{
  "action_maps": [
    {
      "label": "add",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_add"
    },
    {
      "label": "add_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_add_tool"
    },
    {
      "label": "all_optional_params_function",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_all_optional_params_function"
    },
    {
      "label": "alpha_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_alpha_tool"
    },
    {
      "label": "already_ran",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_already_ran"
    },
    {
      "label": "another_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_another_tool"
    },
    {
      "label": "apply_lifecycle_patch",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_apply_lifecycle_patch"
    },
    {
      "label": "approval_echo",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_approval_echo"
    },
    {
      "label": "approval_note",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_approval_note"
    },
    {
      "label": "approval_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_approval_tool"
    },
    {
      "label": "approve_me",
      "mappings": [
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_approve_me"
    },
    {
      "label": "assert_manifest_materialized_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_assert_manifest_materialized_tool"
    },
    {
      "label": "assert_restored_lifecycle_state_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_assert_restored_lifecycle_state_tool"
    },
    {
      "label": "assert_workspace_escape_blocked_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_assert_workspace_escape_blocked_tool"
    },
    {
      "label": "async_no_context",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_async_no_context"
    },
    {
      "label": "async_with_context",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_async_with_context"
    },
    {
      "label": "bad_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_bad_tool"
    },
    {
      "label": "beta_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_beta_tool"
    },
    {
      "label": "billing_status_checker",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_billing_status_checker"
    },
    {
      "label": "boom",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_boom"
    },
    {
      "label": "calculate_sum",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_calculate_sum"
    },
    {
      "label": "create_config",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_create_config"
    },
    {
      "label": "dangerous_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_dangerous_tool"
    },
    {
      "label": "deferred_lookup",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_deferred_lookup"
    },
    {
      "label": "deferred_lookup_account",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_deferred_lookup_account"
    },
    {
      "label": "delegate_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_delegate_tool"
    },
    {
      "label": "disabled_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_disabled_tool"
    },
    {
      "label": "echo",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_echo"
    },
    {
      "label": "echo_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_echo_tool"
    },
    {
      "label": "extract_lifecycle_archive",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_extract_lifecycle_archive"
    },
    {
      "label": "faq_lookup_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_faq_lookup_tool"
    },
    {
      "label": "fast_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_fast_tool"
    },
    {
      "label": "fetch_random_image",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_fetch_random_image"
    },
    {
      "label": "first_approval_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_first_approval_tool"
    },
    {
      "label": "foo",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_foo"
    },
    {
      "label": "foo_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_foo_tool"
    },
    {
      "label": "format_message",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_format_message"
    },
    {
      "label": "get_contact_info",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_contact_info"
    },
    {
      "label": "get_current_time",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_current_time"
    },
    {
      "label": "get_current_timestamp",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_current_timestamp"
    },
    {
      "label": "get_current_weather",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_current_weather"
    },
    {
      "label": "get_customer_profile",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_customer_profile"
    },
    {
      "label": "get_discount_approval_path",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_discount_approval_path"
    },
    {
      "label": "get_discount_approval_rule",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_discount_approval_rule"
    },
    {
      "label": "get_invoice_status",
      "mappings": [
        {
          "basis": "inferred from action verb 'invoice'; confirm against published text (asserted basis: Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'invoice'; confirm against published text (asserted basis: A high-value financial action by an automated system requires effective human oversight before it takes effect.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'invoice'; confirm against published text (asserted basis: An agent moving money without a second authorizer is the canonical excessive-agency failure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_get_invoice_status"
    },
    {
      "label": "get_metadata",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_metadata"
    },
    {
      "label": "get_policy_reference",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_policy_reference"
    },
    {
      "label": "get_secret_word",
      "mappings": [
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Refusing to handle data above a classification ceiling enforces the categorization of the resource.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "RA-2",
          "name": "Security Categorization",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: The ceiling governs the flow of classified information through the agent.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Handling over-classified data is a data-governance violation.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Processing restricted data above ceiling risks sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "handling data above a classification ceiling maps to sensitive-data access",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1530",
          "name": "Data from Cloud Storage",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_get_secret_word"
    },
    {
      "label": "get_shipping_credit_balance",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_shipping_credit_balance"
    },
    {
      "label": "get_shipping_eta",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_shipping_eta"
    },
    {
      "label": "get_temperature",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_temperature"
    },
    {
      "label": "get_user_data",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_user_data"
    },
    {
      "label": "get_user_name",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_user_name"
    },
    {
      "label": "get_weather",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_get_weather"
    },
    {
      "label": "greet",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_greet"
    },
    {
      "label": "guarded",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_guarded"
    },
    {
      "label": "helper",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_helper"
    },
    {
      "label": "how_many_jokes",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_how_many_jokes"
    },
    {
      "label": "inner_hitl_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_inner_hitl_tool"
    },
    {
      "label": "inner_sensitive_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_inner_sensitive_tool"
    },
    {
      "label": "inner_shared_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_inner_shared_tool"
    },
    {
      "label": "inner_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_inner_tool"
    },
    {
      "label": "known_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_known_tool"
    },
    {
      "label": "list_open_orders",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_list_open_orders"
    },
    {
      "label": "lookup_account",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_lookup_account"
    },
    {
      "label": "lookup_customer_profile",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_lookup_customer_profile"
    },
    {
      "label": "lookup_insurance_eligibility",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_lookup_insurance_eligibility"
    },
    {
      "label": "lookup_order",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_lookup_order"
    },
    {
      "label": "lookup_patient",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_lookup_patient"
    },
    {
      "label": "lookup_referral_status",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_lookup_referral_status"
    },
    {
      "label": "lookup_secret",
      "mappings": [
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Refusing to handle data above a classification ceiling enforces the categorization of the resource.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "RA-2",
          "name": "Security Categorization",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: The ceiling governs the flow of classified information through the agent.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Handling over-classified data is a data-governance violation.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Processing restricted data above ceiling risks sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "handling data above a classification ceiling maps to sensitive-data access",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1530",
          "name": "Data from Cloud Storage",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_lookup_secret"
    },
    {
      "label": "multiply_by_two",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_multiply_by_two"
    },
    {
      "label": "needs_ok",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_needs_ok"
    },
    {
      "label": "optional_param_function",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_optional_param_function"
    },
    {
      "label": "other_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_other_tool"
    },
    {
      "label": "outer_shared_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_outer_shared_tool"
    },
    {
      "label": "outer_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_outer_tool"
    },
    {
      "label": "pending_me",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_pending_me"
    },
    {
      "label": "pending_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_pending_tool"
    },
    {
      "label": "ping",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_ping"
    },
    {
      "label": "publish_announcement",
      "mappings": [
        {
          "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_publish_announcement"
    },
    {
      "label": "query_runloop_network_policy",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_query_runloop_network_policy"
    },
    {
      "label": "query_runloop_secret",
      "mappings": [
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Refusing to handle data above a classification ceiling enforces the categorization of the resource.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "RA-2",
          "name": "Security Categorization",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: The ceiling governs the flow of classified information through the agent.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Handling over-classified data is a data-governance violation.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Processing restricted data above ceiling risks sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "handling data above a classification ceiling maps to sensitive-data access",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1530",
          "name": "Data from Cloud Storage",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_query_runloop_secret"
    },
    {
      "label": "random_number",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_random_number"
    },
    {
      "label": "random_number_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_random_number_tool"
    },
    {
      "label": "read_file",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_read_file"
    },
    {
      "label": "record_side_effect",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_record_side_effect"
    },
    {
      "label": "reject_me",
      "mappings": [
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_reject_me"
    },
    {
      "label": "route_to_human_queue",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_route_to_human_queue"
    },
    {
      "label": "second_approval_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_second_approval_tool"
    },
    {
      "label": "send_email",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_send_email"
    },
    {
      "label": "slow_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_slow_tool"
    },
    {
      "label": "start_lifecycle_pty",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_start_lifecycle_pty"
    },
    {
      "label": "submit_refund",
      "mappings": [
        {
          "basis": "inferred from action verb 'refund'; confirm against published text (asserted basis: Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-5",
          "name": "Separation of Duties",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'refund'; confirm against published text (asserted basis: A high-value financial action by an automated system requires effective human oversight before it takes effect.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'refund'; confirm against published text (asserted basis: An agent moving money without a second authorizer is the canonical excessive-agency failure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MANAGE",
          "name": "Manage function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "separation of duties mitigates valid-account / privilege abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1078",
          "name": "Valid Accounts",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_submit_refund"
    },
    {
      "label": "sync_no_context_no_args",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_sync_no_context_no_args"
    },
    {
      "label": "sync_no_context_override",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_sync_no_context_override"
    },
    {
      "label": "sync_no_context_with_args",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_sync_no_context_with_args"
    },
    {
      "label": "sync_tool_decorator_style",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_sync_tool_decorator_style"
    },
    {
      "label": "sync_with_context",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_sync_with_context"
    },
    {
      "label": "synthetic_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_synthetic_tool"
    },
    {
      "label": "test_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_test_tool"
    },
    {
      "label": "test_tool_one",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_test_tool_one"
    },
    {
      "label": "test_tool_two",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_test_tool_two"
    },
    {
      "label": "timeout_configured_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_timeout_configured_tool"
    },
    {
      "label": "timeout_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_timeout_tool"
    },
    {
      "label": "tool2",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_tool2"
    },
    {
      "label": "tool_one",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_tool_one"
    },
    {
      "label": "triage_tool",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_triage_tool"
    },
    {
      "label": "update_customer_record",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_update_customer_record"
    },
    {
      "label": "update_seat",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_update_seat"
    },
    {
      "label": "visible_lookup_account",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_visible_lookup_account"
    },
    {
      "label": "will_fail_on_bad_json",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_will_fail_on_bad_json"
    },
    {
      "label": "will_not_fail_on_bad_json",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_will_not_fail_on_bad_json"
    },
    {
      "label": "will_not_fail_on_bad_json_async",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "cap_will_not_fail_on_bad_json_async"
    },
    {
      "label": "write_file",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "cap_write_file"
    },
    {
      "label": "approve",
      "mappings": [
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_approve"
    },
    {
      "label": "approve_first_interruption",
      "mappings": [
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_approve_first_interruption"
    },
    {
      "label": "approve_tool",
      "mappings": [
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_approve_tool"
    },
    {
      "label": "approve_tool_call",
      "mappings": [
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_approve_tool_call"
    },
    {
      "label": "delete",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete"
    },
    {
      "label": "delete_branch",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_branch"
    },
    {
      "label": "delete_cached_snapshot_fingerprint_best_effort",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_cached_snapshot_fingerprint_best_effort"
    },
    {
      "label": "delete_file",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_file"
    },
    {
      "label": "delete_many",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_many"
    },
    {
      "label": "delete_one",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_one"
    },
    {
      "label": "delete_session",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_session"
    },
    {
      "label": "delete_state",
      "mappings": [
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_delete_state"
    },
    {
      "label": "drop_agent_tool_run_result",
      "mappings": [
        {
          "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_drop_agent_tool_run_result"
    },
    {
      "label": "drop_orphan_function_calls",
      "mappings": [
        {
          "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-5",
          "name": "Access Restrictions for Change",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "a destructive change during a freeze maps to data destruction",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1485",
          "name": "Data Destruction",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_drop_orphan_function_calls"
    },
    {
      "label": "exec",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec"
    },
    {
      "label": "exec_async",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec_async"
    },
    {
      "label": "exec_checked_nonzero",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec_checked_nonzero"
    },
    {
      "label": "exec_command_needs_approval",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec_command_needs_approval"
    },
    {
      "label": "exec_create",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec_create"
    },
    {
      "label": "exec_inspect",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec_inspect"
    },
    {
      "label": "exec_run",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_exec_run"
    },
    {
      "label": "exec_start",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_exec_start"
    },
    {
      "label": "execute",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute"
    },
    {
      "label": "execute_apply_patch_calls",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_apply_patch_calls"
    },
    {
      "label": "execute_approved_tools",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_approved_tools"
    },
    {
      "label": "execute_computer_actions",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_computer_actions"
    },
    {
      "label": "execute_custom_tool_calls",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_custom_tool_calls"
    },
    {
      "label": "execute_final_output",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_final_output"
    },
    {
      "label": "execute_final_output_step",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_final_output_step"
    },
    {
      "label": "execute_function_tool_calls",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_function_tool_calls"
    },
    {
      "label": "execute_handoffs",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_handoffs"
    },
    {
      "label": "execute_local_shell_calls",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_local_shell_calls"
    },
    {
      "label": "execute_mcp_approval_requests",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_mcp_approval_requests"
    },
    {
      "label": "execute_session_command",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_session_command"
    },
    {
      "label": "execute_shell_calls",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_shell_calls"
    },
    {
      "label": "execute_tools_and_side_effects",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_tools_and_side_effects"
    },
    {
      "label": "execute_with_shuffle",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_execute_with_shuffle"
    },
    {
      "label": "export",
      "mappings": [
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_export"
    },
    {
      "label": "post",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_post"
    },
    {
      "label": "provision_accounts",
      "mappings": [
        {
          "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_provision_accounts"
    },
    {
      "label": "provision_manifest_accounts",
      "mappings": [
        {
          "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_provision_manifest_accounts"
    },
    {
      "label": "publish",
      "mappings": [
        {
          "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_publish"
    },
    {
      "label": "reject",
      "mappings": [
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_reject"
    },
    {
      "label": "reject_tool",
      "mappings": [
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_reject_tool"
    },
    {
      "label": "reject_tool_call",
      "mappings": [
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_reject_tool_call"
    },
    {
      "label": "release_agent",
      "mappings": [
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_release_agent"
    },
    {
      "label": "release_agents",
      "mappings": [
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_release_agents"
    },
    {
      "label": "release_waiters",
      "mappings": [
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "CM-3",
          "name": "Configuration Change Control",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "an unapproved production change maps to system-process modification / persistence",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1543",
          "name": "Create or Modify System Process",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_release_waiters"
    },
    {
      "label": "run",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run"
    },
    {
      "label": "run_agent",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_agent"
    },
    {
      "label": "run_agent_async",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_agent_async"
    },
    {
      "label": "run_and_resume",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_and_resume"
    },
    {
      "label": "run_and_resume_after_approval",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_and_resume_after_approval"
    },
    {
      "label": "run_and_resume_with_mutation",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_and_resume_with_mutation"
    },
    {
      "label": "run_command",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_command"
    },
    {
      "label": "run_compaction",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_compaction"
    },
    {
      "label": "run_conversation",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_conversation"
    },
    {
      "label": "run_demo_loop",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_demo_loop"
    },
    {
      "label": "run_examples",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_examples"
    },
    {
      "label": "run_execute_approved_tools",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_execute_approved_tools"
    },
    {
      "label": "run_execute_with_processed_response",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_execute_with_processed_response"
    },
    {
      "label": "run_file_session_scenario",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_file_session_scenario"
    },
    {
      "label": "run_final_output_hooks",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_final_output_hooks"
    },
    {
      "label": "run_function",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_function"
    },
    {
      "label": "run_git",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_git"
    },
    {
      "label": "run_healthcare_support_workflow",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_healthcare_support_workflow"
    },
    {
      "label": "run_in_listener_task",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_in_listener_task"
    },
    {
      "label": "run_input_guardrails",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_input_guardrails"
    },
    {
      "label": "run_input_guardrails_with_queue",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_input_guardrails_with_queue"
    },
    {
      "label": "run_interactive_loop",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_interactive_loop"
    },
    {
      "label": "run_item_to_input_item",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_item_to_input_item"
    },
    {
      "label": "run_items_to_input_items",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_items_to_input_items"
    },
    {
      "label": "run_mount_smoke_test",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_mount_smoke_test"
    },
    {
      "label": "run_namespaced_example",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_namespaced_example"
    },
    {
      "label": "run_once",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_once"
    },
    {
      "label": "run_openai_session_scenario",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_openai_session_scenario"
    },
    {
      "label": "run_output_guardrails",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_output_guardrails"
    },
    {
      "label": "run_phase_one",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_phase_one"
    },
    {
      "label": "run_phase_two",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_phase_two"
    },
    {
      "label": "run_pre_stop_hooks",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_pre_stop_hooks"
    },
    {
      "label": "run_resume",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_resume"
    },
    {
      "label": "run_scenario_step",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_scenario_step"
    },
    {
      "label": "run_single",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_single"
    },
    {
      "label": "run_single_approval",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_single_approval"
    },
    {
      "label": "run_single_input_guardrail",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_single_input_guardrail"
    },
    {
      "label": "run_single_output_guardrail",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_single_output_guardrail"
    },
    {
      "label": "run_single_turn",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_single_turn"
    },
    {
      "label": "run_single_turn_streamed",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_single_turn_streamed"
    },
    {
      "label": "run_sql",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_sql"
    },
    {
      "label": "run_step",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_step"
    },
    {
      "label": "run_streamed",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_streamed"
    },
    {
      "label": "run_streamed_turn",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_streamed_turn"
    },
    {
      "label": "run_subtask",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_subtask"
    },
    {
      "label": "run_sync",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_sync"
    },
    {
      "label": "run_tasks_as_children",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_tasks_as_children"
    },
    {
      "label": "run_tasks_parallel",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_tasks_parallel"
    },
    {
      "label": "run_tool",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_tool"
    },
    {
      "label": "run_top_level_example",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_top_level_example"
    },
    {
      "label": "run_turn",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_turn"
    },
    {
      "label": "run_with_auto_approval",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_with_auto_approval"
    },
    {
      "label": "run_with_custom_client",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_with_custom_client"
    },
    {
      "label": "run_worker",
      "mappings": [
        {
          "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
          "confidence": "ambiguous",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "AMBIGUOUS"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_run_worker"
    },
    {
      "label": "send",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send"
    },
    {
      "label": "send_audio",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_audio"
    },
    {
      "label": "send_bytes",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_bytes"
    },
    {
      "label": "send_client_event",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_client_event"
    },
    {
      "label": "send_event",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_event"
    },
    {
      "label": "send_input",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_input"
    },
    {
      "label": "send_message",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_message"
    },
    {
      "label": "send_mic_audio",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_mic_audio"
    },
    {
      "label": "send_new",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_new"
    },
    {
      "label": "send_std_in",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_std_in"
    },
    {
      "label": "send_stdin",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_stdin"
    },
    {
      "label": "send_str",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_str"
    },
    {
      "label": "send_tool_output",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_tool_output"
    },
    {
      "label": "send_user_message",
      "mappings": [
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_send_user_message"
    },
    {
      "label": "shutdown",
      "mappings": [],
      "matched_via": "none",
      "subject_id": "fn_shutdown"
    },
    {
      "label": "terminate",
      "mappings": [
        {
          "basis": "inferred from action verb 'terminate'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 14",
          "name": "Human oversight",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'terminate'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM06",
          "name": "Excessive Agency",
          "provenance": "INFERRED"
        },
        {
          "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
          "confidence": "advisory",
          "fw": "NIST AI RMF",
          "id": "MEASURE",
          "name": "Measure function",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "autonomous execution without oversight maps to command/scripting abuse",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_terminate"
    },
    {
      "label": "upload",
      "mappings": [
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_upload"
    },
    {
      "label": "upload_file",
      "mappings": [
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "AC-4",
          "name": "Information Flow Enforcement",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
          "confidence": "inferred",
          "fw": "NIST SP 800-53r5",
          "id": "SC-7",
          "name": "Boundary Protection",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
          "confidence": "inferred",
          "fw": "EU AI Act",
          "id": "Art 10",
          "name": "Data and data governance",
          "provenance": "INFERRED"
        },
        {
          "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
          "confidence": "inferred",
          "fw": "OWASP LLM Top 10 (2025)",
          "id": "LLM02",
          "name": "Sensitive Information Disclosure",
          "provenance": "INFERRED"
        },
        {
          "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "TA0010",
          "name": "Exfiltration",
          "provenance": "EXTRACTED"
        },
        {
          "basis": "uncontrolled egress of regulated data maps to exfiltration",
          "confidence": "advisory",
          "fw": "MITRE ATT&CK",
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "provenance": "EXTRACTED"
        }
      ],
      "matched_via": "heuristic",
      "subject_id": "fn_upload_file"
    }
  ],
  "edges": [
    {
      "dst": "fn_approve",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_approve_first_interruption",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_approve_tool",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_approve_tool_call",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_branch",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_cached_snapshot_fingerprint_best_effort",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_file",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_many",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_one",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_session",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_delete_state",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_drop_agent_tool_run_result",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_drop_orphan_function_calls",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_async",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_checked_nonzero",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_command_needs_approval",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_create",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_inspect",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_run",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_exec_start",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_apply_patch_calls",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_approved_tools",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_computer_actions",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_custom_tool_calls",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_final_output",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_final_output_step",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_function_tool_calls",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_handoffs",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_local_shell_calls",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_mcp_approval_requests",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_session_command",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_shell_calls",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_tools_and_side_effects",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_execute_with_shuffle",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_export",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_post",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_provision_accounts",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_provision_manifest_accounts",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_publish",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_reject",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_reject_tool",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_reject_tool_call",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_release_agent",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_release_agents",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_release_waiters",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_agent",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_agent_async",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_and_resume",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_and_resume_after_approval",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_and_resume_with_mutation",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_command",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_compaction",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_conversation",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_demo_loop",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_examples",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_execute_approved_tools",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_execute_with_processed_response",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_file_session_scenario",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_final_output_hooks",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_function",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_git",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_healthcare_support_workflow",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_in_listener_task",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_input_guardrails",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_input_guardrails_with_queue",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_interactive_loop",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_item_to_input_item",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_items_to_input_items",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_mount_smoke_test",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_namespaced_example",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_once",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_openai_session_scenario",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_output_guardrails",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_phase_one",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_phase_two",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_pre_stop_hooks",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_resume",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_scenario_step",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_single",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_single_approval",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_single_input_guardrail",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_single_output_guardrail",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_single_turn",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_single_turn_streamed",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_sql",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_step",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_streamed",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_streamed_turn",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_subtask",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_sync",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_tasks_as_children",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_tasks_parallel",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_tool",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_top_level_example",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_turn",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_with_auto_approval",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_with_custom_client",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_run_worker",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_audio",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_bytes",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_client_event",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_event",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_input",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_message",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_mic_audio",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_new",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_std_in",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_stdin",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_str",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_tool_output",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_send_user_message",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_shutdown",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_terminate",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_upload",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "fn_upload_file",
      "provenance": "EXTRACTED",
      "rel": "EXECUTES",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_add",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_add_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_all_optional_params_function",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_alpha_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_already_ran",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_another_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_apply_lifecycle_patch",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_approval_echo",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_approval_note",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_approval_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_approve_me",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_assert_manifest_materialized_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_assert_restored_lifecycle_state_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_assert_workspace_escape_blocked_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_async_no_context",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_async_with_context",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_bad_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_beta_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_billing_status_checker",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_boom",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_calculate_sum",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_create_config",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_dangerous_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_deferred_lookup",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_deferred_lookup_account",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_delegate_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_disabled_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_echo",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_echo_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_extract_lifecycle_archive",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_faq_lookup_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_fast_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_fetch_random_image",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_first_approval_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_foo",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_foo_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_format_message",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_contact_info",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_current_time",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_current_timestamp",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_current_weather",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_customer_profile",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_discount_approval_path",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_discount_approval_rule",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_invoice_status",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_metadata",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_policy_reference",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_secret_word",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_shipping_credit_balance",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_shipping_eta",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_temperature",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_user_data",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_user_name",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_get_weather",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_greet",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_guarded",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_helper",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_how_many_jokes",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_inner_hitl_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_inner_sensitive_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_inner_shared_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_inner_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_known_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_list_open_orders",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_account",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_customer_profile",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_insurance_eligibility",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_order",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_patient",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_referral_status",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_lookup_secret",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_multiply_by_two",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_needs_ok",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_optional_param_function",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_other_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_outer_shared_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_outer_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_pending_me",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_pending_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_ping",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_publish_announcement",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_query_runloop_network_policy",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_query_runloop_secret",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_random_number",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_random_number_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_read_file",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_record_side_effect",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_reject_me",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_route_to_human_queue",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_second_approval_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_send_email",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_slow_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_start_lifecycle_pty",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_submit_refund",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_sync_no_context_no_args",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_sync_no_context_override",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_sync_no_context_with_args",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_sync_tool_decorator_style",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_sync_with_context",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_synthetic_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_test_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_test_tool_one",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_test_tool_two",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_timeout_configured_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_timeout_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_tool2",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_tool_one",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_triage_tool",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_update_customer_record",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_update_seat",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_visible_lookup_account",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_will_fail_on_bad_json",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_will_not_fail_on_bad_json",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_will_not_fail_on_bad_json_async",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    },
    {
      "dst": "cap_write_file",
      "provenance": "EXTRACTED",
      "rel": "HAS_CAPABILITY",
      "src": "agent_openai_agents_python"
    }
  ],
  "frameworks": [],
  "nodes": [
    {
      "id": "agent_openai_agents_python",
      "name": "openai-agents-python",
      "props": {
        "source_kind": "python"
      },
      "provenance": "EXTRACTED",
      "type": "Agent"
    },
    {
      "id": "cap_add",
      "name": "add",
      "props": {
        "action": "add"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_add_tool",
      "name": "add_tool",
      "props": {
        "action": "add_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_all_optional_params_function",
      "name": "all_optional_params_function",
      "props": {
        "action": "all_optional_params_function"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_alpha_tool",
      "name": "alpha_tool",
      "props": {
        "action": "alpha_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_already_ran",
      "name": "already_ran",
      "props": {
        "action": "already_ran"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_another_tool",
      "name": "another_tool",
      "props": {
        "action": "another_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_apply_lifecycle_patch",
      "name": "apply_lifecycle_patch",
      "props": {
        "action": "apply_lifecycle_patch"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_approval_echo",
      "name": "approval_echo",
      "props": {
        "action": "approval_echo"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_approval_note",
      "name": "approval_note",
      "props": {
        "action": "approval_note"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_approval_tool",
      "name": "approval_tool",
      "props": {
        "action": "approval_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_approve_me",
      "name": "approve_me",
      "props": {
        "action": "approve_me"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_assert_manifest_materialized_tool",
      "name": "assert_manifest_materialized_tool",
      "props": {
        "action": "assert_manifest_materialized_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_assert_restored_lifecycle_state_tool",
      "name": "assert_restored_lifecycle_state_tool",
      "props": {
        "action": "assert_restored_lifecycle_state_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_assert_workspace_escape_blocked_tool",
      "name": "assert_workspace_escape_blocked_tool",
      "props": {
        "action": "assert_workspace_escape_blocked_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_async_no_context",
      "name": "async_no_context",
      "props": {
        "action": "async_no_context"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_async_with_context",
      "name": "async_with_context",
      "props": {
        "action": "async_with_context"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_bad_tool",
      "name": "bad_tool",
      "props": {
        "action": "bad_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_beta_tool",
      "name": "beta_tool",
      "props": {
        "action": "beta_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_billing_status_checker",
      "name": "billing_status_checker",
      "props": {
        "action": "billing_status_checker"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_boom",
      "name": "boom",
      "props": {
        "action": "boom"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_calculate_sum",
      "name": "calculate_sum",
      "props": {
        "action": "calculate_sum"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_create_config",
      "name": "create_config",
      "props": {
        "action": "create_config"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_dangerous_tool",
      "name": "dangerous_tool",
      "props": {
        "action": "dangerous_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_deferred_lookup",
      "name": "deferred_lookup",
      "props": {
        "action": "deferred_lookup"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_deferred_lookup_account",
      "name": "deferred_lookup_account",
      "props": {
        "action": "deferred_lookup_account"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_delegate_tool",
      "name": "delegate_tool",
      "props": {
        "action": "delegate_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_disabled_tool",
      "name": "disabled_tool",
      "props": {
        "action": "disabled_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_echo",
      "name": "echo",
      "props": {
        "action": "echo"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_echo_tool",
      "name": "echo_tool",
      "props": {
        "action": "echo_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_extract_lifecycle_archive",
      "name": "extract_lifecycle_archive",
      "props": {
        "action": "extract_lifecycle_archive"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_faq_lookup_tool",
      "name": "faq_lookup_tool",
      "props": {
        "action": "faq_lookup_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_fast_tool",
      "name": "fast_tool",
      "props": {
        "action": "fast_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_fetch_random_image",
      "name": "fetch_random_image",
      "props": {
        "action": "fetch_random_image"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_first_approval_tool",
      "name": "first_approval_tool",
      "props": {
        "action": "first_approval_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_foo",
      "name": "foo",
      "props": {
        "action": "foo"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_foo_tool",
      "name": "foo_tool",
      "props": {
        "action": "foo_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_format_message",
      "name": "format_message",
      "props": {
        "action": "format_message"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_contact_info",
      "name": "get_contact_info",
      "props": {
        "action": "get_contact_info"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_current_time",
      "name": "get_current_time",
      "props": {
        "action": "get_current_time"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_current_timestamp",
      "name": "get_current_timestamp",
      "props": {
        "action": "get_current_timestamp"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_current_weather",
      "name": "get_current_weather",
      "props": {
        "action": "get_current_weather"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_customer_profile",
      "name": "get_customer_profile",
      "props": {
        "action": "get_customer_profile"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_discount_approval_path",
      "name": "get_discount_approval_path",
      "props": {
        "action": "get_discount_approval_path"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_discount_approval_rule",
      "name": "get_discount_approval_rule",
      "props": {
        "action": "get_discount_approval_rule"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_invoice_status",
      "name": "get_invoice_status",
      "props": {
        "action": "get_invoice_status"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_metadata",
      "name": "get_metadata",
      "props": {
        "action": "get_metadata"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_policy_reference",
      "name": "get_policy_reference",
      "props": {
        "action": "get_policy_reference"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_secret_word",
      "name": "get_secret_word",
      "props": {
        "action": "get_secret_word"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_shipping_credit_balance",
      "name": "get_shipping_credit_balance",
      "props": {
        "action": "get_shipping_credit_balance"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_shipping_eta",
      "name": "get_shipping_eta",
      "props": {
        "action": "get_shipping_eta"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_temperature",
      "name": "get_temperature",
      "props": {
        "action": "get_temperature"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_user_data",
      "name": "get_user_data",
      "props": {
        "action": "get_user_data"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_user_name",
      "name": "get_user_name",
      "props": {
        "action": "get_user_name"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_get_weather",
      "name": "get_weather",
      "props": {
        "action": "get_weather"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_greet",
      "name": "greet",
      "props": {
        "action": "greet"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_guarded",
      "name": "guarded",
      "props": {
        "action": "guarded"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_helper",
      "name": "helper",
      "props": {
        "action": "helper"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_how_many_jokes",
      "name": "how_many_jokes",
      "props": {
        "action": "how_many_jokes"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_inner_hitl_tool",
      "name": "inner_hitl_tool",
      "props": {
        "action": "inner_hitl_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_inner_sensitive_tool",
      "name": "inner_sensitive_tool",
      "props": {
        "action": "inner_sensitive_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_inner_shared_tool",
      "name": "inner_shared_tool",
      "props": {
        "action": "inner_shared_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_inner_tool",
      "name": "inner_tool",
      "props": {
        "action": "inner_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_known_tool",
      "name": "known_tool",
      "props": {
        "action": "known_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_list_open_orders",
      "name": "list_open_orders",
      "props": {
        "action": "list_open_orders"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_account",
      "name": "lookup_account",
      "props": {
        "action": "lookup_account"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_customer_profile",
      "name": "lookup_customer_profile",
      "props": {
        "action": "lookup_customer_profile"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_insurance_eligibility",
      "name": "lookup_insurance_eligibility",
      "props": {
        "action": "lookup_insurance_eligibility"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_order",
      "name": "lookup_order",
      "props": {
        "action": "lookup_order"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_patient",
      "name": "lookup_patient",
      "props": {
        "action": "lookup_patient"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_referral_status",
      "name": "lookup_referral_status",
      "props": {
        "action": "lookup_referral_status"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_lookup_secret",
      "name": "lookup_secret",
      "props": {
        "action": "lookup_secret"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_multiply_by_two",
      "name": "multiply_by_two",
      "props": {
        "action": "multiply_by_two"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_needs_ok",
      "name": "needs_ok",
      "props": {
        "action": "needs_ok"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_optional_param_function",
      "name": "optional_param_function",
      "props": {
        "action": "optional_param_function"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_other_tool",
      "name": "other_tool",
      "props": {
        "action": "other_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_outer_shared_tool",
      "name": "outer_shared_tool",
      "props": {
        "action": "outer_shared_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_outer_tool",
      "name": "outer_tool",
      "props": {
        "action": "outer_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_pending_me",
      "name": "pending_me",
      "props": {
        "action": "pending_me"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_pending_tool",
      "name": "pending_tool",
      "props": {
        "action": "pending_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_ping",
      "name": "ping",
      "props": {
        "action": "ping"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_publish_announcement",
      "name": "publish_announcement",
      "props": {
        "action": "publish_announcement"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_query_runloop_network_policy",
      "name": "query_runloop_network_policy",
      "props": {
        "action": "query_runloop_network_policy"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_query_runloop_secret",
      "name": "query_runloop_secret",
      "props": {
        "action": "query_runloop_secret"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_random_number",
      "name": "random_number",
      "props": {
        "action": "random_number"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_random_number_tool",
      "name": "random_number_tool",
      "props": {
        "action": "random_number_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_read_file",
      "name": "read_file",
      "props": {
        "action": "read_file"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_record_side_effect",
      "name": "record_side_effect",
      "props": {
        "action": "record_side_effect"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_reject_me",
      "name": "reject_me",
      "props": {
        "action": "reject_me"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_route_to_human_queue",
      "name": "route_to_human_queue",
      "props": {
        "action": "route_to_human_queue"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_second_approval_tool",
      "name": "second_approval_tool",
      "props": {
        "action": "second_approval_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_send_email",
      "name": "send_email",
      "props": {
        "action": "send_email"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_slow_tool",
      "name": "slow_tool",
      "props": {
        "action": "slow_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_start_lifecycle_pty",
      "name": "start_lifecycle_pty",
      "props": {
        "action": "start_lifecycle_pty"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_submit_refund",
      "name": "submit_refund",
      "props": {
        "action": "submit_refund"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_sync_no_context_no_args",
      "name": "sync_no_context_no_args",
      "props": {
        "action": "sync_no_context_no_args"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_sync_no_context_override",
      "name": "sync_no_context_override",
      "props": {
        "action": "sync_no_context_override"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_sync_no_context_with_args",
      "name": "sync_no_context_with_args",
      "props": {
        "action": "sync_no_context_with_args"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_sync_tool_decorator_style",
      "name": "sync_tool_decorator_style",
      "props": {
        "action": "sync_tool_decorator_style"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_sync_with_context",
      "name": "sync_with_context",
      "props": {
        "action": "sync_with_context"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_synthetic_tool",
      "name": "synthetic_tool",
      "props": {
        "action": "synthetic_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_test_tool",
      "name": "test_tool",
      "props": {
        "action": "test_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_test_tool_one",
      "name": "test_tool_one",
      "props": {
        "action": "test_tool_one"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_test_tool_two",
      "name": "test_tool_two",
      "props": {
        "action": "test_tool_two"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_timeout_configured_tool",
      "name": "timeout_configured_tool",
      "props": {
        "action": "timeout_configured_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_timeout_tool",
      "name": "timeout_tool",
      "props": {
        "action": "timeout_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_tool2",
      "name": "tool2",
      "props": {
        "action": "tool2"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_tool_one",
      "name": "tool_one",
      "props": {
        "action": "tool_one"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_triage_tool",
      "name": "triage_tool",
      "props": {
        "action": "triage_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_update_customer_record",
      "name": "update_customer_record",
      "props": {
        "action": "update_customer_record"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_update_seat",
      "name": "update_seat",
      "props": {
        "action": "update_seat"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_visible_lookup_account",
      "name": "visible_lookup_account",
      "props": {
        "action": "visible_lookup_account"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_will_fail_on_bad_json",
      "name": "will_fail_on_bad_json",
      "props": {
        "action": "will_fail_on_bad_json"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_will_not_fail_on_bad_json",
      "name": "will_not_fail_on_bad_json",
      "props": {
        "action": "will_not_fail_on_bad_json"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_will_not_fail_on_bad_json_async",
      "name": "will_not_fail_on_bad_json_async",
      "props": {
        "action": "will_not_fail_on_bad_json_async"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "cap_write_file",
      "name": "write_file",
      "props": {
        "action": "write_file"
      },
      "provenance": "EXTRACTED",
      "type": "Capability"
    },
    {
      "id": "fn_approve",
      "name": "approve",
      "props": {
        "action": "approve"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_approve_first_interruption",
      "name": "approve_first_interruption",
      "props": {
        "action": "approve_first_interruption"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_approve_tool",
      "name": "approve_tool",
      "props": {
        "action": "approve_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_approve_tool_call",
      "name": "approve_tool_call",
      "props": {
        "action": "approve_tool_call"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete",
      "name": "delete",
      "props": {
        "action": "delete"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_branch",
      "name": "delete_branch",
      "props": {
        "action": "delete_branch"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_cached_snapshot_fingerprint_best_effort",
      "name": "delete_cached_snapshot_fingerprint_best_effort",
      "props": {
        "action": "delete_cached_snapshot_fingerprint_best_effort"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_file",
      "name": "delete_file",
      "props": {
        "action": "delete_file"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_many",
      "name": "delete_many",
      "props": {
        "action": "delete_many"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_one",
      "name": "delete_one",
      "props": {
        "action": "delete_one"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_session",
      "name": "delete_session",
      "props": {
        "action": "delete_session"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_delete_state",
      "name": "delete_state",
      "props": {
        "action": "delete_state"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_drop_agent_tool_run_result",
      "name": "drop_agent_tool_run_result",
      "props": {
        "action": "drop_agent_tool_run_result"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_drop_orphan_function_calls",
      "name": "drop_orphan_function_calls",
      "props": {
        "action": "drop_orphan_function_calls"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec",
      "name": "exec",
      "props": {
        "action": "exec"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_async",
      "name": "exec_async",
      "props": {
        "action": "exec_async"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_checked_nonzero",
      "name": "exec_checked_nonzero",
      "props": {
        "action": "exec_checked_nonzero"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_command_needs_approval",
      "name": "exec_command_needs_approval",
      "props": {
        "action": "exec_command_needs_approval"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_create",
      "name": "exec_create",
      "props": {
        "action": "exec_create"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_inspect",
      "name": "exec_inspect",
      "props": {
        "action": "exec_inspect"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_run",
      "name": "exec_run",
      "props": {
        "action": "exec_run"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_exec_start",
      "name": "exec_start",
      "props": {
        "action": "exec_start"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute",
      "name": "execute",
      "props": {
        "action": "execute"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_apply_patch_calls",
      "name": "execute_apply_patch_calls",
      "props": {
        "action": "execute_apply_patch_calls"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_approved_tools",
      "name": "execute_approved_tools",
      "props": {
        "action": "execute_approved_tools"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_computer_actions",
      "name": "execute_computer_actions",
      "props": {
        "action": "execute_computer_actions"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_custom_tool_calls",
      "name": "execute_custom_tool_calls",
      "props": {
        "action": "execute_custom_tool_calls"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_final_output",
      "name": "execute_final_output",
      "props": {
        "action": "execute_final_output"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_final_output_step",
      "name": "execute_final_output_step",
      "props": {
        "action": "execute_final_output_step"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_function_tool_calls",
      "name": "execute_function_tool_calls",
      "props": {
        "action": "execute_function_tool_calls"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_handoffs",
      "name": "execute_handoffs",
      "props": {
        "action": "execute_handoffs"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_local_shell_calls",
      "name": "execute_local_shell_calls",
      "props": {
        "action": "execute_local_shell_calls"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_mcp_approval_requests",
      "name": "execute_mcp_approval_requests",
      "props": {
        "action": "execute_mcp_approval_requests"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_session_command",
      "name": "execute_session_command",
      "props": {
        "action": "execute_session_command"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_shell_calls",
      "name": "execute_shell_calls",
      "props": {
        "action": "execute_shell_calls"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_tools_and_side_effects",
      "name": "execute_tools_and_side_effects",
      "props": {
        "action": "execute_tools_and_side_effects"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_execute_with_shuffle",
      "name": "execute_with_shuffle",
      "props": {
        "action": "execute_with_shuffle"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_export",
      "name": "export",
      "props": {
        "action": "export"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_post",
      "name": "post",
      "props": {
        "action": "post"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_provision_accounts",
      "name": "provision_accounts",
      "props": {
        "action": "provision_accounts"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_provision_manifest_accounts",
      "name": "provision_manifest_accounts",
      "props": {
        "action": "provision_manifest_accounts"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_publish",
      "name": "publish",
      "props": {
        "action": "publish"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_reject",
      "name": "reject",
      "props": {
        "action": "reject"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_reject_tool",
      "name": "reject_tool",
      "props": {
        "action": "reject_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_reject_tool_call",
      "name": "reject_tool_call",
      "props": {
        "action": "reject_tool_call"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_release_agent",
      "name": "release_agent",
      "props": {
        "action": "release_agent"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_release_agents",
      "name": "release_agents",
      "props": {
        "action": "release_agents"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_release_waiters",
      "name": "release_waiters",
      "props": {
        "action": "release_waiters"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run",
      "name": "run",
      "props": {
        "action": "run"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_agent",
      "name": "run_agent",
      "props": {
        "action": "run_agent"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_agent_async",
      "name": "run_agent_async",
      "props": {
        "action": "run_agent_async"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_and_resume",
      "name": "run_and_resume",
      "props": {
        "action": "run_and_resume"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_and_resume_after_approval",
      "name": "run_and_resume_after_approval",
      "props": {
        "action": "run_and_resume_after_approval"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_and_resume_with_mutation",
      "name": "run_and_resume_with_mutation",
      "props": {
        "action": "run_and_resume_with_mutation"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_command",
      "name": "run_command",
      "props": {
        "action": "run_command"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_compaction",
      "name": "run_compaction",
      "props": {
        "action": "run_compaction"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_conversation",
      "name": "run_conversation",
      "props": {
        "action": "run_conversation"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_demo_loop",
      "name": "run_demo_loop",
      "props": {
        "action": "run_demo_loop"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_examples",
      "name": "run_examples",
      "props": {
        "action": "run_examples"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_execute_approved_tools",
      "name": "run_execute_approved_tools",
      "props": {
        "action": "run_execute_approved_tools"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_execute_with_processed_response",
      "name": "run_execute_with_processed_response",
      "props": {
        "action": "run_execute_with_processed_response"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_file_session_scenario",
      "name": "run_file_session_scenario",
      "props": {
        "action": "run_file_session_scenario"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_final_output_hooks",
      "name": "run_final_output_hooks",
      "props": {
        "action": "run_final_output_hooks"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_function",
      "name": "run_function",
      "props": {
        "action": "run_function"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_git",
      "name": "run_git",
      "props": {
        "action": "run_git"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_healthcare_support_workflow",
      "name": "run_healthcare_support_workflow",
      "props": {
        "action": "run_healthcare_support_workflow"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_in_listener_task",
      "name": "run_in_listener_task",
      "props": {
        "action": "run_in_listener_task"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_input_guardrails",
      "name": "run_input_guardrails",
      "props": {
        "action": "run_input_guardrails"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_input_guardrails_with_queue",
      "name": "run_input_guardrails_with_queue",
      "props": {
        "action": "run_input_guardrails_with_queue"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_interactive_loop",
      "name": "run_interactive_loop",
      "props": {
        "action": "run_interactive_loop"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_item_to_input_item",
      "name": "run_item_to_input_item",
      "props": {
        "action": "run_item_to_input_item"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_items_to_input_items",
      "name": "run_items_to_input_items",
      "props": {
        "action": "run_items_to_input_items"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_mount_smoke_test",
      "name": "run_mount_smoke_test",
      "props": {
        "action": "run_mount_smoke_test"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_namespaced_example",
      "name": "run_namespaced_example",
      "props": {
        "action": "run_namespaced_example"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_once",
      "name": "run_once",
      "props": {
        "action": "run_once"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_openai_session_scenario",
      "name": "run_openai_session_scenario",
      "props": {
        "action": "run_openai_session_scenario"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_output_guardrails",
      "name": "run_output_guardrails",
      "props": {
        "action": "run_output_guardrails"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_phase_one",
      "name": "run_phase_one",
      "props": {
        "action": "run_phase_one"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_phase_two",
      "name": "run_phase_two",
      "props": {
        "action": "run_phase_two"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_pre_stop_hooks",
      "name": "run_pre_stop_hooks",
      "props": {
        "action": "run_pre_stop_hooks"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_resume",
      "name": "run_resume",
      "props": {
        "action": "run_resume"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_scenario_step",
      "name": "run_scenario_step",
      "props": {
        "action": "run_scenario_step"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_single",
      "name": "run_single",
      "props": {
        "action": "run_single"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_single_approval",
      "name": "run_single_approval",
      "props": {
        "action": "run_single_approval"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_single_input_guardrail",
      "name": "run_single_input_guardrail",
      "props": {
        "action": "run_single_input_guardrail"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_single_output_guardrail",
      "name": "run_single_output_guardrail",
      "props": {
        "action": "run_single_output_guardrail"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_single_turn",
      "name": "run_single_turn",
      "props": {
        "action": "run_single_turn"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_single_turn_streamed",
      "name": "run_single_turn_streamed",
      "props": {
        "action": "run_single_turn_streamed"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_sql",
      "name": "run_sql",
      "props": {
        "action": "run_sql"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_step",
      "name": "run_step",
      "props": {
        "action": "run_step"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_streamed",
      "name": "run_streamed",
      "props": {
        "action": "run_streamed"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_streamed_turn",
      "name": "run_streamed_turn",
      "props": {
        "action": "run_streamed_turn"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_subtask",
      "name": "run_subtask",
      "props": {
        "action": "run_subtask"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_sync",
      "name": "run_sync",
      "props": {
        "action": "run_sync"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_tasks_as_children",
      "name": "run_tasks_as_children",
      "props": {
        "action": "run_tasks_as_children"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_tasks_parallel",
      "name": "run_tasks_parallel",
      "props": {
        "action": "run_tasks_parallel"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_tool",
      "name": "run_tool",
      "props": {
        "action": "run_tool"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_top_level_example",
      "name": "run_top_level_example",
      "props": {
        "action": "run_top_level_example"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_turn",
      "name": "run_turn",
      "props": {
        "action": "run_turn"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_with_auto_approval",
      "name": "run_with_auto_approval",
      "props": {
        "action": "run_with_auto_approval"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_with_custom_client",
      "name": "run_with_custom_client",
      "props": {
        "action": "run_with_custom_client"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_run_worker",
      "name": "run_worker",
      "props": {
        "action": "run_worker"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send",
      "name": "send",
      "props": {
        "action": "send"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_audio",
      "name": "send_audio",
      "props": {
        "action": "send_audio"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_bytes",
      "name": "send_bytes",
      "props": {
        "action": "send_bytes"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_client_event",
      "name": "send_client_event",
      "props": {
        "action": "send_client_event"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_event",
      "name": "send_event",
      "props": {
        "action": "send_event"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_input",
      "name": "send_input",
      "props": {
        "action": "send_input"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_message",
      "name": "send_message",
      "props": {
        "action": "send_message"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_mic_audio",
      "name": "send_mic_audio",
      "props": {
        "action": "send_mic_audio"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_new",
      "name": "send_new",
      "props": {
        "action": "send_new"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_std_in",
      "name": "send_std_in",
      "props": {
        "action": "send_std_in"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_stdin",
      "name": "send_stdin",
      "props": {
        "action": "send_stdin"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_str",
      "name": "send_str",
      "props": {
        "action": "send_str"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_tool_output",
      "name": "send_tool_output",
      "props": {
        "action": "send_tool_output"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_send_user_message",
      "name": "send_user_message",
      "props": {
        "action": "send_user_message"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_shutdown",
      "name": "shutdown",
      "props": {
        "action": "shutdown"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_terminate",
      "name": "terminate",
      "props": {
        "action": "terminate"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_upload",
      "name": "upload",
      "props": {
        "action": "upload"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    },
    {
      "id": "fn_upload_file",
      "name": "upload_file",
      "props": {
        "action": "upload_file"
      },
      "provenance": "EXTRACTED",
      "type": "Task"
    }
  ],
  "note": "Proposed CWN mappings, confidence-tagged. Confirm against the current published control text before relying on them for audit. Enterprise control ids are mapped at onboarding by your GRC team, never auto-asserted.",
  "source": "openai-agents-python",
  "source_kind": "python"
}
