escalates on recurrence rather than on any single instance. One unpinned dependency is a P2 line item. The same shape appearing three or more times is a process defect, reported once. Three or more P2s of that shape become one P1. Three or more P3s become one P2. Three or more P4s become one P3. P1 stays P1.

Step 1 asks for resolved identifiers rather than a judgment by eye. A list of 15 or more entries runs a pinned reference audit tool; a shorter list resolves each identifier against one registry of record (Crossref for DOIs, arXiv for arXiv IDs). A second registry is fetched only when the first misses or the title does not match. bib-audit reports a dead DOI separately from a DOI that resolves to a different paper, which are different findings. Pin it to a release or commit before wiring it into anything automated, on the same reasoning the prompt applies to every other dependency a paper recommends.

The prompt

Prompt v2.2, September 2026. What changed in 2.2, 2.1, and 2.0. A 2.1 report stays valid; it fetched full catalogs, emitted every Matched row, and packaged Novel rows for catalog addition. A 2.0 report stays valid; it screened less of the submission. A 1.0 report stays valid on principle mapping; re-read its integrity findings.

Draft claims that need risk, obligation, control, and one owner, plus Google Docs or GitHub suggestion packets, use the separate draft claims test. That pack is independently proposed and is not a merge with this catalog grader.

What a Novel finding means

A Novel finding means the paper asserted something neither catalog covers. The table Note names the closest ids checked so you can disagree with the miss. It is a coverage observation about this paper against these two catalogs, at P3 at most unless the advice also contradicts a catalog entry.

It is not a request to add anything to a catalog. Catalog edits are made by changing the OSCAL source or the synthesis document, then regenerating. That work is not part of this prompt.

Notes on the catalogs

Both catalogs are generated, not hand-maintained. The classic catalog is normalized from a 93-control OSCAL source; five sets of entries that different frameworks state as literal restatements of one principle were merged into a single entry citing every source, and every original control id stays traceable through src. The AI-agentic catalog is parsed from the synthesis document; bullets the synthesis itself calls restatements were merged, and three sentences describing an absence of coverage rather than a claim any source makes were moved into gap_index so a statement about what nobody said is not represented as if somebody said it. The assessment prompt fetches slim projections of both files. Regenerate all four with python3 build/generate_principle_catalogs.py after editing either source.