concept Updated 2026-10-06

Scopes and Levels

How components nest — asset-level observations versus scoped children.

Why scoping exists

"This asset has prototype pollution" and "this specific Node.js service has prototype pollution" are different claims. The second one is worth more: it tells the engine where the behavior lives, lets it satisfy scoped requirements that a flat observation never could, and produces suggestions you can act on instead of guesses.

Scoping is how you make the second claim. A scoped component is a vector or quirk linked inside the parent component it was observed on, rather than floating on the asset.

The levels

LevelWhat it meansExample
ComponentObserved directly on the assetNode.js, File Upload
Scoped vector (CLV)A vector inside a specific parentSVG upload inside File Upload
Scoped quirk (CLQ)A quirk inside a specific parentPrototype pollution inside Node.js
Quirk on a vector (CLVQ)A quirk on a scoped vectorStored XSS on SVG upload
Nested vector (CLVv)A vector inside another vectorVector chaining
Scoped gadget (CLG)A gadget nested inside a parentGraphQL endpoint inside a technology

Asset-wide vectors and quirks exist too — you observed them, but not inside any particular parent. Link them flat when that is the truth. The rule of thumb: scope when you observed the relationship, not when you assume it.

The exact-parent rule

Scoped matching is strict about parentage. A vector scoped inside one functionality does not satisfy a requirement for the same vector type inside a different functionality:

File Upload → SVG upload      does NOT satisfy      Login Form → SVG upload

This is deliberate. Scoping that ignored its parent would just be a slower way of writing a flat link. Structural claims match structural requirements — that is what makes them precise. Playbook requirements use the same levels, so what you observe and what a playbook demands speak the same language.

Instances: the same component, multiple places

One asset can surface the same component more than once — three file uploads, two APIs, several endpoints running the same service. Each occurrence is an instance, and endpoints are recorded per instance rather than per component.

This matters downstream: instances are what co-location reason about. "File upload and SSRF fetcher on the same endpoint" is a statement about instances, not about components in general — two capabilities that exist on an asset but never meet on the same endpoint are not a chain.

Quirks carry roles

A quirk's meaning is contextual, and the vault records it that way:

  • Enabling or mitigating — the role is assigned per playbook, not on the component itself. The same quirk can enable one attack and mitigate another.
  • Present or absent — stateful quirks record whether the target exhibits the behavior or explicitly does not. A confirmed absence is a result, and the right kind of absence can satisfy a requirement written as "does not exhibit."

Details live in Requirements.

What's next