Glossary
Every Nimbus Vault term in one place.
Targets
Platform — a source of work: a bug bounty platform, a VDP, or a private engagement.
Program — an organization's published scope: rules, rewards, and boundary for testing.
Asset — one concrete thing you are testing: a host, an API, an app, a checkout. Assets can have children.
Wildcard — a component link that matches any concrete value until you confirm the real one, so a known-but-unpinned capability still contributes to matching.
Library
Component — a reusable building block observed on targets. Five types: technology, functionality, gadget, vector, quirk.
Technology — what a target is built on or running.
Functionality — what a target does for its users.
Gadget — an additional capability that rides along with the target.
Vector — the specific way in: an attack-relevant mechanism.
Quirk — behavior that could tip an attack outcome.
Category — a themed grouping of components used by the engine's structured matching.
Tag — a lightweight label for slicing the library and attaching conditions in playbooks.
Asset-Level Component (ALC) — a component linked directly to the asset, rather than scoped inside another component.
Component-Level Vector (CLV) — a vector scoped inside a specific parent component.
Component-Level Quirk (CLQ) — a quirk scoped inside a specific parent component.
Starter Library — the curated set of components and playbooks you can seed a workspace with.
Engine
Nexus Engine — the deterministic, rule-based engine that matches playbooks against assets, ranks suggestions, and builds the proactive checklist.
Requirement — a component a playbook needs before it can apply. Requirements are hard gates.
Co-location — a requirement that two capabilities must meet at the same endpoint before they count as combined.
Suggestion — a ranked playbook match, with the reasoning that produced it.
Prompt — a question from the checklist: does a capability apply to this asset? Resolving it feeds the engine.
Coverage — how much of what could apply to an asset you have actually confirmed.
Yield — a capability a playbook declares as an output.
Primitive — an earned capability granted by a successful playbook; not part of the component library.
Outcome — the recorded result of a run: success, failed, or not applicable.
CAVET — Component Analysis & Vulnerability Enumeration Technique: the methodology Nimbus Vault implements — analyze targets into components, then enumerate exploitable behavior systematically.
Work
Workspace — the container for all assets, components, playbooks, and notespaces; shared with your team.
Notespace — the single page where an entity's links, notes, and history live.
Endpoint — the concrete URL or path where a capability was observed.
Scope — where a link applies: directly on the asset, or inside a parent component.
Agent connection — a capability-scoped token that lets an AI agent read from and write to your workspace over the Model Context Protocol (MCP).