Rule reference
Per-rule pages for the AAK rule registry. The canonical source of truth
is agent_audit_kit/rules/builtin.py — these pages exist to give
operators a click-through reference with the full description, the
remediation recipe, and the linked CVE/OWASP/AICM mapping.
The pages are written by hand for high-traffic rules (CVE-driven, public
SLA) and from RuleDefinition data for the rest. v0.3.5 ships the
first batch — expect coverage to fill in over subsequent releases.
v0.3.84 (2026-08-19) — net-new
| Rule | Severity | Class | CVE / source |
|---|---|---|---|
| AAK-COMPOSE-001 | HIGH | COMPOSITION | CompoSkill arXiv:2608.16246 |
| AAK-COMPOSE-002 | HIGH | COMPOSITION | ColluSkill arXiv:2608.09732 |
| AAK-COMPOSE-003 | MEDIUM | COMPOSITION | CompoSkill arXiv:2608.16246 |
v0.3.43 (2026-07-04) — net-new
| Rule | Severity | Class | CVE / source |
|---|---|---|---|
| AAK-MCP-AUTH-PATHTRAVERSAL-001 | CRITICAL | MCP_CONFIG | CVE-2026-52830 |
v0.3.5 (2026-04-25) — net-new
| Rule | Severity | Class | CVE / source |
|---|---|---|---|
| AAK-LANGCHAIN-SSRF-REDIR-001 | HIGH | TRANSPORT_SECURITY | CVE-2026-41481 |
| AAK-SSRF-TOCTOU-001 | MEDIUM | TRANSPORT_SECURITY | CVE-2026-41488 |
| AAK-AZURE-MCP-001 | HIGH | MCP_CONFIG | CVE-2026-32211 |
| AAK-TOXICFLOW-001 | HIGH | TOOL_POISONING | Snyk Agent Scan parity (feature-flagged) |
Coverage
Full rule list with one-line descriptions: docs/rules.md.
OWASP Agentic Top 10 2026 mapping: docs/owasp-agentic-coverage.md.
OWASP MCP Top 10 mapping: docs/owasp-mapping.md.