Scopes and Levels
How components nest — asset-level observations versus scoped children.
Why scoping exists
"This asset has prototype pollution" and "this specific Node.js service has prototype pollution" are different claims. The second one is worth more: it tells the engine where the behavior lives, lets it satisfy scoped requirements that a flat observation never could, and produces suggestions you can act on instead of guesses.
Scoping is how you make the second claim. A scoped component is a vector or quirk linked inside the parent component it was observed on, rather than floating on the asset.
The levels
| Level | What it means | Example |
|---|---|---|
| Component | Observed directly on the asset | Node.js, File Upload |
| Scoped vector (CLV) | A vector inside a specific parent | SVG upload inside File Upload |
| Scoped quirk (CLQ) | A quirk inside a specific parent | Prototype pollution inside Node.js |
| Quirk on a vector (CLVQ) | A quirk on a scoped vector | Stored XSS on SVG upload |
| Nested vector (CLVv) | A vector inside another vector | Vector chaining |
| Scoped gadget (CLG) | A gadget nested inside a parent | GraphQL endpoint inside a technology |
Asset-wide vectors and quirks exist too — you observed them, but not inside any particular parent. Link them flat when that is the truth. The rule of thumb: scope when you observed the relationship, not when you assume it.
The exact-parent rule
Scoped matching is strict about parentage. A vector scoped inside one functionality does not satisfy a requirement for the same vector type inside a different functionality:
File Upload → SVG upload does NOT satisfy Login Form → SVG upload
This is deliberate. Scoping that ignored its parent would just be a slower way of writing a flat link. Structural claims match structural requirements — that is what makes them precise. Playbook requirements use the same levels, so what you observe and what a playbook demands speak the same language.
Instances: the same component, multiple places
One asset can surface the same component more than once — three file uploads, two APIs, several endpoints running the same service. Each occurrence is an instance, and endpoints are recorded per instance rather than per component.
This matters downstream: instances are what co-location reason about. "File upload and SSRF fetcher on the same endpoint" is a statement about instances, not about components in general — two capabilities that exist on an asset but never meet on the same endpoint are not a chain.
Quirks carry roles
A quirk's meaning is contextual, and the vault records it that way:
- Enabling or mitigating — the role is assigned per playbook, not on the component itself. The same quirk can enable one attack and mitigate another.
- Present or absent — stateful quirks record whether the target exhibits the behavior or explicitly does not. A confirmed absence is a result, and the right kind of absence can satisfy a requirement written as "does not exhibit."
Details live in Requirements.
What's next
- Authoring Guide — how scoped observations become playbook triggers.
- Notespaces and Endpoints — where links, instances, and endpoints live.