{
  "version": "1.0.0",
  "verifiedOn": "2026-08-21",
  "sources": [
    {
      "id": "S01", "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)",
      "url": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final", "relatedUrl": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf", "sourceType": "primary", "publisher": "National Institute of Standards and Technology",
      "publishedOn": "2025-03-24", "correctedOn": "2025-04-01", "verifiedOn": "2026-08-21", "documentStatus": "NIST Trustworthy and Responsible AI report",
      "limitations": "A general adversarial-machine-learning taxonomy; it does not certify an agent implementation or prescribe this mapper's control set."
    },
    {
      "id": "S02", "title": "Strengthening AI Agent Hijacking Evaluations",
      "url": "https://www.nist.gov/news-events/news/2025/01/technical-blog-strengthening-ai-agent-hijacking-evaluations", "sourceType": "primary", "publisher": "National Institute of Standards and Technology",
      "publishedOn": "2025-01-17", "verifiedOn": "2026-08-21", "documentStatus": "NIST technical blog",
      "limitations": "Evaluation guidance and research framing, not a production assurance standard or proof that a specific control blocks every attack."
    },
    {
      "id": "S03", "title": "OWASP Top 10 for Agentic Applications for 2026",
      "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/", "sourceType": "primary", "publisher": "OWASP GenAI Security Project",
      "publishedOn": "2025-12-09", "verifiedOn": "2026-08-21", "documentStatus": "Community risk taxonomy",
      "limitations": "A prioritized risk awareness resource, not certification, endorsement, a complete implementation specification or evidence that a deployment is secure."
    },
    {
      "id": "S04", "title": "Securing Agentic Applications Guide 1.0",
      "url": "https://genai.owasp.org/resource/securing-agentic-applications-guide-1-0/", "sourceType": "primary", "publisher": "OWASP GenAI Security Project",
      "publishedOn": "2025-07-27", "verifiedOn": "2026-08-21", "documentStatus": "Community implementation guide",
      "limitations": "General guidance that requires system-specific threat modeling, validation and ownership; mapping it here does not create OWASP conformance."
    },
    {
      "id": "S05", "title": "Model Context Protocol Authorization",
      "url": "https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization", "sourceType": "primary", "publisher": "Model Context Protocol",
      "publishedOn": "2026-07-28", "verifiedOn": "2026-08-21", "documentStatus": "Protocol specification, 2026-07-28 revision",
      "limitations": "Scoped to MCP authorization behavior; it does not cover every application, model, memory, tool or supply-chain control in this mapper."
    },
    {
      "id": "S06", "title": "Accelerating the Adoption of Software and AI Agent Identity and Authorization",
      "url": "https://csrc.nist.gov/pubs/other/2026/02/05/accelerating-the-adoption-of-software-and-ai-agent/ipd", "sourceType": "primary", "publisher": "NIST National Cybersecurity Center of Excellence",
      "publishedOn": "2026-02-05", "verifiedOn": "2026-08-21", "documentStatus": "Initial public draft concept paper",
      "limitations": "An initial public draft and project concept, not final NIST guidance or a conformity assessment."
    },
    {
      "id": "S07", "title": "Supply-chain Levels for Software Artifacts specification v1.2",
      "url": "https://slsa.dev/spec/v1.2/", "sourceType": "primary", "publisher": "SLSA",
      "publishedOn": "2025-11-24", "verifiedOn": "2026-08-21", "documentStatus": "SLSA specification v1.2",
      "limitations": "Software-artifact provenance guidance; a provenance statement is useful only when verified against appropriate expectations and a trusted root."
    },
    {
      "id": "S08", "title": "Secure Software Development Practices for Generative AI and Dual-Use Foundation Models (NIST SP 800-218A)",
      "url": "https://csrc.nist.gov/pubs/sp/800/218/a/final", "relatedUrl": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-218A.pdf", "sourceType": "primary", "publisher": "National Institute of Standards and Technology",
      "publishedOn": "2024-07-26", "verifiedOn": "2026-08-21", "documentStatus": "NIST Special Publication",
      "limitations": "Secure development practices for model producers and acquirers; it does not validate a particular dependency or agent release."
    },
    {
      "id": "S09", "title": "OWASP Top 10 for Large Language Model Applications 2026",
      "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/", "sourceType": "primary", "publisher": "OWASP GenAI Security Project",
      "publishedOn": "2026-08-03", "verifiedOn": "2026-08-21", "documentStatus": "Community risk taxonomy",
      "limitations": "An LLM application risk taxonomy rather than an agent-specific certification, test result or complete control catalog."
    },
    {
      "id": "S10", "title": "CVE-2025-32711: Microsoft 365 Copilot information disclosure vulnerability",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32711", "relatedUrl": "https://nvd.nist.gov/vuln/detail/CVE-2025-32711", "sourceType": "primary", "publisher": "Microsoft Security Response Center",
      "publishedOn": "2025-06-11", "verifiedOn": "2026-08-21", "documentStatus": "Vendor vulnerability record",
      "limitations": "A bounded record for one responsibly disclosed vulnerability; proof-of-concept behavior must not be generalized into confirmed exploitation, customer breach or universal control effectiveness."
    },
    {
      "id": "S11", "title": "Breaking down ‘EchoLeak’",
      "url": "https://www.catonetworks.com/blog/breaking-down-echoleak/", "sourceType": "researcher disclosure", "publisher": "Cato Networks / Aim Labs research",
      "publishedOn": "2025-05-31", "verifiedOn": "2026-08-21", "documentStatus": "Researcher technical report",
      "limitations": "Supports the demonstrated crafted-email, XPIA, markdown-reference and Teams-proxy proof-of-concept chain and quotes Microsoft reporting no affected customers; it does not establish in-the-wild exploitation or a customer breach."
    },
    {
      "id": "S12", "title": "OWASP Artificial Intelligence Security Verification Standard 1.0",
      "url": "https://owasp.org/www-project-artificial-intelligence-security-verification-standard-aisvs-docs/", "sourceType": "primary", "publisher": "OWASP",
      "publishedOn": "2026-06-24", "verifiedOn": "2026-08-21", "documentStatus": "Standard",
      "limitations": "The listed AISVS 1.0 identifiers are a curated editorial crosswalk to relevant requirements; they are not an AISVS assessment, conformance result, certification or OWASP endorsement."
    }
  ]
}
