reference Updated 2026-10-06

Glossary

Every Nimbus Vault term in one place.

Targets

Platform — a source of work: a bug bounty platform, a VDP, or a private engagement.

Program — an organization's published scope: rules, rewards, and boundary for testing.

Asset — one concrete thing you are testing: a host, an API, an app, a checkout. Assets can have children.

Wildcard — a component link that matches any concrete value until you confirm the real one, so a known-but-unpinned capability still contributes to matching.

Library

Component — a reusable building block observed on targets. Five types: technology, functionality, gadget, vector, quirk.

Technology — what a target is built on or running.

Functionality — what a target does for its users.

Gadget — an additional capability that rides along with the target.

Vector — the specific way in: an attack-relevant mechanism.

Quirk — behavior that could tip an attack outcome.

Category — a themed grouping of components used by the engine's structured matching.

Tag — a lightweight label for slicing the library and attaching conditions in playbooks.

Asset-Level Component (ALC) — a component linked directly to the asset, rather than scoped inside another component.

Component-Level Vector (CLV) — a vector scoped inside a specific parent component.

Component-Level Quirk (CLQ) — a quirk scoped inside a specific parent component.

Starter Library — the curated set of components and playbooks you can seed a workspace with.

Engine

Nexus Engine — the deterministic, rule-based engine that matches playbooks against assets, ranks suggestions, and builds the proactive checklist.

Requirement — a component a playbook needs before it can apply. Requirements are hard gates.

Co-location — a requirement that two capabilities must meet at the same endpoint before they count as combined.

Suggestion — a ranked playbook match, with the reasoning that produced it.

Prompt — a question from the checklist: does a capability apply to this asset? Resolving it feeds the engine.

Coverage — how much of what could apply to an asset you have actually confirmed.

Yield — a capability a playbook declares as an output.

Primitive — an earned capability granted by a successful playbook; not part of the component library.

Outcome — the recorded result of a run: success, failed, or not applicable.

CAVET — Component Analysis & Vulnerability Enumeration Technique: the methodology Nimbus Vault implements — analyze targets into components, then enumerate exploitable behavior systematically.

Work

Workspace — the container for all assets, components, playbooks, and notespaces; shared with your team.

Notespace — the single page where an entity's links, notes, and history live.

Endpoint — the concrete URL or path where a capability was observed.

Scope — where a link applies: directly on the asset, or inside a parent component.

Agent connection — a capability-scoped token that lets an AI agent read from and write to your workspace over the Model Context Protocol (MCP).