3.0
- Adds
full-system,bounded-subsystem, andartifact-onlyreview profiles with claim evidence. - Requires a traditional-security applicability result. Only a confirmed artifact-only review may mark the whole traditional phase not applicable.
- Replaces six-letter coverage for every element with typed STRIDE: process, actor, store, and flow denominators.
- Adds bounded abuse-case and operational-event passes before PHANTOM-B.
- Adds a composition denominator for retrieval, identity delegation, tool actuation, output consumption, feedback loops, and shared stores.
- Adds
source_manifest, the source registry, and evidence-bound external references. Affected CVE and NVD mappings require supplier, product, version, and component evidence. - Moves review importance onto each threat. The allowed factors cite evidence and do not infer likelihood, impact, severity, or residual risk.
- Adds an SRF L1 to L5 coverage audit and optional vertical obligation, control candidate, and acceptance-authority joins.
- Expands the gold corpus from five to ten architectures, including traditional-only, mixed, agent-actuation, artifact-only, and clinical safety cases.
- Extends markdown, JSON, CSV, and Mermaid exports while preserving one threat id across projections.
- The page has one-chat shortcuts for Track A, Track B, and Track C. Optional fields stay on the page, not in the copied text. Omitted catalog, SRF, and vertical inputs are not applicable. The model does not ask for later input and does not wait for continue.
- The page starts with a three-step Track A path. Track B, Track C, and optional JSON examples sit behind disclosure. Copy next starts at P-context. Optional fields stay on the page, not in the copied shortcut text.
P-reportmarkdown projects every threat, position, and control id in grouped tables.P-export-mdemits that stored string.
Schema: v3 JSON Schema. Evaluation contract: rubric.md.