|
27 | 27 | "id": "document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover.md", |
28 | 28 | "path": "document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover.md" |
29 | 29 | }, |
30 | | - "label": "KNOWLEDGE", |
31 | | - "label_rationale": "", |
| 30 | + "label": "NOISE", |
| 31 | + "label_rationale": "Heading/title-only chunk with no methodology body [heading-only tiny-chunk -> NOISE, consistent rule 2026-07-03; was KNOWLEDGE]", |
32 | 32 | "labeled_by": "manshusainishab", |
33 | 33 | "labeled_at": "2026-05-29" |
34 | 34 | }, |
|
96 | 96 | "id": "document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover.md", |
97 | 97 | "path": "document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover.md" |
98 | 98 | }, |
99 | | - "label": "UNCERTAIN", |
100 | | - "label_rationale": "borderline: structured as an example but is the primary methodology unit for testing GitHub-specific subdomain takeover. Prompt iteration must clarify whether canonical WSTG worked examples count as KNOWLEDGE or as \"additional example\" NOISE.", |
| 99 | + "label": "KNOWLEDGE", |
| 100 | + "label_rationale": "Worked attack-scenario walkthrough (GitHub subdomain takeover) -- security content [recall-first correction 2026-07-03; was UNCERTAIN]", |
101 | 101 | "labeled_by": "manshusainishab", |
102 | 102 | "labeled_at": "2026-05-29" |
103 | 103 | }, |
|
131 | 131 | "id": "document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover.md", |
132 | 132 | "path": "document/4-Web_Application_Security_Testing/02-Configuration_and_Deployment_Management_Testing/10-Test_for_Subdomain_Takeover.md" |
133 | 133 | }, |
134 | | - "label": "UNCERTAIN", |
135 | | - "label_rationale": "same case as chunk 3 — scenario walkthrough under Summary. Linked for prompt-iteration consistency.", |
| 134 | + "label": "KNOWLEDGE", |
| 135 | + "label_rationale": "Worked attack-scenario walkthrough (expired-domain subdomain takeover) [recall-first correction 2026-07-03; was UNCERTAIN]", |
136 | 136 | "labeled_by": "manshusainishab", |
137 | 137 | "labeled_at": "2026-05-29" |
138 | 138 | }, |
|
548 | 548 | "id": "document/4-Web_Application_Security_Testing/04-Authentication_Testing/11-Testing_Multi-Factor_Authentication.md", |
549 | 549 | "path": "document/4-Web_Application_Security_Testing/04-Authentication_Testing/11-Testing_Multi-Factor_Authentication.md" |
550 | 550 | }, |
551 | | - "label": "KNOWLEDGE", |
552 | | - "label_rationale": "", |
| 551 | + "label": "NOISE", |
| 552 | + "label_rationale": "Heading/title-only chunk with no methodology body [heading-only tiny-chunk -> NOISE, consistent rule 2026-07-03; was KNOWLEDGE]", |
553 | 553 | "labeled_by": "manshusainishab", |
554 | 554 | "labeled_at": "2026-05-29" |
555 | 555 | }, |
|
1748 | 1748 | "id": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md", |
1749 | 1749 | "path": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md" |
1750 | 1750 | }, |
1751 | | - "label": "KNOWLEDGE", |
1752 | | - "label_rationale": "", |
| 1751 | + "label": "NOISE", |
| 1752 | + "label_rationale": "Heading/title-only chunk with no methodology body [heading-only tiny-chunk -> NOISE, consistent rule 2026-07-03; was KNOWLEDGE]", |
1753 | 1753 | "labeled_by": "manshusainishab", |
1754 | 1754 | "labeled_at": "2026-05-29" |
1755 | 1755 | }, |
|
1851 | 1851 | "id": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md", |
1852 | 1852 | "path": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md" |
1853 | 1853 | }, |
1854 | | - "label": "KNOWLEDGE", |
1855 | | - "label_rationale": "", |
| 1854 | + "label": "NOISE", |
| 1855 | + "label_rationale": "Heading/title-only chunk with no methodology body [heading-only tiny-chunk -> NOISE, consistent rule 2026-07-03; was KNOWLEDGE]", |
1856 | 1856 | "labeled_by": "manshusainishab", |
1857 | 1857 | "labeled_at": "2026-05-29" |
1858 | 1858 | }, |
|
1887 | 1887 | "id": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md", |
1888 | 1888 | "path": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md" |
1889 | 1889 | }, |
1890 | | - "label": "UNCERTAIN", |
1891 | | - "label_rationale": "DOM sinks (innerHTML/outerHTML) framed as examples but functionally an attack-vector catalog. Same pattern as chunks 3-4; needs prompt clarification on canonical-primitive vs illustrative-example.", |
| 1890 | + "label": "KNOWLEDGE", |
| 1891 | + "label_rationale": "Catalog of dangerous DOM sinks (innerHTML/outerHTML) = XSS attack vectors [recall-first correction 2026-07-03; was UNCERTAIN]", |
1892 | 1892 | "labeled_by": "manshusainishab", |
1893 | 1893 | "labeled_at": "2026-05-29" |
1894 | 1894 | }, |
|
1923 | 1923 | "id": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md", |
1924 | 1924 | "path": "cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.md" |
1925 | 1925 | }, |
1926 | | - "label": "UNCERTAIN", |
1927 | | - "label_rationale": "same case as chunk 55 — DOM sinks framed as examples. Linked for prompt-iteration consistency.", |
| 1926 | + "label": "KNOWLEDGE", |
| 1927 | + "label_rationale": "Catalog of dangerous DOM methods (document.write/writeln) = XSS attack vectors [recall-first correction 2026-07-03; was UNCERTAIN]", |
1928 | 1928 | "labeled_by": "manshusainishab", |
1929 | 1929 | "labeled_at": "2026-05-29" |
1930 | 1930 | }, |
|
3068 | 3068 | "id": "Website/content/en/user-day/owasp-samm-to-the-rescue.md", |
3069 | 3069 | "path": "Website/content/en/user-day/owasp-samm-to-the-rescue.md" |
3070 | 3070 | }, |
3071 | | - "label": "UNCERTAIN", |
3072 | | - "label_rationale": "talk abstract with substantive attack content (AWS CodeBuild StartBuild pipeline poisoning) wrapped in event-page framing. Prompt iteration must clarify whether talk teasers with named attack techniques count as KNOWLEDGE.", |
| 3071 | + "label": "KNOWLEDGE", |
| 3072 | + "label_rationale": "Talk abstract naming a concrete technique (CodeBuild pipeline poisoning) [recall-first correction 2026-07-03; was UNCERTAIN]", |
3073 | 3073 | "labeled_by": "manshusainishab", |
3074 | 3074 | "labeled_at": "2026-05-29" |
3075 | 3075 | }, |
|
0 commit comments