Skip to content

[THR-002] Threat-register identity and status #51

Description

@Hacks4Snacks

Roadmap priority: P1/P2

Goal: Keep manual, currently generated, persisted generated, and stale entries explicit while
providing stable author-controlled identity.

  • Add optional caller-supplied manual ids in the reserved manual: namespace, with canonical
    validation, deterministic reuse, and collision rejection across CLI/API/MCP/Studio.
  • Decide whether Critical is supported; preserve it without silent downgrade and define behavior
    when a foreign MTMT knowledge base permits only High/Medium/Low.
  • Compute separate current-generated, persisted-generated, manual, and stale-generated counts
    using the same effective rule bundle and model fingerprint.
  • Make stale entries inspectable and explicitly removable/resettable; never delete triage merely
    because a rule no longer fires.
  • Add origin/status fields and split counts to open --json, human output, reports, and MCP.

Acceptance criteria:

  • Stable manual identity survives tmforge-json and .tm7 round trips.
  • Stale detection is deterministic and reports pack/fingerprint mismatch instead of guessing when the
    effective rules are unavailable.
  • Every public surface distinguishes manual, current generated, persisted generated, and stale
    generated entries consistently.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions