Quirks
Behavior that tips an attack — and why scoping quirks to their parent matters most.
What a quirk is
A quirk is behavior that changes an outcome: missing CSRF protection, prototype pollution, predictable reset tokens, verbose error pages, permissive CORS, unsafe deserialization.
In CAVET terms, quirks are ground truth — not what should be true of the stack in theory, but what is true of this target as observed.
Quirks rarely stand alone. They amplify, dampen, or gate what a vector can do — which is why the engine weighs specific vector/quirk pairings when it ranks suggestions, not just the presence of each one.
How they link
Usually scoped inside the component where the behavior was observed:
Node.js (technology)
└─ Prototype pollution (quirk)
Password Reset (functionality)
└─ Predictable tokens (quirk)
A quirk scoped to its parent is far more valuable than the same quirk floating on the asset. It tells the engine exactly where the behavior lives, and it unlocks playbooks that require that pairing — playbooks that a flat quirk can never satisfy.
Stateful quirks
Some quirks are stateful: triggering them changes how the target behaves or the state it is in. Record the behavior you actually observed, with the state details that matter, rather than the generic label — the engine accounts for how a specific quirk pairs with a specific vector when scoring.
Library hygiene
Name the behavior, not the exploit. Prototype pollution is a quirk; "RCE via prototype pollution in lodash merge" is a playbook.
In the app
Create one from Quirks with Add Quirk: Name (required), Category (required), a Stateful toggle ("This quirk is stateful" — or stateless), Description, and Tags.
Statefulness is set here, at creation: stateful quirks carry a Present / Absent state wherever they're linked, and their objectives carry the same state. Whether a quirk enables or mitigates is not set here — it's chosen per playbook link, because the same quirk can enable one attack and mitigate another. Link quirks scoped inside the component where they were observed (a CLQ on the technology): the scoping is what lets scoped playbook requirements be satisfied at all.