From 75a117390440ae35d5dd67a00c8bcdf26f16a65b Mon Sep 17 00:00:00 2001 From: Alex Schapiro Date: Tue, 21 Jul 2026 04:19:45 +0000 Subject: [PATCH] docs(reporting): drop 'one weakness per report' calibration bullet --- strix/tools/reporting/tool.py | 3 --- 1 file changed, 3 deletions(-) diff --git a/strix/tools/reporting/tool.py b/strix/tools/reporting/tool.py index c8c2972c..d6b6b209 100644 --- a/strix/tools/reporting/tool.py +++ b/strix/tools/reporting/tool.py @@ -440,9 +440,6 @@ async def create_vulnerability_report( user's data, a read-only information leak, or merely confirming that an account / domain / software version *exists* (enumeration) is ``C:L`` (often ``I:N``) — not ``C:H``. - - **Score one weakness per report.** If the alarming impact depends - on chaining a second issue, report and score them separately rather - than folding the chained worst case into one inflated vector. - **Model required position and interaction honestly.** An adversary-in-the-middle prerequisite (e.g. cleartext transmission) or a required victim action is not guaranteed — reflect it in