Research crosswalks
Mappings are mechanism-level relations, not proof of equivalence or prevention. Unmapped labels remain explicit.
Retained aliases
- AF-AU-13: Untrusted task or tool text becomes a new authority grant. Resolves to AF-SE-01. Same third-party data-to-authority boundary; general authority wording retained as a variant.
- AF-LV-13: Recovery never re-enters the original task after success. Resolves to AF-LN-07. Same missing repair-to-original-mission continuation edge.
- AF-MM-10: Context compaction evicts load-bearing constraints. Resolves to AF-LN-03. Constraint-loss specialization of lossy summary replacing governing work state.
- AF-HT-04: Available authority is ignored and routine mechanics are returned to the operator. Resolves to AF-LN-14. Same operator-as-mechanical-relay dependency.
- AF-PH-01: Controller acknowledgment mistaken for physical achievement. Resolves to AF-TX-02. Physical specialization of acknowledgment promoted to achieved postcondition.
- AF-PH-05: Physical wear or consumption accumulates under repeatable commands. Resolves to AF-ID-10. Physical specialization of repeated secondary consequences behind an idempotent-looking state.
- AF-EV-03: Deterministic checker implements the wrong predicate. Resolves to AF-VR-03. Wrong/incomplete predicate is the same verification-specification gap.
- AF-EV-08: Evaluator shares the executor's blind spot or incentive. Resolves to AF-VR-15. Same common-source/common-mode false independence.
- AF-ID-11: Replayed result confused with present state. Resolves to AF-VR-05. Replayed historical outcome used as current-state evidence.
- AF-MM-08: Stale memory treated as the authoritative current state. Resolves to AF-VR-05. Memory-cache specialization of historical evidence used as current truth.
- AF-OB-05: Alert generated but not delivered to its real recipient. Resolves to AF-LV-15. Same locally recorded notification without actual delivery; general incident-alert variant retained.
- AF-HT-02: Approval details do not match the executed final payload. Resolves to AF-AU-05. Mutable payload specialization of approval not bound to the actually executed artifact.
Source labels
EFFECT26: A1: duplicate external effect
all eight published umbrella anomalies mapped
EFFECT26: A2: required effect absent at commit
all eight published umbrella anomalies mapped
EFFECT26: A3: unsafe undo of unresolved effect
all eight published umbrella anomalies mapped
EFFECT26: A4: aborted-workflow residue
all eight published umbrella anomalies mapped
EFFECT26: A5: effect released before branch resolution
all eight published umbrella anomalies mapped
EFFECT26: A6: committed effect depends on nonsurviving effect
all eight published umbrella anomalies mapped
EFFECT26: A7: unordered noncommuting effects
all eight published umbrella anomalies mapped
EFFECT26: A8: consequences survive local undo
all eight published umbrella anomalies mapped
MAST25: FM-1.1: task constraints not followed
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-1.2: role boundaries not followed
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-1.3: completed steps repeated
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-1.4: history lost
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-1.5: stopping criteria not recognized
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-2.1: dialogue restarted incorrectly
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-2.2: missing clarification
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-2.3: task derailment
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-2.4: necessary information withheld
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-2.5: peer input ignored
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-2.6: decision/action inconsistency
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-3.1: early task termination
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-3.2: verification absent or incomplete
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
MAST25: FM-3.3: incorrect verification
all fourteen labels mapped
Coordination labels do not authorize parallel Camden reasoning roots.
TOOLSCAN25: IAC: too few required calls
all seven labels mapped
TOOLSCAN25: IAV: invalid value or omitted required argument
all seven labels mapped
TOOLSCAN25: IAN: nonexistent argument name
all seven labels mapped
TOOLSCAN25: IAT: wrong argument type
all seven labels mapped
TOOLSCAN25: RAC: repeated calls
all seven labels mapped
TOOLSCAN25: IFN: nonexistent function
all seven labels mapped
TOOLSCAN25: IFE: malformed call format
all seven labels mapped
TOOLBENCHX26: contract drift
all five hazard families mapped
TOOLBENCHX26: invocation mismatch
all five hazard families mapped
TOOLBENCHX26: tool execution failure
all five hazard families mapped
TOOLBENCHX26: output representation drift
all five hazard families mapped
TOOLBENCHX26: conflicting source outputs
all five hazard families mapped
CHAOS26: ToolFailure
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: A2ATimeout
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: ToolLatency
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: A2ALatency
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: InfiniteLoop
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: ToolMisroute
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: AgentMisroute
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: ContextOverflow
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: OutputCorruption
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
CHAOS26: GuardrailBypass
all ten injected fault types mapped
Injected fault family, not automatically a separately observed production incident.
OWASP26: ASI01: goal hijack
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI02: tool misuse
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI03: identity and privilege abuse
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI04: supply-chain compromise
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI05: unexpected code execution
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI06: memory/context poisoning
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI07: insecure agent communication
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI08: cascading failures
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI09: human-agent trust exploitation
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
OWASP26: ASI10: rogue agents
all ten umbrella labels mapped
Mapped from the official launch article; umbrella categories overlap.
MEMFAIL26: summary/detail failure
four mechanism families mapped
MEMFAIL26: storage/update failure
four mechanism families mapped
MEMFAIL26: retrieval failure
four mechanism families mapped
MEMFAIL26: reasoning despite correct memory
four mechanism families mapped
AGENTLEAK26: final output
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
AGENTLEAK26: agent messages
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
AGENTLEAK26: tool input
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
AGENTLEAK26: tool output
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
AGENTLEAK26: shared memory
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
AGENTLEAK26: system logs
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
AGENTLEAK26: artifacts
all seven disclosure channels mapped
The paper does not evaluate every channel at the same scale.
RAJ26: owner: instruction/grader mismatch
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: excessive initiative
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: insufficient initiative
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: satisficing
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: task-instruction failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: reasoning error
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: unapproved irreversible action
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: sycophancy
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: missing domain knowledge
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: owner: value misalignment
Unmapped
outside a purely observable effect taxonomy
The source includes judgments about deliberation even with an apparently correct outcome. This catalog does not invent observable effect evidence or require private chain-of-thought disclosure. Observable stakeholder/constraint violations map to PL/AU/PR; the broader label remains a scope limitation.
RAJ26: grader: specification gaming
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: grader: evaluation awareness
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: third party: indirect injection
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: third party: contextual sycophancy
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: context: state tracking failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: context: goal drift
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: context: rationale erosion
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: missed write
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: stale state
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: overgeneralized rule
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: rationale erosion
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: pollution
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: redundancy
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: missed read
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: memory: retrieved constraint ignored
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: malformed arguments
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: low-quality arguments
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: wrong available tool
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: nonexistent tool
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: feedback neglected
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: recovery failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: tool: integration mistranslation
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: peer: delegation failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: peer: communication failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: subagent: delegation failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: subagent: communication failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: external environment: service failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: external environment: stale delivery
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: external environment: recovery failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: local environment: observation failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
RAJ26: local environment: recovery failure
role-specific label mapped
Mapped by mechanism; fault-bearing component remains a separate source axis.
AGENTEVAL26: scope error
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: unresolved ambiguity
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: omitted tool
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: missing verification
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: skipped prerequisite
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: dependency order violated
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: inefficient sequence
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: wrong tool category
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: wrong tool granularity
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: parameter type mismatch
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: parameter value wrong
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: required parameter absent
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: tool timeout
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: unhandled tool error
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: truncated context
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: output selectively omitted
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: fabricated output
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: results conflated
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: partial task called complete
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AGENTEVAL26: retry loop exited early
all visible Table 8 rows mapped; caption discrepancy retained
v1 Table 8 visibly contains 20 rows while its caption states 21; no missing row was invented.
AIRT26: interacting components produce policy violations
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: unfair multi-principal allocation
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: organizational knowledge loss
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: safety subordinated to operational priority
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: agent compromise
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: injected agent instructions
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: agent impersonation
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: workflow graph manipulated
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: poisoned agent provisioning
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: distributed jailbreak fragments
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: agentic supply chain
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: goal hijack
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: inter-agent trust escalation
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: computer-use visual attack
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: session contamination
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: MCP/plugin abuse
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: architecture/capability disclosure
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: insufficient transparency/accountability
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: parasocial reliance
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: amplified bias
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: user impersonation
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: unintelligible consent
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: hallucinated inputs or results
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: instruction misinterpretation
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: memory poisoning/theft
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: targeted knowledge-base poisoning
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: cross-domain injection
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: human-approval bypass
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: malicious or compromised function
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: incorrect permissions
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: resource exhaustion
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: insufficient isolation
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: excessive agency
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
AIRT26: data provenance lost
34 overview labels mapped at umbrella level
Umbrella mapping may cover only the observable workflow portion of a broader safety/social risk; it does not claim all proposed threat variants were reproduced.
MCPFAULT26: server dependencies
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: server platform mismatch
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: server packaging/deployment
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: server access synchronization
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: server resource handling
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: server logging
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: network configuration
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: API usage
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: server infrastructure
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool call/execution
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool discovery/registration
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool response handling
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool authorization
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool connection settings
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool connection synchronization
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool authentication
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: tool dependency
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host server configuration
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host LLM integration
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host dependency
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host connection synchronization
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host connection settings
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host/server configuration mismatch
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: session handling
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host logging
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: host authorization
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: hook configuration
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: documentation fault
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
MCPFAULT26: general programming fault
visible leaf-family mapping, not a CVE-level incident census
Figure 3 and detailed subtype text were inspected; source hierarchy counts are not added to the anomaly count.
AGFAULT26: LLM integration/configuration
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: provider API compatibility
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: token handling/tracking
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: LLM authentication
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: agent lifecycle and termination
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: state consistency
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: tool API and parameter handling
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: connection setup
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: authentication/authorization
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: database/resource handling
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: synchronization
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: logging/telemetry
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: persistence/state restoration
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: types/encoding/validation
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: dependency/import/install/resolver
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: platform/integration compatibility
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: exceptions/implementation defects
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: UI/visualization
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
AGFAULT26: documentation
grouped software fault coverage; not every source sublabel individually reproduced
Grouped at component/defect-family level. Source fault, symptom and proposed-cause taxonomies are not conflated.
Supplied labels
- lost acknowledgment / duplicate effect: AF-TX-01.
- missing committed effect: AF-TX-02, AF-AT-05.
- orphaned compensation: AF-CP-01.
- ambiguous timeout / late execution: AF-TX-03, AF-TX-04.
- polling desynchronization: AF-TX-06.
- delayed visibility: AF-TX-05.
- compound partial success: AF-AT-11.
- invocation mistranslation: AF-TX-10.
- LLM-minted idempotency key: AF-ID-01.
- premature externalization: AF-AT-03.
- contaminated speculation / discarded branch: AF-AT-03, AF-AT-04.
- out-of-order asynchronous result: AF-TX-07, AF-TX-09.
- partial multi-tool commit: AF-AT-05.
- TOCTOU: AF-CC-15.
- uncompensated residue: AF-CP-04.
- phantom compensation: AF-CP-06.
- cascading compensation failure: AF-CP-02, AF-CP-11.
- irreversibility without rollback: AF-CP-07, AF-AT-05.
- false inverse: AF-CP-07.
- conflicting externalizations: AF-CC-01.
- lost update: AF-CC-02.
- split-brain handoff: AF-CC-11.
- noncommuting operation order: AF-CC-01, AF-PL-02.
- dual write / missing outbox: AF-AT-01.
- stale conflict abort: AF-LV-08.
- verification theater: AF-VR-01.
- circular verification: AF-VR-02.
- verification blind spot: AF-VR-03.
- hallucinated completion: AF-VR-10, AF-PL-07.
- reality substitution: AF-VR-05.
- receipt without effect: AF-TX-02, AF-VR-04.
- effect without receipt: AF-TX-01, AF-LN-09.
- intention without execution: AF-VR-10.
- fail-plausible: AF-VR-11.
- specification gaming: AF-EV-02.
- cross-source conflict: AF-VR-07.
- lineage amputation: AF-LN-02.
- ghost lineage: AF-LN-01.
- summary substitution: AF-LN-03.
- missed write: AF-MM-15.
- memory rationale erosion: AF-MM-05.
- authority inflation: AF-AU-01.
- stale authority: AF-AU-02.
- privilege inheritance: AF-AU-03.
- delayed execution bypass: AF-AU-05, AF-AU-11.
- approval description laundering: AF-AU-07.
- excessive agency: AF-AU-01, AF-AU-04.
- identity-dependent worker: AF-RP-07, AF-MM-15.
- personality/model coupling: AF-RP-08.
- zombie predecessor: AF-CC-09, AF-CC-10.
- silent death: AF-LV-01.
- infinite recovery: AF-LV-07.
- continuation after stop: AF-AU-02, AF-TX-03.
- step repetition: AF-RP-03, AF-PL-13.
- premature loop exit: AF-PL-07.
- dead consumer wait: AF-LV-03, AF-LV-04.
- procedure capture: AF-PL-05.
- safety substitution: AF-PL-06.
- goal drift: AF-PL-08.
- indirect prompt injection: AF-SE-01.
- poisoned fixture or beacon: AF-SE-02, AF-SC-02.
- goal hijack: AF-SE-05.
- memory poisoning: AF-SE-04.
- session contamination: AF-SE-05.
- MCP cross-tool abuse: AF-SE-02, AF-SE-09.
- architecture/secret disclosure: AF-SE-12.
- inter-agent spoofing: AF-SE-06.
- visual injection: AF-SE-03.
- rogue self-propagation: AF-SE-14.
- command interpolation RCE: AF-SE-07.
- human trust exploitation: AF-AU-07, AF-HT-05.
- incorrect tool selection: AF-PX-13.
- tool hallucination: AF-PX-03.
- malformed arguments: AF-PX-04.
- suboptimal arguments: AF-PX-14.
- tool feedback neglect: AF-PX-16.
- tool recovery failure: AF-LV-07, AF-LV-08.
- specification drift: AF-PX-11.
- output drift: AF-PX-15.
- memory-induced tool drift: AF-MM-12.
- wrong environment: AF-BI-01.
- memory following failure: AF-MM-02.
- missed memory read: AF-MM-01.
- memory staleness: AF-VR-05, AF-MM-04.
- overgeneralization: AF-MM-05.
- memory pollution: AF-MM-09.
- temporal memory contamination: AF-MM-13.
- context rot: AF-MM-11.
- retrieval/embedding drift: AF-MM-07.
- collective hallucination: AF-VR-15.
- context overflow: AF-EC-05, AF-LN-03.
- disobey task specification: AF-AU-01, AF-PL-07.
- disobey role specification: AF-AU-03, AF-AU-04.
- conversation reset: AF-RP-09, AF-LN-03.
- failure to clarify: AF-PL-11.
- withheld peer information: AF-PL-12.
- ignored peer input: AF-PL-12.
- reasoning/action mismatch: AF-PL-04.
- incorrect verifier assignment: AF-VR-02, AF-VR-15.
- delegation black hole: AF-LV-01, AF-LN-04.
- multi-agent cascade: AF-VR-15, AF-LV-09, AF-PH-04.
- timezone/DST: AF-TM-01, AF-TM-02.
- budget called success: AF-LV-11, AF-PL-07.
- rate-limit/domain confusion: AF-TX-11, AF-EN-10.
- cost runaway: AF-EC-01.
- context hoarding: AF-EC-05.
- serving cache overhead: AF-EC-07.
- approval fatigue: AF-HT-01.
- unstated expectation mismatch: AF-VR-03, AF-EV-04.
- contextual sycophancy: AF-HT-05.
- error swallowing: AF-OB-01.
- forensic blind spot: AF-OB-03.
- silent guardrail bypass: AF-VR-12, AF-SE-13.
- output corruption: AF-TX-10, AF-EN-09.
- platform quirk: AF-EN-02.
- design-assumption mismatch: AF-EN-04, AF-EV-11.
- unmonitored live consumers: AF-EN-11.
- stale harness event: AF-TM-05, AF-LV-04.
- unobservable tool with no outcome or idempotency primitive: Unmapped. Interface limitation, not automatically a failure. A truthful UNKNOWN and fenced conflicting retry may be the correct outcome. See the guarantee-boundary analysis.
- KV-cache identity splicing or cross-tenant contamination: Unmapped. Not established by the cited tool-progress paper. Actual cache isolation defects would map to PR-04/EN lifecycle boundaries, but no specific observed KV incident is claimed here.