Problem
TRACE is being mapped into OpenCRE, which cross-links a topic to ASVS, CWE, ISO 27001, NIST 800-53, SAMM and the OWASP AI Exchange from a single stable link.
Working the first pass surfaced a prerequisite we do not meet. OpenCRE links into a stable anchor for one specific requirement and regenerates those links from its API in CI. Our spec pages have no stable per-primitive anchor, so an external standard can only link to the page.
What is needed
Durable anchor IDs for the primitives an external standard would actually cite, starting with:
- Trust levels L0 / L1 / L2 in
docs/trust-levels.md
- The evidence record structure in
docs/schema.md
Durability is the point. OpenCRE's pitch is that its links do not rot, so an anchor that shifts when a heading is reworded defeats the purpose.
Wider than this repo
The same gap applies to every agentrust-io spec carrying a control an external framework would reference: cmcp (tool invocation control), ca2a (inter-agent trust), agent-manifest (agent identity, capability manifest), agentic-usage-control (continuous usage control), weight-custody-manifest (weight custody).
Proposing we settle the convention here first and then apply it across the others rather than inventing a different scheme per repo.
Context
First-pass mapping found 25 of 30 controls land on existing CREs and 19 look like genuine additions. Discussion with the OpenCRE maintainers is in flight.
Problem
TRACE is being mapped into OpenCRE, which cross-links a topic to ASVS, CWE, ISO 27001, NIST 800-53, SAMM and the OWASP AI Exchange from a single stable link.
Working the first pass surfaced a prerequisite we do not meet. OpenCRE links into a stable anchor for one specific requirement and regenerates those links from its API in CI. Our spec pages have no stable per-primitive anchor, so an external standard can only link to the page.
What is needed
Durable anchor IDs for the primitives an external standard would actually cite, starting with:
docs/trust-levels.mddocs/schema.mdDurability is the point. OpenCRE's pitch is that its links do not rot, so an anchor that shifts when a heading is reworded defeats the purpose.
Wider than this repo
The same gap applies to every agentrust-io spec carrying a control an external framework would reference:
cmcp(tool invocation control),ca2a(inter-agent trust),agent-manifest(agent identity, capability manifest),agentic-usage-control(continuous usage control),weight-custody-manifest(weight custody).Proposing we settle the convention here first and then apply it across the others rather than inventing a different scheme per repo.
Context
First-pass mapping found 25 of 30 controls land on existing CREs and 19 look like genuine additions. Discussion with the OpenCRE maintainers is in flight.