feat(chain,skills): close benchmark misses — CRLF-on-Location, second-order precondition; condense BENCHMARK

The 13-target benchmark left 3 misses. Root-caused and fixed the two that were
coverage gaps (the third was single-run variance, already handled by the
session-limit fix):

- CRLF header injection (web_crlf_header_go): the agent confirmed the open
  redirect on /go?url= and stopped; the CRLF payload was never generated. The
  open_redirect skill now tests %0d%0a header injection on the SAME param, and
  CHAIN_DOCTRINE says a param landing in a Location header must also be tested
  for response splitting. chain.rs: CWE-113/93/644 now provide capabilities;
  attack_graph maps their kill-chain stage.
- Second-order SQLi (web_sqli_second_order): the sink was behind /admin, which
  the customer account could not reach. CHAIN_DOCTRINE now teaches the
  precondition pattern (store the payload, trigger from every identity, escalate
  first if the trigger page needs a role you lack, else report as a chained
  lead). chain.rs: CWE-564 requires PrivilegedContext so it chains after privesc.

BENCHMARK.md: added the TypeSafe calibrated-adjudication row; dropped the
"genuinely ahead" prose (the table is the summary); condensed the rest
188 -> 89 lines; refreshed scale (27 validators, 47 modules, 383 tests).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 5 committed 2026-09-20 12:42:36 -03:00
1 parent dff2e3c0f0
commit fce86522ca
5 files changed
+38 -119

No files matched your search

@@ -45,6 +45,9 @@ fn map_cwe(cwe: &str) -> (&'static str, &'static str, &'static str) {
// Session fixation.
384 => ("A07:2021-Auth-Failures", "T1539", "credential-access"),
601 => ("A01:2021-Broken-Access-Control", "T1566", "initial-access"),
113 | 93 => ("A03:2021-Injection", "T1557", "initial-access"),
644 => ("A03:2021-Injection", "T1557", "initial-access"),
564 => ("A03:2021-Injection", "T1190", "execution"),
352 => ("A01:2021-Broken-Access-Control", "T1189", "execution"),
434 => ("A04:2021-Insecure-Design", "T1505.003", "execution"),
1321 | 915 => ("A08:2021-Software-Data-Integrity", "T1059", "execution"),