Vectors
The specific mechanisms that turn observed behavior into a reachable attack.
What a vector is
A vector is the specific way in — the mechanism that turns observed behavior into a reachable attack: SVG upload, an SSRF-prone webhook fetcher, path traversal in file handling, OAuth redirect manipulation, mass assignment.
In CAVET terms, vectors are the application's perception system — the lenses through which it sees input. The same payload behaves differently depending on which lens it arrives through.
A vector is a mechanism, not a payload. SVG upload is a vector; the payload you deliver through it is an exploit, and that belongs in the playbook that uses it — not in the library.
How they link
Vectors are rarely asset-wide. They are usually scoped inside the parent that produces them — the functionality or technology where the mechanism was observed:
File Upload (functionality)
└─ SVG upload (vector)
Webhook Configuration (functionality)
└─ SSRF-prone fetcher (vector)
Scoped matches rank higher in the engine. The more precisely a vector is anchored, the more trustworthy the suggestion it appears in.
Record the endpoint
When you know where a vector was observed, record the endpoint on the link. Endpoints are how the engine decides whether two capabilities actually meet — a vector without one can still match, but any playbook with a co-location requirement will not.
Library hygiene
One mechanism per component. Split "SVG upload with stored XSS" into SVG upload (vector) and stored XSS (quirk) — the playbook is where they combine.
In the app
Create one from Vectors with Add Vector: Name (required), Category (required), Description, and Tags.
Vectors are usually observed rather than invented — you find an SVG upload while mapping an uploader, then link it as a scoped child (CLV) of the component that produces it. Nest deeper with Nested Vectors, attach a quirk to a vector with Add CLVQ, and express variance with a playbook Category + Tag combination instead of naming every format (the File Types + #archive-file pattern).
What's next
Quirks — the behaviors that change what a vector can do.