AVE Agentic Vulnerability Enumeration
Crosswalks

Crosswalks

The field has many scanners and no shared vocabulary — independent studies find different tools barely agree on what they flag. AVE is the neutral reference they can all map to. These crosswalks let findings from any tool resolve to a common AVE id, so results become comparable across the ecosystem.

SkillSpector → AVE

NVIDIA SkillSpector organizes detection as 16 categories across 64 patterns. Each category maps to one or more AVE behavioral classes. Gaps marked “—” are categories with no distinct AVE class (or scanner-internal mechanics, not a vulnerability class).

SkillSpector categoryAVE id(s)
prompt injectionAVE-2026-00002, AVE-2026-00013
data exfiltrationAVE-2026-00026
privilege escalationAVE-2026-00045
supply chainAVE-2026-00042
excessive agencyAVE-2026-00011, AVE-2026-00048
output handlingAVE-2026-00026
system prompt leakageAVE-2026-00013
memory poisoningAVE-2026-00013
tool misuseAVE-2026-00045
rogue agentAVE-2026-00048
trigger abuseAVE-2026-00001
dangerous code (AST)AVE-2026-00024
taint trackingAVE-2026-00050
YARA signatures— (engine, not a class)
MCP least privilegeAVE-2026-00011
MCP tool poisoningAVE-2026-00002, AVE-2026-00045

ClawScan → AVE

ClawScan finding types mapped to AVE ids. Source dataset: OpenClaw/clawhub-security-signals.

ClawScan finding typeAVE id
instruction-overrideAVE-2026-00002
remote-fetchAVE-2026-00001
post-install-mutationAVE-2026-00042
egress-to-unknown-hostAVE-2026-00026
cross-server-callAVE-2026-00045
header-tamperAVE-2026-00049
oauth-misconfigAVE-2026-00051
type-spoofAVE-2026-00024

AVE → OWASP · MITRE ATLAS

Every AVE record maps to the frameworks teams already trust. Generated from the record set.

AVE idAttack classOWASP MCPOWASP AgenticMITRE ATLAS

Maintain a scanner? Map your finding types to AVE →