# Expanded Authoritative Current Source Review V01

Issue: #233

Date: 2026-06-24

Status: candidate review evidence only. This document does not enable production current retrieval.

## Purpose

NIST AI RMF is persistently enabled as the first current/public source. This review identifies additional authoritative and respected engineering sources that may later become current/public context sources after separate owner approval, deployment configuration, production smoke, and rollback evidence.

This issue does not enable any additional production source.

## Selection Criteria

Accepted candidates must have:

- public HTTPS URL
- official government, standards, regulator-adjacent, security-framework, or respected engineering source owner
- no login observed during non-authenticated review
- no credentials in the URL
- no private, localhost, or internal hostname
- no wildcard origin
- narrow allowed origin
- narrow allowed path prefix
- text-like content suitable for `allowlisted_public_fetch`
- stable enough for current/public context
- clear claim boundary ending in `not_package_authority`
- clear trust and freshness labels
- reason for inclusion and limitations

Excluded sources include blogs, news, social posts, forums, marketing pages, random web results, unaudited personal sites, broad domains without path constraints, login-required pages, private URLs, and sources whose owner or publication posture is unclear.

## Reviewed Candidates

| Candidate | URL | Source owner | Source type | Result |
|---|---|---|---|---|
| NIST SSDF / SP 800-218 | `https://csrc.nist.gov/pubs/sp/800/218/final` | NIST Computer Security Resource Center | `secure_software_development_framework` | Accepted as candidate-only |
| NIST AI RMF Playbook | `https://airc.nist.gov/airmf-resources/playbook/` | NIST AI Resource Center | `public_standards_or_regulatory` | Accepted as candidate-only |
| OWASP Top 10 for LLMs and Gen AI Apps 2025 | `https://genai.owasp.org/llm-top-10/` | OWASP Foundation GenAI Security Project | `llm_application_security_framework` | Accepted as candidate-only |
| CISA Secure by Design | `https://www.cisa.gov/securebydesign` | Cybersecurity and Infrastructure Security Agency | `government_cybersecurity_guidance` | Accepted as candidate-only |
| CISA Artificial Intelligence | `https://www.cisa.gov/ai` | Cybersecurity and Infrastructure Security Agency | `government_cybersecurity_guidance` | Accepted as candidate-only |
| Google Site Reliability Engineering Book | `https://sre.google/sre-book/table-of-contents/` | Google SRE | `respected_engineering_guidance` | Accepted as candidate-only |
| NIST AI RMF Generative AI Profile | `https://doi.org/10.6028/NIST.AI.600-1` | NIST | `public_standards_or_regulatory` | Deferred |
| MITRE ATLAS | `https://atlas.mitre.org/` | MITRE | `ai_threat_modeling_framework` | Deferred |

## Public Availability Checks

Checks used non-authenticated HTTP requests on 2026-06-24. Registry entries use the final URL when a candidate resolved to a canonical path.

| Candidate | HTTP status | Content type | Redirects | Retrieval note |
|---|---:|---|---:|---|
| NIST SSDF / SP 800-218 | 200 | `text/html; charset=utf-8` | 0 | Public official HTML page, no login observed, exact CSRC publication path. |
| NIST AI RMF Playbook | 200 | `text/html; charset=utf-8` | 0 | Public official AIRC HTML page, no login observed, exact playbook path. |
| OWASP Top 10 for LLMs and Gen AI Apps 2025 | 200 | `text/html; charset=UTF-8` | 0 | Public project HTML page, no login observed, exact LLM Top 10 path. |
| CISA Secure by Design | 200 | `text/html; charset=UTF-8` | 0 | Public government HTML page, no login observed, exact Secure by Design path. |
| CISA Artificial Intelligence | 200 | `text/html; charset=UTF-8` | 0 | Public government HTML page, no login observed, exact AI path. |
| Google Site Reliability Engineering Book | 200 | `text/html` | 0 | Public respected engineering HTML page, no login observed, exact book table-of-contents path. |
| NIST AI RMF Generative AI Profile | 200 | `application/pdf` | 1 | Official DOI resolves to NIST PDF, which is not text-like for the current adapter. |
| MITRE ATLAS | 200 | `text/html; charset=utf-8` | 0 | Public dedicated ATLAS origin. Deferred because narrower tested matrix paths returned 404, leaving only a broad root path. |

## Accepted Candidate-Only Sources

The accepted sources are recorded in `current_source_registry_expanded_candidates_v01.json`.

Every accepted registry entry remains:

- `approval_status: "candidate_only"`
- `retrieval_enabled: false`
- current/public context only
- not approved package authority
- not production configuration

### NIST SSDF / SP 800-218

- Allowed origin: `https://csrc.nist.gov`
- Allowed path prefix: `/pubs/sp/800/218/final`
- Trust label: `authoritative_public_standard_candidate`
- Freshness label: `periodic_review_required`
- Claim boundary: `current_public_secure_software_guidance_only_not_package_authority`
- Reason for inclusion: authoritative secure software development guidance that can support package-first comparisons about secure engineering and software supply-chain discipline.
- Limitations: voluntary guidance can be mistaken for enterprise approval if source lanes are not preserved. It should not approve a tool, vendor, system, data class, workflow, or production use.

### NIST AI RMF Playbook

- Allowed origin: `https://airc.nist.gov`
- Allowed path prefix: `/airmf-resources/playbook/`
- Trust label: `authoritative_public_standard_candidate`
- Freshness label: `living_resource_review_required`
- Claim boundary: `current_public_context_only_not_package_authority`
- Reason for inclusion: official NIST AI RMF knowledge-base material related to the already enabled NIST AI RMF source.
- Limitations: the page says the AI RMF is being revised and that the Playbook is expected to evolve. It should not be used to make stale or stronger-than-stated claims.

### OWASP Top 10 for LLMs and Gen AI Apps 2025

- Allowed origin: `https://genai.owasp.org`
- Allowed path prefix: `/llm-top-10/`
- Trust label: `respected_security_framework_candidate`
- Freshness label: `periodic_review_required`
- Claim boundary: `current_public_security_guidance_only_not_package_authority`
- Reason for inclusion: respected LLM application security framework with a 2025 Top 10 page relevant to prompt injection, data disclosure, supply chain, agency, and related risks.
- Limitations: OWASP material is community-maintained and should not be treated as company policy, production approval, or a complete control set.

### CISA Secure by Design

- Allowed origin: `https://www.cisa.gov`
- Allowed path prefix: `/securebydesign`
- Trust label: `authoritative_public_government_candidate`
- Freshness label: `periodic_review_required`
- Claim boundary: `current_public_cybersecurity_guidance_only_not_package_authority`
- Reason for inclusion: official CISA guidance relevant to secure product and engineering practices.
- Limitations: the page is public guidance, not a repository-specific approval for architecture, deployment, or production operation.

### CISA Artificial Intelligence

- Allowed origin: `https://www.cisa.gov`
- Allowed path prefix: `/ai`
- Trust label: `authoritative_public_government_candidate`
- Freshness label: `periodic_review_required`
- Claim boundary: `current_public_cybersecurity_guidance_only_not_package_authority`
- Reason for inclusion: official CISA AI page relevant to cybersecurity posture and AI-related public guidance.
- Limitations: landing-page content may aggregate programs and announcements. Before enablement, owner review must confirm it supports the intended current/public claim narrowly enough.

### Google Site Reliability Engineering Book

- Allowed origin: `https://sre.google`
- Allowed path prefix: `/sre-book/table-of-contents/`
- Trust label: `respected_engineering_guidance_candidate`
- Freshness label: `periodic_review_required`
- Claim boundary: `current_public_engineering_guidance_only_not_package_authority`
- Reason for inclusion: mature, well-known engineering practice reference for reliability, SLOs, toil, and operational discipline.
- Limitations: Google SRE material is not neutral standards authority and does not approve this repository's tooling, hosting, model, or production practices.

## Deferred Or Rejected Sources

No reviewed source is rejected in this review.

Deferred sources:

- NIST AI RMF Generative AI Profile: official DOI verified, but it redirects to a NIST PDF with `application/pdf`. The current adapter accepts text-like HTML, plain text, markdown, and JSON-like content only. Defer until a stable official text-like landing page exists or PDF extraction is explicitly scoped and validated.
- MITRE ATLAS: official root URL verified as public HTML on a dedicated ATLAS origin. Defer because tested narrower matrix paths returned 404 and a root-only allowed path would be too broad for this registry posture.

## Vendor-Source Treatment Rules

Vendor sources are candidate-only unless a later issue proves they are necessary for platform-specific facts such as pricing, limits, API behavior, model behavior, runtime configuration, or deployment constraints.

Vendor sources must not be used as neutral industry authority, product endorsement, procurement approval, production approval, or evidence that a tool is approved for enterprise use.

## Engineering-Source Treatment Rules

Respected engineering sources can support comparison, interpretation, and implementation screening only after approved package support exists.

They must not override package guidance, resolve package/current conflicts by themselves, approve tools, approve production use, approve data classes, or stand in for owner validation.

## Production Enablement Non-Goals

This issue does not:

- enable any new production source
- modify Cloudflare environment variables or production config values
- modify Cloudflare Access or WAF
- modify provider or model secrets
- modify provider or model configuration
- alter the currently persistent NIST configuration
- add arbitrary web search
- add browser-side current-source fetches
- add user-provided URL retrieval
- add durable telemetry, database, vector store, Supabase, uploads, or session attachments
- expose secrets
- promote current/public sources into approved package authority
- authorize `codex-automerge`

## Residual Risks

- Public sources can change after review.
- HTML extraction can lose tables, navigation context, caveats, or update notices.
- Candidate-only entries can be mistaken for production approval unless validator and receipt boundaries stay explicit.
- NIST AIRC and CISA pages can evolve as living resources and require review before enablement.
- Vendor and vendor-published engineering sources can carry platform bias.
- MITRE ATLAS may need a separate path-constraint review before it can be safely added to a registry.

## Recommended Next Enablement Order

1. NIST SSDF / SP 800-218: strongest next candidate because it is authoritative, official, public HTML, narrow-path, and relevant to secure software development without vendor bias.
2. NIST AI RMF Playbook: useful same-family expansion from the currently enabled NIST AI RMF source, but living-resource freshness must be reviewed before enablement.
3. OWASP Top 10 for LLMs and Gen AI Apps 2025: relevant to LLM application security, with community-source caveats.
4. CISA Secure by Design: strong government cybersecurity guidance, best used for secure engineering posture comparisons.
5. CISA Artificial Intelligence: useful but should be reviewed for page-specific claim narrowness before enablement.
6. Google Site Reliability Engineering Book: respected engineering practice reference, but lower priority because it is not government, standards, or regulator-adjacent authority.
