Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

One-pass CAPEC ingestion → generate per-domain attack pattern taxonomies for PromptKit security audits

Aperta
#231 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
38/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
python
Ambito
security, tooling

Direzione di ricerca

Inizia leggendo l’implementazione dell’ingestione di CWE da #228/#229, quindi esamina i download di CAPEC e i riferimenti allo schema. Distribuisci il lavoro tra .github/prompts/, .github/skills/, scripts/ingest-capec.py, data/capec/, taxonomies/ e manifest.yaml. Il lavoro è completato quando una singola esecuzione produce tassonomie CAPEC versionate per dominio, con riferimenti incrociati a CWE e verifica.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Problem / Motivation

PromptKit security audits currently scope what weakness to look for (via CWE taxonomies from #228), but do not scope how attackers exploit those weaknesses. CAPEC (Common Attack Pattern Enumeration and Classification) is the complementary MITRE database that classifies attack patterns — the adversary-side view of CWE weaknesses.

Adding CAPEC-derived taxonomies would let security audit prompts guide the LLM with domain-specific attack patterns, improving threat modeling and exploit path analysis.

CAPEC entries cross-reference CWE IDs, so the two taxonomy sets can be composed: "look for these weaknesses (CWE) using these attack patterns (CAPEC)."

Goal

Implement a pipeline (modeled on the CWE ingestion skill from #228/#229) that:

  1. Ingests the official CAPEC corpus (versioned XML) from MITRE: https://capec.mitre.org/data/downloads.html
  2. In a single run, generates per-domain CAPEC taxonomies (reusing the same 13-domain registry from #228).
  3. Cross-references CWE IDs in each CAPEC entry to enable CWE↔CAPEC composition at audit time.

Deliverables

  • /ingest-capec-taxonomies prompt file (.github/prompts/) and matching CLI skill (.github/skills/)
  • Reusable Python script at scripts/ingest-capec.py
  • Per-domain taxonomy files: taxonomies/capec-<domain>.md
  • Normalized data: data/capec/<version>/
  • Updated manifest.yaml

Design Notes

  • Same architecture as CWE ingestion: 6-phase pipeline (Acquisition → Normalization → Domain Mapping → Taxonomy Generation → Integration → Verification)
  • Same domain registry: Reuse the 13 domains from #228. Consider extracting the registry to a shared data/domain-registry.json so both skills reference the same list.
  • CAPEC XML schema differs from CWE — separate parsing logic required. Key fields: attack pattern ID, name, abstraction, prerequisites, related weaknesses (CWE IDs), execution flow, consequences.
  • Domain mapping: Use CAPEC Related_Weakness CWE cross-references as the primary signal (map CAPEC entries to domains via their associated CWEs). Fall back to CAPEC-specific Prerequisites and Skills_Required fields.
  • Separate skill from CWE ingestion — different input format, different semantics (attack patterns vs weakness classes), different parsing.

External References

Non-Goals

  • Do not merge with the CWE ingestion skill — keep as separate, composable skills.
  • Do not claim exploitability of specific code from attack patterns.
  • Do not fork or maintain a separate CAPEC; track upstream MITRE versions.

Relationship to Other Issues

  • Depends on #228 for the domain registry and taxonomy file conventions.
  • CAPEC taxonomies complement CWE taxonomies — together they scope both the "what" and "how" of security audits.
Lingua principale
JavaScript
Stelle
109
Fork
23
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/PromptKit

Tutte le issue di microsoft/PromptKit

Issue simili

Altre issue su JavaScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.