{
  "schemaVersion": "cg-owasp-agentic-coverage-methodology-1.0.0",
  "version": "1.0.0",
  "generatedAt": "2026-07-20T00:00:00.000Z",
  "framework": {
    "id": "OWASP-AGENTIC-TOP-10-2026",
    "title": "OWASP Top 10 for Agentic Applications 2026",
    "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/"
  },
  "mappingRule": "A control is mapped only when its public claim boundary, support matrix, threat model, or test vectors produce evidence relevant to the named risk area.",
  "verificationRule": "Every referenced public release manifest and every artifact named by that manifest is read and SHA-256 checked when this release is generated and tested.",
  "statusRule": "publisher_evidence_available means CapitalGuard published a hash-bound control release relevant to the category. It does not mean the full category is mitigated.",
  "limitations": [
    "CapitalGuard operates this evidence release; no independent lab validation is claimed.",
    "OWASP did not endorse or certify CapitalGuard and is not affiliated with this release.",
    "A control protects only operations routed through its documented enforcement boundary.",
    "The map does not prove absence of vulnerabilities, complete category coverage, or incident prevention.",
    "The OWASP framework may change; this release remains bound to the cited 2026 edition."
  ],
  "reproduction": {
    "generate": "node scripts/generate-owasp-agentic-coverage-release.mjs",
    "verify": "node scripts/verify-owasp-agentic-coverage.mjs"
  }
}
