One-pass CAPEC ingestion → generate per-domain attack pattern taxonomies for PromptKit security audits
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 38/100
Direzione di ricerca
Inizia leggendo l’implementazione dell’ingestione di CWE da #228/#229, quindi esamina i download di CAPEC e i riferimenti allo schema. Distribuisci il lavoro tra .github/prompts/, .github/skills/, scripts/ingest-capec.py, data/capec/, taxonomies/ e manifest.yaml. Il lavoro è completato quando una singola esecuzione produce tassonomie CAPEC versionate per dominio, con riferimenti incrociati a CWE e verifica.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Problem / Motivation
PromptKit security audits currently scope what weakness to look for (via CWE taxonomies from #228), but do not scope how attackers exploit those weaknesses. CAPEC (Common Attack Pattern Enumeration and Classification) is the complementary MITRE database that classifies attack patterns — the adversary-side view of CWE weaknesses.
Adding CAPEC-derived taxonomies would let security audit prompts guide the LLM with domain-specific attack patterns, improving threat modeling and exploit path analysis.
CAPEC entries cross-reference CWE IDs, so the two taxonomy sets can be composed: "look for these weaknesses (CWE) using these attack patterns (CAPEC)."
Goal
Implement a pipeline (modeled on the CWE ingestion skill from #228/#229) that:
- Ingests the official CAPEC corpus (versioned XML) from MITRE: https://capec.mitre.org/data/downloads.html
- In a single run, generates per-domain CAPEC taxonomies (reusing the same 13-domain registry from #228).
- Cross-references CWE IDs in each CAPEC entry to enable CWE↔CAPEC composition at audit time.
Deliverables
/ingest-capec-taxonomiesprompt file (.github/prompts/) and matching CLI skill (.github/skills/)- Reusable Python script at
scripts/ingest-capec.py - Per-domain taxonomy files:
taxonomies/capec-<domain>.md - Normalized data:
data/capec/<version>/ - Updated
manifest.yaml
Design Notes
- Same architecture as CWE ingestion: 6-phase pipeline (Acquisition → Normalization → Domain Mapping → Taxonomy Generation → Integration → Verification)
- Same domain registry: Reuse the 13 domains from #228. Consider extracting the registry to a shared
data/domain-registry.jsonso both skills reference the same list. - CAPEC XML schema differs from CWE — separate parsing logic required. Key fields: attack pattern ID, name, abstraction, prerequisites, related weaknesses (CWE IDs), execution flow, consequences.
- Domain mapping: Use CAPEC
Related_WeaknessCWE cross-references as the primary signal (map CAPEC entries to domains via their associated CWEs). Fall back to CAPEC-specificPrerequisitesandSkills_Requiredfields. - Separate skill from CWE ingestion — different input format, different semantics (attack patterns vs weakness classes), different parsing.
External References
- CAPEC downloads: https://capec.mitre.org/data/downloads.html
- CAPEC schema: https://capec.mitre.org/documents/schema/
- CAPEC↔CWE mapping: cross-references embedded in CAPEC XML
Related_Weaknesselements
Non-Goals
- Do not merge with the CWE ingestion skill — keep as separate, composable skills.
- Do not claim exploitability of specific code from attack patterns.
- Do not fork or maintain a separate CAPEC; track upstream MITRE versions.
Relationship to Other Issues
- Depends on #228 for the domain registry and taxonomy file conventions.
- CAPEC taxonomies complement CWE taxonomies — together they scope both the "what" and "how" of security audits.
- Lingua principale
- JavaScript
- Stelle
- 109
- Fork
- 23
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di microsoft/PromptKit
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
-
Investigate: structured feedback classification as a cross-cutting protocolForse di nuovo libera @abeltrano l’ha presa 186 giorni fa e non c’è nessuna pull request aperta. Apertaenhancement
Tutte le issue di microsoft/PromptKit
Issue simili
-
[Feature]:Apertaenhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 73/100
Uuriko/project-room#1554 ·
I maintainer di solito rispondono entro 1 giorno
-
automated issue report
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
lirantal/discoprint#36 ·
I maintainer di solito rispondono entro 1 giorno
-
accepting PR Content:HTML
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
mdn/content#45988 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
pnpm/pnpm#16635 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno