[
  {
    "id": "nist-ai-rmf-public-framework-candidate",
    "title": "NIST AI Risk Management Framework",
    "url": "https://www.nist.gov/itl/ai-risk-management-framework",
    "allowed_origin": "https://www.nist.gov",
    "allowed_path_prefix": "/itl/ai-risk-management-framework",
    "source_type": "public_standards_or_regulatory",
    "trust_label": "candidate_owner_review_required",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_context_only_not_package_authority",
    "source_owner": "National Institute of Standards and Technology",
    "approved_by": "not_approved",
    "approval_status": "candidate_only",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "query_terms": [
      "AI risk management",
      "trustworthy AI",
      "governance framework",
      "risk framework"
    ],
    "retrieval_enabled": false,
    "notes": "Accepted as a candidate-only public standards or regulator-adjacent source. Do not configure this entry in production. This entry is not approved package authority.",
    "public_availability": "public_https_no_login_observed",
    "proposed_approver": "package_governance_owner_review_required",
    "review_cadence": "before production enablement and at least quarterly if approved later",
    "retrieval_safety": "HTTPS-only public HTML page, exact origin, exact path prefix, credentials omitted, no login observed.",
    "redirect_behavior": "Live check observed zero redirects. Future redirects must remain inside the allowed origin and path prefix.",
    "content_type_suitability": "Live check returned text/html, which is compatible with the current server-side adapter.",
    "expected_claim_usefulness": "Comparison and interpretation for AI risk management language when approved package support already exists.",
    "limitations_and_bias_risks": "Voluntary public framework context can be mistaken for policy approval or enterprise authorization if source lanes are not preserved.",
    "suitability": {
      "comparison": true,
      "interpretation": true,
      "implementation_screening": false,
      "decision_support": false
    },
    "must_remain_candidate_only": true,
    "reason_for_inclusion": "Official public AI risk management framework material relevant to package governance and source-grounded assistant posture.",
    "live_verification": {
      "checked_date": "2026-06-24",
      "method": "curl unauthenticated metadata fetch with redirects followed for final status metadata",
      "final_url": "https://www.nist.gov/itl/ai-risk-management-framework",
      "status_code": 200,
      "content_type": "text/html; charset=UTF-8",
      "redirect_count": 0
    }
  },
  {
    "id": "owasp-genai-llm-top-10-candidate",
    "title": "OWASP Top 10 for LLMs and Gen AI Apps",
    "url": "https://genai.owasp.org/llm-top-10/",
    "allowed_origin": "https://genai.owasp.org",
    "allowed_path_prefix": "/llm-top-10/",
    "source_type": "candidate_public_documentation",
    "trust_label": "candidate_owner_review_required",
    "freshness_label": "periodic_review_required",
    "claim_boundary": "current_public_context_only_not_package_authority",
    "source_owner": "OWASP Foundation GenAI Security Project",
    "approved_by": "not_approved",
    "approval_status": "candidate_only",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "query_terms": [
      "LLM application security",
      "prompt injection",
      "secure AI application",
      "generative AI risk"
    ],
    "retrieval_enabled": false,
    "notes": "Accepted as a candidate-only public LLM application security source. Do not configure this entry in production. This entry is not approved package authority.",
    "public_availability": "public_https_no_login_observed",
    "proposed_approver": "package_governance_owner_review_required",
    "review_cadence": "before production enablement and at least quarterly if approved later",
    "retrieval_safety": "HTTPS-only public HTML page, exact origin, narrow project path prefix, credentials omitted, no login observed.",
    "redirect_behavior": "Live check observed zero redirects. Future redirects must remain inside the allowed origin and path prefix.",
    "content_type_suitability": "Live check returned text/html, which is compatible with the current server-side adapter.",
    "expected_claim_usefulness": "Comparison, interpretation, and implementation screening for secure LLM application risk categories when approved package support already exists.",
    "limitations_and_bias_risks": "Community project material can change and may be broader than this package's field guidance scope.",
    "suitability": {
      "comparison": true,
      "interpretation": true,
      "implementation_screening": true,
      "decision_support": false
    },
    "must_remain_candidate_only": true,
    "reason_for_inclusion": "Documentation-grade public secure LLM application guidance relevant to source-grounded assistant boundaries.",
    "live_verification": {
      "checked_date": "2026-06-24",
      "method": "curl unauthenticated metadata fetch with redirects followed for final status metadata",
      "final_url": "https://genai.owasp.org/llm-top-10/",
      "status_code": 200,
      "content_type": "text/html; charset=UTF-8",
      "redirect_count": 0
    }
  },
  {
    "id": "openai-api-pricing-docs-candidate",
    "title": "OpenAI API Pricing",
    "url": "https://developers.openai.com/api/docs/pricing",
    "allowed_origin": "https://developers.openai.com",
    "allowed_path_prefix": "/api/docs/pricing",
    "source_type": "public_official_documentation",
    "trust_label": "candidate_owner_review_required",
    "freshness_label": "time_sensitive_review_required",
    "claim_boundary": "current_public_reference_only_not_package_authority",
    "source_owner": "OpenAI developer documentation",
    "approved_by": "not_approved",
    "approval_status": "candidate_only",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "query_terms": [
      "token pricing",
      "API pricing",
      "model cost",
      "token cost accounting"
    ],
    "retrieval_enabled": false,
    "notes": "Accepted as a candidate-only public vendor documentation source for token and cost reference context. Do not configure this entry in production. This entry is not approved package authority.",
    "public_availability": "public_https_no_login_observed",
    "proposed_approver": "package_governance_owner_review_required",
    "review_cadence": "before production enablement and before each pricing-sensitive production use if approved later",
    "retrieval_safety": "HTTPS-only public HTML page, exact origin, exact docs path prefix, credentials omitted, no login observed.",
    "redirect_behavior": "Live check observed zero redirects. Future redirects must remain inside the allowed origin and path prefix.",
    "content_type_suitability": "Live check returned text/html, which is compatible with the current server-side adapter.",
    "expected_claim_usefulness": "Token and cost accounting reference when package-supported tokenomics guidance needs current vendor context.",
    "limitations_and_bias_risks": "Vendor pricing is time-sensitive, provider-specific, and not neutral industry evidence. It must not be used as a billing guarantee or vendor endorsement.",
    "suitability": {
      "comparison": true,
      "interpretation": false,
      "implementation_screening": true,
      "decision_support": false
    },
    "must_remain_candidate_only": true,
    "reason_for_inclusion": "Official vendor documentation relevant to model behavior and token or cost accounting posture.",
    "live_verification": {
      "checked_date": "2026-06-24",
      "method": "curl unauthenticated metadata fetch with redirects followed for final status metadata",
      "final_url": "https://developers.openai.com/api/docs/pricing",
      "status_code": 200,
      "content_type": "text/html; charset=utf-8",
      "redirect_count": 0
    }
  },
  {
    "id": "cloudflare-workers-limits-docs-candidate",
    "title": "Cloudflare Workers Limits",
    "url": "https://developers.cloudflare.com/workers/platform/limits/",
    "allowed_origin": "https://developers.cloudflare.com",
    "allowed_path_prefix": "/workers/platform/limits/",
    "source_type": "public_official_documentation",
    "trust_label": "candidate_owner_review_required",
    "freshness_label": "time_sensitive_review_required",
    "claim_boundary": "current_public_reference_only_not_package_authority",
    "source_owner": "Cloudflare developer documentation",
    "approved_by": "not_approved",
    "approval_status": "candidate_only",
    "approved_date": "not_approved",
    "review_due_date": "before_production_enablement",
    "query_terms": [
      "Cloudflare Workers limits",
      "runtime limits",
      "request limits",
      "environment variable limits"
    ],
    "retrieval_enabled": false,
    "notes": "Accepted as a candidate-only public platform documentation source for implementation screening context. Do not configure this entry in production. This entry is not approved package authority.",
    "public_availability": "public_https_no_login_observed",
    "proposed_approver": "package_governance_owner_review_required",
    "review_cadence": "before production enablement and before each platform-limit-sensitive production use if approved later",
    "retrieval_safety": "HTTPS-only public HTML page, exact origin, exact docs path prefix, credentials omitted, no login observed.",
    "redirect_behavior": "Live check observed zero redirects. Future redirects must remain inside the allowed origin and path prefix.",
    "content_type_suitability": "Live check returned text/html, which is compatible with the current server-side adapter.",
    "expected_claim_usefulness": "Runtime and deployment implementation screening when package-supported architecture guidance needs current platform-limit context.",
    "limitations_and_bias_risks": "Platform limits vary by plan and time. Documentation does not approve this repository's production configuration.",
    "suitability": {
      "comparison": true,
      "interpretation": false,
      "implementation_screening": true,
      "decision_support": false
    },
    "must_remain_candidate_only": true,
    "reason_for_inclusion": "Official public platform documentation relevant to server-side proof-surface and adapter-limit screening.",
    "live_verification": {
      "checked_date": "2026-06-24",
      "method": "curl unauthenticated metadata fetch with redirects followed for final status metadata",
      "final_url": "https://developers.cloudflare.com/workers/platform/limits/",
      "status_code": 200,
      "content_type": "text/html",
      "redirect_count": 0
    }
  }
]
