{
  "alg": "Ed25519",
  "atom_id": "oao-OPENAIAGENTS-25e53abe2a",
  "decision": "GOVERNED:UNGOVERNED",
  "evidence": {
    "ontology": {
      "action_maps": [
        {
          "label": "add",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_add"
        },
        {
          "label": "add_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_add_tool"
        },
        {
          "label": "all_optional_params_function",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_all_optional_params_function"
        },
        {
          "label": "alpha_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_alpha_tool"
        },
        {
          "label": "already_ran",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_already_ran"
        },
        {
          "label": "another_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_another_tool"
        },
        {
          "label": "apply_lifecycle_patch",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_apply_lifecycle_patch"
        },
        {
          "label": "approval_echo",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_approval_echo"
        },
        {
          "label": "approval_note",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_approval_note"
        },
        {
          "label": "approval_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_approval_tool"
        },
        {
          "label": "approve_me",
          "mappings": [
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_approve_me"
        },
        {
          "label": "assert_manifest_materialized_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_assert_manifest_materialized_tool"
        },
        {
          "label": "assert_restored_lifecycle_state_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_assert_restored_lifecycle_state_tool"
        },
        {
          "label": "assert_workspace_escape_blocked_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_assert_workspace_escape_blocked_tool"
        },
        {
          "label": "async_no_context",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_async_no_context"
        },
        {
          "label": "async_with_context",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_async_with_context"
        },
        {
          "label": "bad_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_bad_tool"
        },
        {
          "label": "beta_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_beta_tool"
        },
        {
          "label": "billing_status_checker",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_billing_status_checker"
        },
        {
          "label": "boom",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_boom"
        },
        {
          "label": "calculate_sum",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_calculate_sum"
        },
        {
          "label": "create_config",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_create_config"
        },
        {
          "label": "dangerous_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_dangerous_tool"
        },
        {
          "label": "deferred_lookup",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_deferred_lookup"
        },
        {
          "label": "deferred_lookup_account",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_deferred_lookup_account"
        },
        {
          "label": "delegate_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_delegate_tool"
        },
        {
          "label": "disabled_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_disabled_tool"
        },
        {
          "label": "echo",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_echo"
        },
        {
          "label": "echo_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_echo_tool"
        },
        {
          "label": "extract_lifecycle_archive",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_extract_lifecycle_archive"
        },
        {
          "label": "faq_lookup_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_faq_lookup_tool"
        },
        {
          "label": "fast_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_fast_tool"
        },
        {
          "label": "fetch_random_image",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_fetch_random_image"
        },
        {
          "label": "first_approval_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_first_approval_tool"
        },
        {
          "label": "foo",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_foo"
        },
        {
          "label": "foo_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_foo_tool"
        },
        {
          "label": "format_message",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_format_message"
        },
        {
          "label": "get_contact_info",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_contact_info"
        },
        {
          "label": "get_current_time",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_current_time"
        },
        {
          "label": "get_current_timestamp",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_current_timestamp"
        },
        {
          "label": "get_current_weather",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_current_weather"
        },
        {
          "label": "get_customer_profile",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_customer_profile"
        },
        {
          "label": "get_discount_approval_path",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_discount_approval_path"
        },
        {
          "label": "get_discount_approval_rule",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_discount_approval_rule"
        },
        {
          "label": "get_invoice_status",
          "mappings": [
            {
              "basis": "inferred from action verb 'invoice'; confirm against published text (asserted basis: Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-5",
              "name": "Separation of Duties",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'invoice'; confirm against published text (asserted basis: A high-value financial action by an automated system requires effective human oversight before it takes effect.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'invoice'; confirm against published text (asserted basis: An agent moving money without a second authorizer is the canonical excessive-agency failure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MANAGE",
              "name": "Manage function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "separation of duties mitigates valid-account / privilege abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1078",
              "name": "Valid Accounts",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_get_invoice_status"
        },
        {
          "label": "get_metadata",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_metadata"
        },
        {
          "label": "get_policy_reference",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_policy_reference"
        },
        {
          "label": "get_secret_word",
          "mappings": [
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Refusing to handle data above a classification ceiling enforces the categorization of the resource.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "RA-2",
              "name": "Security Categorization",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: The ceiling governs the flow of classified information through the agent.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Handling over-classified data is a data-governance violation.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Processing restricted data above ceiling risks sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "handling data above a classification ceiling maps to sensitive-data access",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1530",
              "name": "Data from Cloud Storage",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_get_secret_word"
        },
        {
          "label": "get_shipping_credit_balance",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_shipping_credit_balance"
        },
        {
          "label": "get_shipping_eta",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_shipping_eta"
        },
        {
          "label": "get_temperature",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_temperature"
        },
        {
          "label": "get_user_data",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_user_data"
        },
        {
          "label": "get_user_name",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_user_name"
        },
        {
          "label": "get_weather",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_get_weather"
        },
        {
          "label": "greet",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_greet"
        },
        {
          "label": "guarded",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_guarded"
        },
        {
          "label": "helper",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_helper"
        },
        {
          "label": "how_many_jokes",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_how_many_jokes"
        },
        {
          "label": "inner_hitl_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_inner_hitl_tool"
        },
        {
          "label": "inner_sensitive_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_inner_sensitive_tool"
        },
        {
          "label": "inner_shared_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_inner_shared_tool"
        },
        {
          "label": "inner_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_inner_tool"
        },
        {
          "label": "known_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_known_tool"
        },
        {
          "label": "list_open_orders",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_list_open_orders"
        },
        {
          "label": "lookup_account",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_lookup_account"
        },
        {
          "label": "lookup_customer_profile",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_lookup_customer_profile"
        },
        {
          "label": "lookup_insurance_eligibility",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_lookup_insurance_eligibility"
        },
        {
          "label": "lookup_order",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_lookup_order"
        },
        {
          "label": "lookup_patient",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_lookup_patient"
        },
        {
          "label": "lookup_referral_status",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_lookup_referral_status"
        },
        {
          "label": "lookup_secret",
          "mappings": [
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Refusing to handle data above a classification ceiling enforces the categorization of the resource.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "RA-2",
              "name": "Security Categorization",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: The ceiling governs the flow of classified information through the agent.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Handling over-classified data is a data-governance violation.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Processing restricted data above ceiling risks sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "handling data above a classification ceiling maps to sensitive-data access",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1530",
              "name": "Data from Cloud Storage",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_lookup_secret"
        },
        {
          "label": "multiply_by_two",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_multiply_by_two"
        },
        {
          "label": "needs_ok",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_needs_ok"
        },
        {
          "label": "optional_param_function",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_optional_param_function"
        },
        {
          "label": "other_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_other_tool"
        },
        {
          "label": "outer_shared_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_outer_shared_tool"
        },
        {
          "label": "outer_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_outer_tool"
        },
        {
          "label": "pending_me",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_pending_me"
        },
        {
          "label": "pending_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_pending_tool"
        },
        {
          "label": "ping",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_ping"
        },
        {
          "label": "publish_announcement",
          "mappings": [
            {
              "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_publish_announcement"
        },
        {
          "label": "query_runloop_network_policy",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_query_runloop_network_policy"
        },
        {
          "label": "query_runloop_secret",
          "mappings": [
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Refusing to handle data above a classification ceiling enforces the categorization of the resource.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "RA-2",
              "name": "Security Categorization",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: The ceiling governs the flow of classified information through the agent.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Handling over-classified data is a data-governance violation.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'secret'; confirm against published text (asserted basis: Processing restricted data above ceiling risks sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "handling data above a classification ceiling maps to sensitive-data access",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1530",
              "name": "Data from Cloud Storage",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_query_runloop_secret"
        },
        {
          "label": "random_number",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_random_number"
        },
        {
          "label": "random_number_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_random_number_tool"
        },
        {
          "label": "read_file",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_read_file"
        },
        {
          "label": "record_side_effect",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_record_side_effect"
        },
        {
          "label": "reject_me",
          "mappings": [
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_reject_me"
        },
        {
          "label": "route_to_human_queue",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_route_to_human_queue"
        },
        {
          "label": "second_approval_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_second_approval_tool"
        },
        {
          "label": "send_email",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_send_email"
        },
        {
          "label": "slow_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_slow_tool"
        },
        {
          "label": "start_lifecycle_pty",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_start_lifecycle_pty"
        },
        {
          "label": "submit_refund",
          "mappings": [
            {
              "basis": "inferred from action verb 'refund'; confirm against published text (asserted basis: Dual control is the textbook separation-of-duties control: no single actor (here, one agent) completes a sensitive transaction alone.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-5",
              "name": "Separation of Duties",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'refund'; confirm against published text (asserted basis: A high-value financial action by an automated system requires effective human oversight before it takes effect.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'refund'; confirm against published text (asserted basis: An agent moving money without a second authorizer is the canonical excessive-agency failure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Risk treatment: enforce a control commensurate with transaction risk.",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MANAGE",
              "name": "Manage function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "separation of duties mitigates valid-account / privilege abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1078",
              "name": "Valid Accounts",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_submit_refund"
        },
        {
          "label": "sync_no_context_no_args",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_sync_no_context_no_args"
        },
        {
          "label": "sync_no_context_override",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_sync_no_context_override"
        },
        {
          "label": "sync_no_context_with_args",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_sync_no_context_with_args"
        },
        {
          "label": "sync_tool_decorator_style",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_sync_tool_decorator_style"
        },
        {
          "label": "sync_with_context",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_sync_with_context"
        },
        {
          "label": "synthetic_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_synthetic_tool"
        },
        {
          "label": "test_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_test_tool"
        },
        {
          "label": "test_tool_one",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_test_tool_one"
        },
        {
          "label": "test_tool_two",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_test_tool_two"
        },
        {
          "label": "timeout_configured_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_timeout_configured_tool"
        },
        {
          "label": "timeout_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_timeout_tool"
        },
        {
          "label": "tool2",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_tool2"
        },
        {
          "label": "tool_one",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_tool_one"
        },
        {
          "label": "triage_tool",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_triage_tool"
        },
        {
          "label": "update_customer_record",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_update_customer_record"
        },
        {
          "label": "update_seat",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_update_seat"
        },
        {
          "label": "visible_lookup_account",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_visible_lookup_account"
        },
        {
          "label": "will_fail_on_bad_json",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_will_fail_on_bad_json"
        },
        {
          "label": "will_not_fail_on_bad_json",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_will_not_fail_on_bad_json"
        },
        {
          "label": "will_not_fail_on_bad_json_async",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "cap_will_not_fail_on_bad_json_async"
        },
        {
          "label": "write_file",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "cap_write_file"
        },
        {
          "label": "approve",
          "mappings": [
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_approve"
        },
        {
          "label": "approve_first_interruption",
          "mappings": [
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_approve_first_interruption"
        },
        {
          "label": "approve_tool",
          "mappings": [
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_approve_tool"
        },
        {
          "label": "approve_tool_call",
          "mappings": [
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'approve'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_approve_tool_call"
        },
        {
          "label": "delete",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete"
        },
        {
          "label": "delete_branch",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_branch"
        },
        {
          "label": "delete_cached_snapshot_fingerprint_best_effort",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_cached_snapshot_fingerprint_best_effort"
        },
        {
          "label": "delete_file",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_file"
        },
        {
          "label": "delete_many",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_many"
        },
        {
          "label": "delete_one",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_one"
        },
        {
          "label": "delete_session",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_session"
        },
        {
          "label": "delete_state",
          "mappings": [
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'delete'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_delete_state"
        },
        {
          "label": "drop_agent_tool_run_result",
          "mappings": [
            {
              "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_drop_agent_tool_run_result"
        },
        {
          "label": "drop_orphan_function_calls",
          "mappings": [
            {
              "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Honoring a change freeze is configuration change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: A freeze restricts who/when changes may be applied.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-5",
              "name": "Access Restrictions for Change",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'drop'; confirm against published text (asserted basis: Deploying during a freeze is acting beyond authority.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "a destructive change during a freeze maps to data destruction",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1485",
              "name": "Data Destruction",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_drop_orphan_function_calls"
        },
        {
          "label": "exec",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec"
        },
        {
          "label": "exec_async",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec_async"
        },
        {
          "label": "exec_checked_nonzero",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec_checked_nonzero"
        },
        {
          "label": "exec_command_needs_approval",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec_command_needs_approval"
        },
        {
          "label": "exec_create",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec_create"
        },
        {
          "label": "exec_inspect",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec_inspect"
        },
        {
          "label": "exec_run",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_exec_run"
        },
        {
          "label": "exec_start",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_exec_start"
        },
        {
          "label": "execute",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute"
        },
        {
          "label": "execute_apply_patch_calls",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_apply_patch_calls"
        },
        {
          "label": "execute_approved_tools",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_approved_tools"
        },
        {
          "label": "execute_computer_actions",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_computer_actions"
        },
        {
          "label": "execute_custom_tool_calls",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_custom_tool_calls"
        },
        {
          "label": "execute_final_output",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_final_output"
        },
        {
          "label": "execute_final_output_step",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_final_output_step"
        },
        {
          "label": "execute_function_tool_calls",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_function_tool_calls"
        },
        {
          "label": "execute_handoffs",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_handoffs"
        },
        {
          "label": "execute_local_shell_calls",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_local_shell_calls"
        },
        {
          "label": "execute_mcp_approval_requests",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_mcp_approval_requests"
        },
        {
          "label": "execute_session_command",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_session_command"
        },
        {
          "label": "execute_shell_calls",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_shell_calls"
        },
        {
          "label": "execute_tools_and_side_effects",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_tools_and_side_effects"
        },
        {
          "label": "execute_with_shuffle",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_execute_with_shuffle"
        },
        {
          "label": "export",
          "mappings": [
            {
              "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'export'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_export"
        },
        {
          "label": "post",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_post"
        },
        {
          "label": "provision_accounts",
          "mappings": [
            {
              "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_provision_accounts"
        },
        {
          "label": "provision_manifest_accounts",
          "mappings": [
            {
              "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'provision'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_provision_manifest_accounts"
        },
        {
          "label": "publish",
          "mappings": [
            {
              "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'publish'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_publish"
        },
        {
          "label": "reject",
          "mappings": [
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_reject"
        },
        {
          "label": "reject_tool",
          "mappings": [
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_reject_tool"
        },
        {
          "label": "reject_tool_call",
          "mappings": [
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'reject'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_reject_tool_call"
        },
        {
          "label": "release_agent",
          "mappings": [
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_release_agent"
        },
        {
          "label": "release_agents",
          "mappings": [
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_release_agents"
        },
        {
          "label": "release_waiters",
          "mappings": [
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Requiring an approved change request is the core of change control.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "CM-3",
              "name": "Configuration Change Control",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: An unapproved production change by an agent needs human sign-off.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'release'; confirm against published text (asserted basis: Deploying without approval is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "an unapproved production change maps to system-process modification / persistence",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1543",
              "name": "Create or Modify System Process",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_release_waiters"
        },
        {
          "label": "run",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run"
        },
        {
          "label": "run_agent",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_agent"
        },
        {
          "label": "run_agent_async",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_agent_async"
        },
        {
          "label": "run_and_resume",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_and_resume"
        },
        {
          "label": "run_and_resume_after_approval",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_and_resume_after_approval"
        },
        {
          "label": "run_and_resume_with_mutation",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_and_resume_with_mutation"
        },
        {
          "label": "run_command",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_command"
        },
        {
          "label": "run_compaction",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_compaction"
        },
        {
          "label": "run_conversation",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_conversation"
        },
        {
          "label": "run_demo_loop",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_demo_loop"
        },
        {
          "label": "run_examples",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_examples"
        },
        {
          "label": "run_execute_approved_tools",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_execute_approved_tools"
        },
        {
          "label": "run_execute_with_processed_response",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_execute_with_processed_response"
        },
        {
          "label": "run_file_session_scenario",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_file_session_scenario"
        },
        {
          "label": "run_final_output_hooks",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_final_output_hooks"
        },
        {
          "label": "run_function",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_function"
        },
        {
          "label": "run_git",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_git"
        },
        {
          "label": "run_healthcare_support_workflow",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_healthcare_support_workflow"
        },
        {
          "label": "run_in_listener_task",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_in_listener_task"
        },
        {
          "label": "run_input_guardrails",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_input_guardrails"
        },
        {
          "label": "run_input_guardrails_with_queue",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_input_guardrails_with_queue"
        },
        {
          "label": "run_interactive_loop",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_interactive_loop"
        },
        {
          "label": "run_item_to_input_item",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_item_to_input_item"
        },
        {
          "label": "run_items_to_input_items",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_items_to_input_items"
        },
        {
          "label": "run_mount_smoke_test",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_mount_smoke_test"
        },
        {
          "label": "run_namespaced_example",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_namespaced_example"
        },
        {
          "label": "run_once",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_once"
        },
        {
          "label": "run_openai_session_scenario",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_openai_session_scenario"
        },
        {
          "label": "run_output_guardrails",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_output_guardrails"
        },
        {
          "label": "run_phase_one",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_phase_one"
        },
        {
          "label": "run_phase_two",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_phase_two"
        },
        {
          "label": "run_pre_stop_hooks",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_pre_stop_hooks"
        },
        {
          "label": "run_resume",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_resume"
        },
        {
          "label": "run_scenario_step",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_scenario_step"
        },
        {
          "label": "run_single",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_single"
        },
        {
          "label": "run_single_approval",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_single_approval"
        },
        {
          "label": "run_single_input_guardrail",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_single_input_guardrail"
        },
        {
          "label": "run_single_output_guardrail",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_single_output_guardrail"
        },
        {
          "label": "run_single_turn",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_single_turn"
        },
        {
          "label": "run_single_turn_streamed",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_single_turn_streamed"
        },
        {
          "label": "run_sql",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_sql"
        },
        {
          "label": "run_step",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_step"
        },
        {
          "label": "run_streamed",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_streamed"
        },
        {
          "label": "run_streamed_turn",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_streamed_turn"
        },
        {
          "label": "run_subtask",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_subtask"
        },
        {
          "label": "run_sync",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_sync"
        },
        {
          "label": "run_tasks_as_children",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_tasks_as_children"
        },
        {
          "label": "run_tasks_parallel",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_tasks_parallel"
        },
        {
          "label": "run_tool",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_tool"
        },
        {
          "label": "run_top_level_example",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_top_level_example"
        },
        {
          "label": "run_turn",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_turn"
        },
        {
          "label": "run_with_auto_approval",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_with_auto_approval"
        },
        {
          "label": "run_with_custom_client",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_with_custom_client"
        },
        {
          "label": "run_worker",
          "mappings": [
            {
              "basis": "heuristic: side-effecting action with no second authorizer detected -- confirm against published text",
              "confidence": "ambiguous",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "AMBIGUOUS"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_run_worker"
        },
        {
          "label": "send",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send"
        },
        {
          "label": "send_audio",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_audio"
        },
        {
          "label": "send_bytes",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_bytes"
        },
        {
          "label": "send_client_event",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_client_event"
        },
        {
          "label": "send_event",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_event"
        },
        {
          "label": "send_input",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_input"
        },
        {
          "label": "send_message",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_message"
        },
        {
          "label": "send_mic_audio",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_mic_audio"
        },
        {
          "label": "send_new",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_new"
        },
        {
          "label": "send_std_in",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_std_in"
        },
        {
          "label": "send_stdin",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_stdin"
        },
        {
          "label": "send_str",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_str"
        },
        {
          "label": "send_tool_output",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_tool_output"
        },
        {
          "label": "send_user_message",
          "mappings": [
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'send'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_send_user_message"
        },
        {
          "label": "shutdown",
          "mappings": [],
          "matched_via": "none",
          "subject_id": "fn_shutdown"
        },
        {
          "label": "terminate",
          "mappings": [
            {
              "basis": "inferred from action verb 'terminate'; confirm against published text (asserted basis: An adverse automated decision affecting a person requires human oversight before it is issued.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 14",
              "name": "Human oversight",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'terminate'; confirm against published text (asserted basis: Issuing an adverse decision with no human in the loop is excessive agency.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM06",
              "name": "Excessive Agency",
              "provenance": "INFERRED"
            },
            {
              "basis": "Adverse outcomes are a measured risk requiring a treatment (human review).",
              "confidence": "advisory",
              "fw": "NIST AI RMF",
              "id": "MEASURE",
              "name": "Measure function",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "autonomous execution without oversight maps to command/scripting abuse",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_terminate"
        },
        {
          "label": "upload",
          "mappings": [
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_upload"
        },
        {
          "label": "upload_file",
          "mappings": [
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Blocking export to an out-of-scope endpoint is information-flow enforcement.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "AC-4",
              "name": "Information Flow Enforcement",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Preventing data leaving the controlled boundary is boundary protection.)",
              "confidence": "inferred",
              "fw": "NIST SP 800-53r5",
              "id": "SC-7",
              "name": "Boundary Protection",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Uncontrolled egress of regulated data is a data-governance failure.)",
              "confidence": "inferred",
              "fw": "EU AI Act",
              "id": "Art 10",
              "name": "Data and data governance",
              "provenance": "INFERRED"
            },
            {
              "basis": "inferred from action verb 'upload'; confirm against published text (asserted basis: Egress of regulated records is sensitive-information disclosure.)",
              "confidence": "inferred",
              "fw": "OWASP LLM Top 10 (2025)",
              "id": "LLM02",
              "name": "Sensitive Information Disclosure",
              "provenance": "INFERRED"
            },
            {
              "basis": "Data leaving to an external domain maps to the Exfiltration tactic; confirm the specific technique with an analyst.",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "TA0010",
              "name": "Exfiltration",
              "provenance": "EXTRACTED"
            },
            {
              "basis": "uncontrolled egress of regulated data maps to exfiltration",
              "confidence": "advisory",
              "fw": "MITRE ATT&CK",
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "provenance": "EXTRACTED"
            }
          ],
          "matched_via": "heuristic",
          "subject_id": "fn_upload_file"
        }
      ],
      "edges": [
        {
          "dst": "fn_approve",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_approve_first_interruption",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_approve_tool",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_approve_tool_call",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_branch",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_cached_snapshot_fingerprint_best_effort",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_file",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_many",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_one",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_session",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_delete_state",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_drop_agent_tool_run_result",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_drop_orphan_function_calls",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_async",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_checked_nonzero",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_command_needs_approval",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_create",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_inspect",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_run",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_exec_start",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_apply_patch_calls",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_approved_tools",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_computer_actions",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_custom_tool_calls",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_final_output",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_final_output_step",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_function_tool_calls",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_handoffs",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_local_shell_calls",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_mcp_approval_requests",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_session_command",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_shell_calls",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_tools_and_side_effects",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_execute_with_shuffle",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_export",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_post",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_provision_accounts",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_provision_manifest_accounts",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_publish",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_reject",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_reject_tool",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_reject_tool_call",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_release_agent",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_release_agents",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_release_waiters",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_agent",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_agent_async",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_and_resume",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_and_resume_after_approval",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_and_resume_with_mutation",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_command",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_compaction",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_conversation",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_demo_loop",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_examples",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_execute_approved_tools",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_execute_with_processed_response",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_file_session_scenario",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_final_output_hooks",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_function",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_git",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_healthcare_support_workflow",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_in_listener_task",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_input_guardrails",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_input_guardrails_with_queue",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_interactive_loop",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_item_to_input_item",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_items_to_input_items",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_mount_smoke_test",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_namespaced_example",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_once",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_openai_session_scenario",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_output_guardrails",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_phase_one",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_phase_two",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_pre_stop_hooks",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_resume",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_scenario_step",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_single",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_single_approval",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_single_input_guardrail",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_single_output_guardrail",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_single_turn",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_single_turn_streamed",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_sql",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_step",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_streamed",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_streamed_turn",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_subtask",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_sync",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_tasks_as_children",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_tasks_parallel",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_tool",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_top_level_example",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_turn",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_with_auto_approval",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_with_custom_client",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_run_worker",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_audio",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_bytes",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_client_event",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_event",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_input",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_message",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_mic_audio",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_new",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_std_in",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_stdin",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_str",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_tool_output",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_send_user_message",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_shutdown",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_terminate",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_upload",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "fn_upload_file",
          "provenance": "EXTRACTED",
          "rel": "EXECUTES",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_add",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_add_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_all_optional_params_function",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_alpha_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_already_ran",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_another_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_apply_lifecycle_patch",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_approval_echo",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_approval_note",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_approval_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_approve_me",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_assert_manifest_materialized_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_assert_restored_lifecycle_state_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_assert_workspace_escape_blocked_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_async_no_context",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_async_with_context",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_bad_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_beta_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_billing_status_checker",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_boom",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_calculate_sum",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_create_config",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_dangerous_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_deferred_lookup",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_deferred_lookup_account",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_delegate_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_disabled_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_echo",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_echo_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_extract_lifecycle_archive",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_faq_lookup_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_fast_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_fetch_random_image",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_first_approval_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_foo",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_foo_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_format_message",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_contact_info",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_current_time",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_current_timestamp",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_current_weather",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_customer_profile",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_discount_approval_path",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_discount_approval_rule",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_invoice_status",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_metadata",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_policy_reference",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_secret_word",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_shipping_credit_balance",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_shipping_eta",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_temperature",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_user_data",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_user_name",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_get_weather",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_greet",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_guarded",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_helper",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_how_many_jokes",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_inner_hitl_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_inner_sensitive_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_inner_shared_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_inner_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_known_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_list_open_orders",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_account",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_customer_profile",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_insurance_eligibility",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_order",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_patient",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_referral_status",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_lookup_secret",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_multiply_by_two",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_needs_ok",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_optional_param_function",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_other_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_outer_shared_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_outer_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_pending_me",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_pending_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_ping",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_publish_announcement",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_query_runloop_network_policy",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_query_runloop_secret",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_random_number",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_random_number_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_read_file",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_record_side_effect",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_reject_me",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_route_to_human_queue",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_second_approval_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_send_email",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_slow_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_start_lifecycle_pty",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_submit_refund",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_sync_no_context_no_args",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_sync_no_context_override",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_sync_no_context_with_args",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_sync_tool_decorator_style",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_sync_with_context",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_synthetic_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_test_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_test_tool_one",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_test_tool_two",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_timeout_configured_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_timeout_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_tool2",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_tool_one",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_triage_tool",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_update_customer_record",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_update_seat",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_visible_lookup_account",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_will_fail_on_bad_json",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_will_not_fail_on_bad_json",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_will_not_fail_on_bad_json_async",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        },
        {
          "dst": "cap_write_file",
          "provenance": "EXTRACTED",
          "rel": "HAS_CAPABILITY",
          "src": "agent_openai_agents_python"
        }
      ],
      "frameworks": [],
      "nodes": [
        {
          "id": "agent_openai_agents_python",
          "name": "openai-agents-python",
          "props": {
            "source_kind": "python"
          },
          "provenance": "EXTRACTED",
          "type": "Agent"
        },
        {
          "id": "cap_add",
          "name": "add",
          "props": {
            "action": "add"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_add_tool",
          "name": "add_tool",
          "props": {
            "action": "add_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_all_optional_params_function",
          "name": "all_optional_params_function",
          "props": {
            "action": "all_optional_params_function"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_alpha_tool",
          "name": "alpha_tool",
          "props": {
            "action": "alpha_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_already_ran",
          "name": "already_ran",
          "props": {
            "action": "already_ran"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_another_tool",
          "name": "another_tool",
          "props": {
            "action": "another_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_apply_lifecycle_patch",
          "name": "apply_lifecycle_patch",
          "props": {
            "action": "apply_lifecycle_patch"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_approval_echo",
          "name": "approval_echo",
          "props": {
            "action": "approval_echo"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_approval_note",
          "name": "approval_note",
          "props": {
            "action": "approval_note"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_approval_tool",
          "name": "approval_tool",
          "props": {
            "action": "approval_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_approve_me",
          "name": "approve_me",
          "props": {
            "action": "approve_me"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_assert_manifest_materialized_tool",
          "name": "assert_manifest_materialized_tool",
          "props": {
            "action": "assert_manifest_materialized_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_assert_restored_lifecycle_state_tool",
          "name": "assert_restored_lifecycle_state_tool",
          "props": {
            "action": "assert_restored_lifecycle_state_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_assert_workspace_escape_blocked_tool",
          "name": "assert_workspace_escape_blocked_tool",
          "props": {
            "action": "assert_workspace_escape_blocked_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_async_no_context",
          "name": "async_no_context",
          "props": {
            "action": "async_no_context"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_async_with_context",
          "name": "async_with_context",
          "props": {
            "action": "async_with_context"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_bad_tool",
          "name": "bad_tool",
          "props": {
            "action": "bad_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_beta_tool",
          "name": "beta_tool",
          "props": {
            "action": "beta_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_billing_status_checker",
          "name": "billing_status_checker",
          "props": {
            "action": "billing_status_checker"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_boom",
          "name": "boom",
          "props": {
            "action": "boom"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_calculate_sum",
          "name": "calculate_sum",
          "props": {
            "action": "calculate_sum"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_create_config",
          "name": "create_config",
          "props": {
            "action": "create_config"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_dangerous_tool",
          "name": "dangerous_tool",
          "props": {
            "action": "dangerous_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_deferred_lookup",
          "name": "deferred_lookup",
          "props": {
            "action": "deferred_lookup"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_deferred_lookup_account",
          "name": "deferred_lookup_account",
          "props": {
            "action": "deferred_lookup_account"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_delegate_tool",
          "name": "delegate_tool",
          "props": {
            "action": "delegate_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_disabled_tool",
          "name": "disabled_tool",
          "props": {
            "action": "disabled_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_echo",
          "name": "echo",
          "props": {
            "action": "echo"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_echo_tool",
          "name": "echo_tool",
          "props": {
            "action": "echo_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_extract_lifecycle_archive",
          "name": "extract_lifecycle_archive",
          "props": {
            "action": "extract_lifecycle_archive"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_faq_lookup_tool",
          "name": "faq_lookup_tool",
          "props": {
            "action": "faq_lookup_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_fast_tool",
          "name": "fast_tool",
          "props": {
            "action": "fast_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_fetch_random_image",
          "name": "fetch_random_image",
          "props": {
            "action": "fetch_random_image"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_first_approval_tool",
          "name": "first_approval_tool",
          "props": {
            "action": "first_approval_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_foo",
          "name": "foo",
          "props": {
            "action": "foo"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_foo_tool",
          "name": "foo_tool",
          "props": {
            "action": "foo_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_format_message",
          "name": "format_message",
          "props": {
            "action": "format_message"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_contact_info",
          "name": "get_contact_info",
          "props": {
            "action": "get_contact_info"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_current_time",
          "name": "get_current_time",
          "props": {
            "action": "get_current_time"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_current_timestamp",
          "name": "get_current_timestamp",
          "props": {
            "action": "get_current_timestamp"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_current_weather",
          "name": "get_current_weather",
          "props": {
            "action": "get_current_weather"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_customer_profile",
          "name": "get_customer_profile",
          "props": {
            "action": "get_customer_profile"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_discount_approval_path",
          "name": "get_discount_approval_path",
          "props": {
            "action": "get_discount_approval_path"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_discount_approval_rule",
          "name": "get_discount_approval_rule",
          "props": {
            "action": "get_discount_approval_rule"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_invoice_status",
          "name": "get_invoice_status",
          "props": {
            "action": "get_invoice_status"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_metadata",
          "name": "get_metadata",
          "props": {
            "action": "get_metadata"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_policy_reference",
          "name": "get_policy_reference",
          "props": {
            "action": "get_policy_reference"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_secret_word",
          "name": "get_secret_word",
          "props": {
            "action": "get_secret_word"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_shipping_credit_balance",
          "name": "get_shipping_credit_balance",
          "props": {
            "action": "get_shipping_credit_balance"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_shipping_eta",
          "name": "get_shipping_eta",
          "props": {
            "action": "get_shipping_eta"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_temperature",
          "name": "get_temperature",
          "props": {
            "action": "get_temperature"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_user_data",
          "name": "get_user_data",
          "props": {
            "action": "get_user_data"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_user_name",
          "name": "get_user_name",
          "props": {
            "action": "get_user_name"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_get_weather",
          "name": "get_weather",
          "props": {
            "action": "get_weather"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_greet",
          "name": "greet",
          "props": {
            "action": "greet"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_guarded",
          "name": "guarded",
          "props": {
            "action": "guarded"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_helper",
          "name": "helper",
          "props": {
            "action": "helper"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_how_many_jokes",
          "name": "how_many_jokes",
          "props": {
            "action": "how_many_jokes"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_inner_hitl_tool",
          "name": "inner_hitl_tool",
          "props": {
            "action": "inner_hitl_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_inner_sensitive_tool",
          "name": "inner_sensitive_tool",
          "props": {
            "action": "inner_sensitive_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_inner_shared_tool",
          "name": "inner_shared_tool",
          "props": {
            "action": "inner_shared_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_inner_tool",
          "name": "inner_tool",
          "props": {
            "action": "inner_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_known_tool",
          "name": "known_tool",
          "props": {
            "action": "known_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_list_open_orders",
          "name": "list_open_orders",
          "props": {
            "action": "list_open_orders"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_account",
          "name": "lookup_account",
          "props": {
            "action": "lookup_account"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_customer_profile",
          "name": "lookup_customer_profile",
          "props": {
            "action": "lookup_customer_profile"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_insurance_eligibility",
          "name": "lookup_insurance_eligibility",
          "props": {
            "action": "lookup_insurance_eligibility"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_order",
          "name": "lookup_order",
          "props": {
            "action": "lookup_order"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_patient",
          "name": "lookup_patient",
          "props": {
            "action": "lookup_patient"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_referral_status",
          "name": "lookup_referral_status",
          "props": {
            "action": "lookup_referral_status"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_lookup_secret",
          "name": "lookup_secret",
          "props": {
            "action": "lookup_secret"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_multiply_by_two",
          "name": "multiply_by_two",
          "props": {
            "action": "multiply_by_two"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_needs_ok",
          "name": "needs_ok",
          "props": {
            "action": "needs_ok"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_optional_param_function",
          "name": "optional_param_function",
          "props": {
            "action": "optional_param_function"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_other_tool",
          "name": "other_tool",
          "props": {
            "action": "other_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_outer_shared_tool",
          "name": "outer_shared_tool",
          "props": {
            "action": "outer_shared_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_outer_tool",
          "name": "outer_tool",
          "props": {
            "action": "outer_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_pending_me",
          "name": "pending_me",
          "props": {
            "action": "pending_me"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_pending_tool",
          "name": "pending_tool",
          "props": {
            "action": "pending_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_ping",
          "name": "ping",
          "props": {
            "action": "ping"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_publish_announcement",
          "name": "publish_announcement",
          "props": {
            "action": "publish_announcement"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_query_runloop_network_policy",
          "name": "query_runloop_network_policy",
          "props": {
            "action": "query_runloop_network_policy"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_query_runloop_secret",
          "name": "query_runloop_secret",
          "props": {
            "action": "query_runloop_secret"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_random_number",
          "name": "random_number",
          "props": {
            "action": "random_number"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_random_number_tool",
          "name": "random_number_tool",
          "props": {
            "action": "random_number_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_read_file",
          "name": "read_file",
          "props": {
            "action": "read_file"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_record_side_effect",
          "name": "record_side_effect",
          "props": {
            "action": "record_side_effect"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_reject_me",
          "name": "reject_me",
          "props": {
            "action": "reject_me"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_route_to_human_queue",
          "name": "route_to_human_queue",
          "props": {
            "action": "route_to_human_queue"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_second_approval_tool",
          "name": "second_approval_tool",
          "props": {
            "action": "second_approval_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_send_email",
          "name": "send_email",
          "props": {
            "action": "send_email"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_slow_tool",
          "name": "slow_tool",
          "props": {
            "action": "slow_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_start_lifecycle_pty",
          "name": "start_lifecycle_pty",
          "props": {
            "action": "start_lifecycle_pty"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_submit_refund",
          "name": "submit_refund",
          "props": {
            "action": "submit_refund"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_sync_no_context_no_args",
          "name": "sync_no_context_no_args",
          "props": {
            "action": "sync_no_context_no_args"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_sync_no_context_override",
          "name": "sync_no_context_override",
          "props": {
            "action": "sync_no_context_override"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_sync_no_context_with_args",
          "name": "sync_no_context_with_args",
          "props": {
            "action": "sync_no_context_with_args"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_sync_tool_decorator_style",
          "name": "sync_tool_decorator_style",
          "props": {
            "action": "sync_tool_decorator_style"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_sync_with_context",
          "name": "sync_with_context",
          "props": {
            "action": "sync_with_context"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_synthetic_tool",
          "name": "synthetic_tool",
          "props": {
            "action": "synthetic_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_test_tool",
          "name": "test_tool",
          "props": {
            "action": "test_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_test_tool_one",
          "name": "test_tool_one",
          "props": {
            "action": "test_tool_one"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_test_tool_two",
          "name": "test_tool_two",
          "props": {
            "action": "test_tool_two"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_timeout_configured_tool",
          "name": "timeout_configured_tool",
          "props": {
            "action": "timeout_configured_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_timeout_tool",
          "name": "timeout_tool",
          "props": {
            "action": "timeout_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_tool2",
          "name": "tool2",
          "props": {
            "action": "tool2"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_tool_one",
          "name": "tool_one",
          "props": {
            "action": "tool_one"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_triage_tool",
          "name": "triage_tool",
          "props": {
            "action": "triage_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_update_customer_record",
          "name": "update_customer_record",
          "props": {
            "action": "update_customer_record"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_update_seat",
          "name": "update_seat",
          "props": {
            "action": "update_seat"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_visible_lookup_account",
          "name": "visible_lookup_account",
          "props": {
            "action": "visible_lookup_account"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_will_fail_on_bad_json",
          "name": "will_fail_on_bad_json",
          "props": {
            "action": "will_fail_on_bad_json"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_will_not_fail_on_bad_json",
          "name": "will_not_fail_on_bad_json",
          "props": {
            "action": "will_not_fail_on_bad_json"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_will_not_fail_on_bad_json_async",
          "name": "will_not_fail_on_bad_json_async",
          "props": {
            "action": "will_not_fail_on_bad_json_async"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "cap_write_file",
          "name": "write_file",
          "props": {
            "action": "write_file"
          },
          "provenance": "EXTRACTED",
          "type": "Capability"
        },
        {
          "id": "fn_approve",
          "name": "approve",
          "props": {
            "action": "approve"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_approve_first_interruption",
          "name": "approve_first_interruption",
          "props": {
            "action": "approve_first_interruption"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_approve_tool",
          "name": "approve_tool",
          "props": {
            "action": "approve_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_approve_tool_call",
          "name": "approve_tool_call",
          "props": {
            "action": "approve_tool_call"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete",
          "name": "delete",
          "props": {
            "action": "delete"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_branch",
          "name": "delete_branch",
          "props": {
            "action": "delete_branch"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_cached_snapshot_fingerprint_best_effort",
          "name": "delete_cached_snapshot_fingerprint_best_effort",
          "props": {
            "action": "delete_cached_snapshot_fingerprint_best_effort"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_file",
          "name": "delete_file",
          "props": {
            "action": "delete_file"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_many",
          "name": "delete_many",
          "props": {
            "action": "delete_many"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_one",
          "name": "delete_one",
          "props": {
            "action": "delete_one"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_session",
          "name": "delete_session",
          "props": {
            "action": "delete_session"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_delete_state",
          "name": "delete_state",
          "props": {
            "action": "delete_state"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_drop_agent_tool_run_result",
          "name": "drop_agent_tool_run_result",
          "props": {
            "action": "drop_agent_tool_run_result"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_drop_orphan_function_calls",
          "name": "drop_orphan_function_calls",
          "props": {
            "action": "drop_orphan_function_calls"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec",
          "name": "exec",
          "props": {
            "action": "exec"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_async",
          "name": "exec_async",
          "props": {
            "action": "exec_async"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_checked_nonzero",
          "name": "exec_checked_nonzero",
          "props": {
            "action": "exec_checked_nonzero"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_command_needs_approval",
          "name": "exec_command_needs_approval",
          "props": {
            "action": "exec_command_needs_approval"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_create",
          "name": "exec_create",
          "props": {
            "action": "exec_create"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_inspect",
          "name": "exec_inspect",
          "props": {
            "action": "exec_inspect"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_run",
          "name": "exec_run",
          "props": {
            "action": "exec_run"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_exec_start",
          "name": "exec_start",
          "props": {
            "action": "exec_start"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute",
          "name": "execute",
          "props": {
            "action": "execute"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_apply_patch_calls",
          "name": "execute_apply_patch_calls",
          "props": {
            "action": "execute_apply_patch_calls"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_approved_tools",
          "name": "execute_approved_tools",
          "props": {
            "action": "execute_approved_tools"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_computer_actions",
          "name": "execute_computer_actions",
          "props": {
            "action": "execute_computer_actions"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_custom_tool_calls",
          "name": "execute_custom_tool_calls",
          "props": {
            "action": "execute_custom_tool_calls"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_final_output",
          "name": "execute_final_output",
          "props": {
            "action": "execute_final_output"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_final_output_step",
          "name": "execute_final_output_step",
          "props": {
            "action": "execute_final_output_step"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_function_tool_calls",
          "name": "execute_function_tool_calls",
          "props": {
            "action": "execute_function_tool_calls"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_handoffs",
          "name": "execute_handoffs",
          "props": {
            "action": "execute_handoffs"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_local_shell_calls",
          "name": "execute_local_shell_calls",
          "props": {
            "action": "execute_local_shell_calls"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_mcp_approval_requests",
          "name": "execute_mcp_approval_requests",
          "props": {
            "action": "execute_mcp_approval_requests"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_session_command",
          "name": "execute_session_command",
          "props": {
            "action": "execute_session_command"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_shell_calls",
          "name": "execute_shell_calls",
          "props": {
            "action": "execute_shell_calls"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_tools_and_side_effects",
          "name": "execute_tools_and_side_effects",
          "props": {
            "action": "execute_tools_and_side_effects"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_execute_with_shuffle",
          "name": "execute_with_shuffle",
          "props": {
            "action": "execute_with_shuffle"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_export",
          "name": "export",
          "props": {
            "action": "export"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_post",
          "name": "post",
          "props": {
            "action": "post"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_provision_accounts",
          "name": "provision_accounts",
          "props": {
            "action": "provision_accounts"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_provision_manifest_accounts",
          "name": "provision_manifest_accounts",
          "props": {
            "action": "provision_manifest_accounts"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_publish",
          "name": "publish",
          "props": {
            "action": "publish"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_reject",
          "name": "reject",
          "props": {
            "action": "reject"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_reject_tool",
          "name": "reject_tool",
          "props": {
            "action": "reject_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_reject_tool_call",
          "name": "reject_tool_call",
          "props": {
            "action": "reject_tool_call"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_release_agent",
          "name": "release_agent",
          "props": {
            "action": "release_agent"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_release_agents",
          "name": "release_agents",
          "props": {
            "action": "release_agents"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_release_waiters",
          "name": "release_waiters",
          "props": {
            "action": "release_waiters"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run",
          "name": "run",
          "props": {
            "action": "run"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_agent",
          "name": "run_agent",
          "props": {
            "action": "run_agent"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_agent_async",
          "name": "run_agent_async",
          "props": {
            "action": "run_agent_async"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_and_resume",
          "name": "run_and_resume",
          "props": {
            "action": "run_and_resume"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_and_resume_after_approval",
          "name": "run_and_resume_after_approval",
          "props": {
            "action": "run_and_resume_after_approval"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_and_resume_with_mutation",
          "name": "run_and_resume_with_mutation",
          "props": {
            "action": "run_and_resume_with_mutation"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_command",
          "name": "run_command",
          "props": {
            "action": "run_command"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_compaction",
          "name": "run_compaction",
          "props": {
            "action": "run_compaction"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_conversation",
          "name": "run_conversation",
          "props": {
            "action": "run_conversation"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_demo_loop",
          "name": "run_demo_loop",
          "props": {
            "action": "run_demo_loop"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_examples",
          "name": "run_examples",
          "props": {
            "action": "run_examples"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_execute_approved_tools",
          "name": "run_execute_approved_tools",
          "props": {
            "action": "run_execute_approved_tools"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_execute_with_processed_response",
          "name": "run_execute_with_processed_response",
          "props": {
            "action": "run_execute_with_processed_response"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_file_session_scenario",
          "name": "run_file_session_scenario",
          "props": {
            "action": "run_file_session_scenario"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_final_output_hooks",
          "name": "run_final_output_hooks",
          "props": {
            "action": "run_final_output_hooks"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_function",
          "name": "run_function",
          "props": {
            "action": "run_function"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_git",
          "name": "run_git",
          "props": {
            "action": "run_git"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_healthcare_support_workflow",
          "name": "run_healthcare_support_workflow",
          "props": {
            "action": "run_healthcare_support_workflow"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_in_listener_task",
          "name": "run_in_listener_task",
          "props": {
            "action": "run_in_listener_task"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_input_guardrails",
          "name": "run_input_guardrails",
          "props": {
            "action": "run_input_guardrails"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_input_guardrails_with_queue",
          "name": "run_input_guardrails_with_queue",
          "props": {
            "action": "run_input_guardrails_with_queue"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_interactive_loop",
          "name": "run_interactive_loop",
          "props": {
            "action": "run_interactive_loop"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_item_to_input_item",
          "name": "run_item_to_input_item",
          "props": {
            "action": "run_item_to_input_item"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_items_to_input_items",
          "name": "run_items_to_input_items",
          "props": {
            "action": "run_items_to_input_items"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_mount_smoke_test",
          "name": "run_mount_smoke_test",
          "props": {
            "action": "run_mount_smoke_test"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_namespaced_example",
          "name": "run_namespaced_example",
          "props": {
            "action": "run_namespaced_example"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_once",
          "name": "run_once",
          "props": {
            "action": "run_once"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_openai_session_scenario",
          "name": "run_openai_session_scenario",
          "props": {
            "action": "run_openai_session_scenario"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_output_guardrails",
          "name": "run_output_guardrails",
          "props": {
            "action": "run_output_guardrails"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_phase_one",
          "name": "run_phase_one",
          "props": {
            "action": "run_phase_one"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_phase_two",
          "name": "run_phase_two",
          "props": {
            "action": "run_phase_two"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_pre_stop_hooks",
          "name": "run_pre_stop_hooks",
          "props": {
            "action": "run_pre_stop_hooks"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_resume",
          "name": "run_resume",
          "props": {
            "action": "run_resume"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_scenario_step",
          "name": "run_scenario_step",
          "props": {
            "action": "run_scenario_step"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_single",
          "name": "run_single",
          "props": {
            "action": "run_single"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_single_approval",
          "name": "run_single_approval",
          "props": {
            "action": "run_single_approval"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_single_input_guardrail",
          "name": "run_single_input_guardrail",
          "props": {
            "action": "run_single_input_guardrail"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_single_output_guardrail",
          "name": "run_single_output_guardrail",
          "props": {
            "action": "run_single_output_guardrail"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_single_turn",
          "name": "run_single_turn",
          "props": {
            "action": "run_single_turn"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_single_turn_streamed",
          "name": "run_single_turn_streamed",
          "props": {
            "action": "run_single_turn_streamed"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_sql",
          "name": "run_sql",
          "props": {
            "action": "run_sql"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_step",
          "name": "run_step",
          "props": {
            "action": "run_step"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_streamed",
          "name": "run_streamed",
          "props": {
            "action": "run_streamed"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_streamed_turn",
          "name": "run_streamed_turn",
          "props": {
            "action": "run_streamed_turn"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_subtask",
          "name": "run_subtask",
          "props": {
            "action": "run_subtask"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_sync",
          "name": "run_sync",
          "props": {
            "action": "run_sync"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_tasks_as_children",
          "name": "run_tasks_as_children",
          "props": {
            "action": "run_tasks_as_children"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_tasks_parallel",
          "name": "run_tasks_parallel",
          "props": {
            "action": "run_tasks_parallel"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_tool",
          "name": "run_tool",
          "props": {
            "action": "run_tool"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_top_level_example",
          "name": "run_top_level_example",
          "props": {
            "action": "run_top_level_example"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_turn",
          "name": "run_turn",
          "props": {
            "action": "run_turn"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_with_auto_approval",
          "name": "run_with_auto_approval",
          "props": {
            "action": "run_with_auto_approval"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_with_custom_client",
          "name": "run_with_custom_client",
          "props": {
            "action": "run_with_custom_client"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_run_worker",
          "name": "run_worker",
          "props": {
            "action": "run_worker"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send",
          "name": "send",
          "props": {
            "action": "send"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_audio",
          "name": "send_audio",
          "props": {
            "action": "send_audio"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_bytes",
          "name": "send_bytes",
          "props": {
            "action": "send_bytes"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_client_event",
          "name": "send_client_event",
          "props": {
            "action": "send_client_event"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_event",
          "name": "send_event",
          "props": {
            "action": "send_event"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_input",
          "name": "send_input",
          "props": {
            "action": "send_input"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_message",
          "name": "send_message",
          "props": {
            "action": "send_message"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_mic_audio",
          "name": "send_mic_audio",
          "props": {
            "action": "send_mic_audio"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_new",
          "name": "send_new",
          "props": {
            "action": "send_new"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_std_in",
          "name": "send_std_in",
          "props": {
            "action": "send_std_in"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_stdin",
          "name": "send_stdin",
          "props": {
            "action": "send_stdin"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_str",
          "name": "send_str",
          "props": {
            "action": "send_str"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_tool_output",
          "name": "send_tool_output",
          "props": {
            "action": "send_tool_output"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_send_user_message",
          "name": "send_user_message",
          "props": {
            "action": "send_user_message"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_shutdown",
          "name": "shutdown",
          "props": {
            "action": "shutdown"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_terminate",
          "name": "terminate",
          "props": {
            "action": "terminate"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_upload",
          "name": "upload",
          "props": {
            "action": "upload"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        },
        {
          "id": "fn_upload_file",
          "name": "upload_file",
          "props": {
            "action": "upload_file"
          },
          "provenance": "EXTRACTED",
          "type": "Task"
        }
      ],
      "note": "Proposed CWN mappings, confidence-tagged. Confirm against the current published control text before relying on them for audit. Enterprise control ids are mapped at onboarding by your GRC team, never auto-asserted.",
      "source": "openai-agents-python",
      "source_kind": "python"
    },
    "summary": {
      "asserted_covered": 0,
      "edges": 235,
      "frameworks": [],
      "governed_actions": 235,
      "nodes": 236,
      "source": "openai-agents-python",
      "source_kind": "python",
      "ungoverned_actions": 112
    }
  },
  "evidence_hash": "25e53abe2a88f34fe7ab4dc4c6626e0b84fbda68c90ee62cda1a6aa8959ac006",
  "ml_dsa_public_key_b64": "zd3F0VAFVXjB5KbuVYGKTiz3QH3QnV+O4rZ1C0iHttJfNiLZuJxaH1/2RJtNSt/Hm/lGG3R6xZgx1znJ3CxTREgHGbsA2YF09iLxe6in845yZLJ1eL+ytD94Y6gPNLWbv7ckrv73nm/Bv056gYdu8bGRMqBd5+RwLyMMlKLAwX1gL4Ld481fWwe8z28xdLm2TlqcxUqXQ/gTc94bsCU9zgOr3vmq3EVrq3j34Q8Eu/1S98NHJLoVjot2p3PWGiL2Qk2evyUN2SpubU9Uu7iKvsU7J/3RvT+4VHv4nEtMgpr4je00PAIgSr5+lnHuB9CSZ+HodI2B0Nb0KLuGLQMngRemYccG2tzR8mtalQTixrJhaqj/2ffLioa6kV33UG74TuwH0mAsH38OypP9FO/i8xPIcJMPkoS/8yUT/eqkPYdJZ1+SmqcY7rO/5lFRsWTevAq30IOJrklywZAAOHshK6ZeL22RxhXfG9pKmky2rwPIEE6hatbwEanL8zCN2Z+AL0VUOOdk1aMsPqspKM834SkkGmawMiNsOvghlNNFPtcL0jghFwFZMng5Yb+e132MWbVrMkXKwS80Pr1mrEbL9OChDzoe5L4YMhv91RLWB7vhaCdQeeV9GU7JzdBV/IT8MrK236VLbzaQXhvuQgbfwrxAz+sLry9osppeETtIGrGi8JC+BZfgx7r3a+7Im1/fY419awBj5ifoVWNPg0oPWbt99vQHfLD5SOtm8d2UOvmYqmHgNYZ8a/IJZtj9xcNgjvKbUttan60lCMhGJBVP9msysxrwOyqYjv+skx3LtUCK9UuTSc1IFmF82xvqUdSvricLslHNRm+uqXhaUW9+rweL3xxr+373Ykjzb8aLsqCJeWhAp6JUbwSXRTB0H5cJmdsuOC+hBFd6x1jqBK5vDaFXkytH6yFNosm2yAudYJbW+AaR3iu9cx4TF22Vkysn3pXPXD6Nefw6VI3NPDUsU0+AP/cCBVPe5J8fpbG9R7Ham2JIjJ+ejL6gkt6N9RFv4PIgk9tW0t2c/G96NPY95rO2mBIOUsa3VRDa3VbryeoadmLXyEo5e/Ukv/pTnRP3+uniDLeVmRVI0GrPhUx8YN4BU9x5Sy3PL6bWcxX5KEUY+dKzMJafH0f3RTnHmcyjU7u8WuY9SCGu4iExfzig5J4QrdOjKAOICTAgLkrXjV1Nyc+cUP0FEEgoviHdirlPTZKLkU76qmF1BBgYrzfnVftGrNGJMRUFmhLDh/oaodDc3DjerKNJOtJbG2PVR4TzCGyqRLLqlcCdXnU8AwLDNqGvxPqQxFmNaOMmcrTxYi1xsHtIxufrul/ZWa0MBTXcnpdN1zNaUrbUGZEFmMC2T6oZ447MWp+UKK83L5LOGt34PsN3esbmJrP0rGWY4Crhoi2Akvz9QpwZOh+FGUIHaM1GKtLqzpfL9lhhmAPn55JCS/l0mRDiD+39gsujgt+SKVMh2/DQaoMdlyFHxu+0mfKMLvpSjqevYqSgGJfv2NUvE/0HExMgCfEkSD7xRAf+3V3VJRygE/Wadh4bvyUsKjA2LgEMJg6kazuCy0CrxG/gXmFfhpdvtfOpoh90jGpFDMvL05wZ/3oimUXK0xlJx+HuwyQNymWWTdiFe55g3/CcfmDTBFb09JT9EzrhbVHpRip2zenFDdMluhscs67IlG4wZWvYJZ4IsM5pbZHSltJdq4lRQe2cEd06TtrPkhMRQ/n46lry0Q8luGWYDVUM6yH1z3oNmv5gr87gCWvA02FJO9610oFurP4qEczpjndwuhwpI7FFoLwEHtuWcX//V0wjYQdcaH/NWBEQMMgwhNau7h4whvEBZxsg0d6grsIAzLV+xrBfDIRPMU/W2BRcNoyb2dqAHHVnImQCl03t3j16ipb6nTDCXYzgr+NscJ3GOWkZdPG2P8Vr1cC4OPfnhAGlZ9roVDC8S1JQr+K/bpMpD/Knc1FQ7nXO0/kPl0342OWBuXjDdYjxxW3hX2LsQx9pXKU0HUYzV+JWdL3zuE/PzbYf4cTsOkrhSj0aJTZs8m2RXF9tLV+7g8qVSYXQ2gfCvm77OdUDi0XXKjn2EyztnWRr3US17r/Wl/TSi+b2UAgVqPWEcFM6ujNN5fdUYXz4jzGQmZEWmr/+QH2+nK9VB3+BLNyxtl1SLEmv+lYX2o03qoQHB6NHCawIEuLYJK/EKy3D92THCmumZ92Bdvh9cMfmXhj6CnjTB9D6Gy3GAQUMc8UgoZLZt/odow7fGa723TbxqOoNOe6LOS12T3XYjPF+8UPODDR4gK2nZYAwopEts2MD21FzkIgMuUckFe8HJoa+nA0z743fewGM9bJ2msHArkiHPYJStONpUAmTZJt5JFau2nrCa8ck1WYWLXmLLyWAe9l4ns3fTgwM8Dm9QI4gvFylNusvyfhTOpS3sK3xxflO3ZZOWwvz1i9OPLmRV0C2FY7LvoFZMvB8GiGapLJ+601+gPw18bSEkbDOontH9FDipGGzjV+S4q7KPlx34YltVLBZ1xMWb37+B9s9UGvymU4KqS69DLLofgi/44h4bgFWPH9nSGo89j0IYGCdcC3Vt8vHAZ25ub+XUoE=",
  "ml_dsa_signature_b64": "Vg2drONRLKAsE1v9BXcU+lncAe1jWcMyoMi/0yTpnCET/TNqX5DUCCbvWNouyQNUViqH5eWn9RyKBafxSEavjpG+Iw7LjWpU310H7oIsYn95ePKC6wnvKBAspt4heSHozuLm2B18iWXKdngM61rU/4Dxz2jEXs2dbVYc1agwgQdGf/SQ2y16vEq7WJt1aXIctD7UBL4w5hqnP2H/by+OtRCK1zaF6ELAKRhkQBOjwLXwndhQRvLR+yw7+ISIlOex8tRlS+EIWS6C9pdZT2g6tKktkdbHT0rrAVU0OdZTua/bw3tO5D05RANGbyo/z9wavobtQK81zJp8YBK1VbV4VsMgKBuSrtDfEJvWGmhgBk55RNVywWedqBS+aVjFOh/u4JyKLg5R/n4od2xjSEdkHT+DWvO182McK00MgBzmJaJggfxu0Her+Tv49g0doo3Mr39ho1rs/9VNXSrXxEmhfWRQwOHtJwj2U2kbXPMxR6KOJcr7+9TDN2tMLOR7Up7hl9RyPN6W1EbztwANawuRKb0PUNwx3E2qVEtvPdYxHMwktlqSxIMLDJxpPHIQroBoa0IBg1GzmV5O6BPziULrBsIisj+z1CEeuIEqAOYGJ0kYCkOKCqebXc3Hw3A8+mvKBARD+nyn+QjgvlUA+2H11XQHXFWbFtFiot47EKSTct5NbN7zPyVGDTGasvNW5TTRvDVQCFWHULBMF2PmpBQHWcArA3Utl9MKmGByZzQ4yRWTpWupEPtra+fJxveFTdlW3fx2W3wTYmAMEj2GV30A/RB5BQs+/u/qtfPP2wkcWJ+Mb9yLS8ihr7x29a6L5TnfWCrohiTn7FkwYeSUEER/vHH7D0VXlQwqpM8D9ahsIdS7ddeJmS6rY7EUe54x/vazCs1JTTBQDlW81+N0V2bUvzu5vyQHUrIYSbIb8k9QDsACyB0DEbI5u0tpkyM4wSY0XCWipLMZodDedTstvDX1YFCwFzn+RoDBncZJBXtPt2aN/lVtZjzRhzYRrpCQ0PvYvZpaexTS1QedT4GGKIYejBikfek5A7s2pmUZTSVCcqlj3LR+VbZltj/T5eAm5liQ7Z8B6tREJU/Ja4PTPPL/RrY092IPcqVINu/GsHlITXOOua+Z9dfcyRk1YhZp0iI1u/HccvexKu62FmpT3gBze1pHdOsqeOmFb5tSSbM6v8koBEvLSah64n4YileSGmiokSzCRpP8tkbKHFmM6rfUwC5kjBAtVv3jOp+rNel9tp8KPDd6HYSqNbnWsxiZlfJH3tNrJ0f5Z+sSWocakoSmVYMMLfOuu2n49xvaPPmjPB/CgZKk1pEnm6mZeL2kH/pTp1DT1EeVemcb/LvNvDDBSZA8zey+UDlQa7hv/YBaMoFuGS39VdoZvUQ+7e3m8oRgh3vMVLsPU7cmeoKXe32hsUQGPAbkQZkvQAQeiX4OqztkutXBwBba7DxRbcicWvkqH7O4bf4v7EdAYbocHV8UC9KITtxTp9eMOVsgaoxQWPpBs9yD/dz/Jaxs7hfH9/OoG+VNShA5H2U4KlczY8fX+JRBBkpERjlzlP22kuTZ6VYBx0siS3oj5rkiKWPQi/eIVEh+NFp+Ykn+WF/MRuLYqQ3d6VSk8wAv9M1tKn91eASJXMZbk6nQ8BAl34ofCes1CtWuLXwDP8tDu4Tkk1aJuF+L1HbXGockKJAsyuJYbswDHdcwdtWIx5JLP9IwWOnYkN6PheY8oRzXJdQYrBUAQEKly2aeSz28yjxo/aq8S1pM9IWPvLyQm/4x613L9LifKOBEMzjc2Zvq+NdlJrgO01Rtn72clH5N53p4OV3QYuWVSMZr0PWvKdgvB1STtgRkZf+IjNBIXWUUkJEFICbTcbL/0hjJZjlmTvL7kuJFLGzPIar5AUXVvcBJMar//vhYY1HA3xFMsiv4mrt8qkNAWQCZxKelI/6W/TvSHpwu45J0fr6ASQi+j+PSjINUULCPoiiK3BeYaDDDCXK7qjhrU4wUfr7fO8Jp/2RDnPEGZQ0WCSv1vNh+/zwSa6DP0d59uRIN/VA1Dlg5beMnGdCQExwEBCVboc/2bjAXr4ascSlPOd0cnyjTUFw23/Mrp87T9Y2NpqLs/TfoFVNBllpIb7XRrcgI1TG4r3y5cAMxCv5VyEICHdrx1E34X6mdE1Hwlg9+PcnYhbAG/vRHl5lfGaOpJlOYJ3ltKyiunBvn1pZ6uXXYi5R18fADpaehoNVX75QgvG/RO6fqfKEBNBaISGruSqe4phLBu+U1eLA2+Xp1c6p2DokNfAS2HOBuzdRv/vnDWmsD1eqAvWy06UH1ZcWc6aZMjOw75dIq5XvbOplGLS88aPedAjkRIfQTh3WqklkY1z2rdbfBUiuOn2J/7ubA6zbER8LjqliaAd2Wh7jnTvC7/O8KvZV76AdG1xj8XpbqC7HIp79JNEQd9JGc2u29K6V9Ul8lwB2Q58Ki9u9fXauT1Ve9C+hL7UqV2s4ShdWnzQ0zH3+TwVO7ZgKa9HI5BIxpFuzI5+aFKF57NrzSEQN9jnisTl8NjfDBYsdCU3NN02gz6ILs9d4jcFdtv8+nwdvQrNw1ZCx3YjOVaCpoTW/V2QznMuSADhvKZmIzmw9jpGIms+KtS7e7/BmLYnUlTQslDOsj5T77/d6s0XB1oGG4e7mRBPK3Hws8KGHpX1N2A1AVYLzV+KOe7JmQ+zHp8zXQ61CpsT82xFpE7MdZhXLf3K/nBqCaP9lNoyKST04UAMmm4cKGTY8dYSmmvb3MDL10AegTOSZIh4A1BzwmsvCZHM4QVCmaTx/j1RhRGNNmZizsN6rP9zlyD36GJ808VykNa1HaP8i0J6Farwds9W9RMbs/Xrt9h5CopAh6loHNJtaqY1Sz6Y2mMHfiAcbCV4bUvCs3PzUuMUYCmVQLAUxbhvrT7FGw0g0irGy3tjeFLnOGo0EkYXI/7F5LN6k35Wd7gKdQ2J2e0aJz3sfUHyAlaHaqIWcvdbEocVfYGT3H6Vw/Yjkqf91+iDqWN/oJqt5WIoFMyk11DXn/446C1Fruuy0LeqjjXHp9eZEyqJaJu/zB3UXoEVPhNe4/rmSUquSbSebrpakczNKEEmoQDNxzin/CBvzy4eG1mA5ESTQ48bwjK5yU0HQm3vYjCHu6sPSHKSD4FvOSbiH8/RcHiGuy0RWKcBHae/crvt4UF++bTyEi3azjxELy2lLFw7zpa8UdSt540zSGs52JZxEK91RkQ/82heIy+uVZzUv/mA6hU1rKNB+/KmIpWgA0FXDmeUCrf/tuq8DMc46BCcqhzkSRkeN37zjLQrqIwu8g9VeYxY2abRCKamnT50SDRIYK5NsBAelI8fVICo/1yWtQq/jQC4QRN5oqnnfZjf30h2vTzrJCFiUle1DwePRWlH+qxXyhdLT1+1kFzFYDiB19I1HOEq1Beju949/7yaG4W3fB3Pi7pExIXck+hJwuUgcQQKfyqhbKoKdfsdmqpNlA853/+6/D5vL/tHRfm1nE/kyCwFCBr1m2aKDt1KdsoYv80RvYrJeC2ufRw7HUn3A+8SuY3YycYm9ss4Z5ugDtzks2Z+dOHiOdxuQKdaFMZygO49MjSnpUxRj2Ri/KxY5lxGEUy5tHg07Ye45Yr/87k8wZvMyZ2v6Thv269O49AjuSkR741h4yTMnIHnRjZ+InfpY4lYfX/QRX+MjAUsv662Tdv3KfXk2+ZfAmhaLqqY3k//XHbNfAhLtwMJAyN+ZTjhp67pBUhe3ieI+nfDiq+QgiNS64a7KBvCVXgIOMBnBYz9m0ylXHUUJhJ6qgvalya1UW+ddJTJeuKO2yQ1wDV/VB/POGqCYFlqtidjPozd7+MalztDMGrXNRMoqhxXBACQIR+TslI6AW7mqz33R8a1XIqlFnBLZWL8v7aYJ+u4VC9DduQ8m7bqRtASQ8Cn7Jd/ehD6VFivxWrMEH3R/pTyMGAScTNvXgSotjzCf7coqntzpDyhOKkpAkgYWLJb+9bGWsIZlw6oHEzV4B7DxT6cmnPXPkpXT5WZLM1hhyJr+BaPGO8RhpTESpgaaZm7drAVZ6vpFPdZ23Sre/s3dkCpb8kqMjj36+ffo4TE4+xKVKDQUoWBbozE0+ZkqUXxP8jjlqd/ERFxaa3d3W3TQXLf5Viged+GGYd76YZgOPKGdodE/+l3gDIGooNT/UDANmS2U5z/AEIpXAaj//FOgKG09bD7ejfKgkaz/fsIFTx9W/1fiKAzgNrf30wfSJcA/E2DJWxosKNtnbkIGwrNaM2bOn+2EgP8grQ6dmBvZVY83j+CgUVdQ2bYnXKNWD0WIkaIyuJzk6fKn6JSlKXZ2/wNXhhI6v6B0gL1lseIiKqtfaAy41fYSUxtrnAAAAAAAAAAAAAAAABAoTFyIr",
  "note_pq": "Hybrid signature: Ed25519 always; ML-DSA-65 (FIPS 204) and SLH-DSA (FIPS 205) added when a PQ backend is installed. Each leg signs the same canonical body; any one verifying proves authenticity. Install: pip install \"openagentontology[pq]\".",
  "signature_alg": "Ed25519+ML-DSA-65+SLH-DSA",
  "signature_b64": "BchqG4+YIYGNrAVXGNFoCKJxSQPhBv/UGRTo036Rd1kvg7N1TwmhBBhWFR5yHBmIpG9tcbashjVJiaR3+hhOAw==",
  "signed": true,
  "signed_at": "2026-06-12T05:21:35.447908+00:00",
  "slh_dsa_public_key_b64": "bXNhZNeO0U50ZGJz/hQQCpW03+uEluFG/BkVrNlKk1k=",
  "slh_dsa_signature_b64": "tNuRy/yIWdvMhTe4Kmgrmn0FepuNaOHIfIUKEJTheaQbEMR4mbaS55GFKTPF/SvUU1JJWOXfstyW8YW0hmDQ90sFIr11yN2DN1GA++Mv/cuAM5MWTyU3hlPDRsaYHXlCJlMiogzyRSSNgk2dnDEZih8fAG3JZ4AgQB2ZNqw/2dRGlzzQXa8x1jEJUxNK1wB7I0bObJqy+Z3/0wzIFImPFWbsVtnsnUYNnhZFMSWKA1cyKL9hHA3DGLtAdD9vbh23hRtWuW+vd/40K9FVc8ljcIth1lkzzO8PiRblUutqxfHMuoV8n0KtRrHYCpKioL8xoke4RtoU2OfE5lNVSlQvkXuiCWAUjoXY/kH4wf9dtENO8gyihB+k1DLo69wvJAlDi9lZgn5nWVwwUutHym5oVHC1ux7Dyp18SnbCRjXa6lMWD6t7QVIBswjMbca9dXGNTt9cAgRdz+ft/ebKvr5+tyACbT/nLhwHbs83udGw+ddO7KcO2ZZAy6c2vggp++r+QWjAIigI92yaGlCIxGq1fnI3fpQzF6JXmStvVXk1mrw/BFlTd2Ocm5hY0cU0VoQM0svaEIeLSjYUiydKoqkGqsrA6nSpwf04yrYf5eoAzbPEMjcvyyVumbmcuH5+lNwOZRUaEAk62oh/Z8ZIfTGYqzapACZlrNOwQ2yb4y0PfN4hEHvCOTXva76oCaXjVeJlEWZkv0waNQmH6Vp7XRA0TsATp1XpR3zwcx2iGvarjUMWsgs3dMHiQ9TVcPYpSeYAvCXdcL1IjU8QHTqac7cEaHT6Jl+rVs5TXBkxxJKbit9WATDq2dOaZe8dZxRQ3avaW0osF+KWKKB3myeKBeQhO6tFpceB8L+Cfauj6bUh2tzv2Tza3YFwGvNvJ7Ks8gupmK2u2VAsJS10luDJlQh3fubd/J0fQGQpwwyqvgnPHczb2M8GpNQ1DH4zTDV+ZwEKdQVGPRNS6UpvEFTBdQjZWpB0cBacYYPdlmz3Ij3lSSyira2ElXc+fmSCQ/bjScAD/ywVJMAYAy7oC/3sHYGY6sPgjRpAt3AFlJfEgI2yL5SUuDZ+vMM8ogP4dHOVyF0T2dk4OjjOJ0qR4qjFtk3IfGzJYcge0cbbC9TVmhpF1DHqMWciVAwD06MtuvAocqHxWRTWhsTV0ALREZt+FIOL7aCTpteXZ/3PsiUozaaguOu4d25oztwsvpB8daxAv8DTAdixmnB4qBmkJ7I4GlF2IWk70keYCkM4+q/4WF0dLzWF8fZVMznwW+Bm6RY6OgIeBqFKKbYCAziiHENFiXamLmED9xXpAX7NEZlUXOqqpzGEKbaR/EMTuIoVnl6C4T92CdACf4yRPLF1ahJ2WOOLLlOV404KnXl3nUfN1mgEqk+CP/wg+OTVC/eoa4DoRPHdb9DGMp4K/4tiIKSDKl7BtpsfOb0CZpLC0MR++3FmF+f0r1IqwqPye70rsUZ3bsK66Kf1d6QxtXFajqV08/nKhUK7DmnxqIGA2NG+kMchlizuEB6JvxwroAwJepkF7D3nZz9toFNXcaR0gNxlr8YxVNiIJ8tfonJNzKr3na0eBieONEyXPGAK7WW3jchYAdzmnouSnpR9Y/p6t3eN1FES3wsUf/QFRhpsaZ4G+OSx5a38aReNliDbm4qzzcr1J8Y9Pl7rr5s1ocfqnqfIFiB2iJbZukc8edRKwzaYL8uk9on4alNK1Ca8KnjIP5iCWr6QE/55fgE8vLqIL9TfF2zmf6b+0c8pZ6J8NTdycawV922V+EYN2IaVWYgeOJJmz8tdcGt9IEr2xrtwKItMEaBby5ZRIE2aPWBaphOQT7xPiJhkLBXq3a05Xw0y4sSstY7Tb0RbA6zf1h0DWrjt0mfVR58JElkGKEXYdWOF9uL3LhNcdx4Dlx+0ksGMhZ+GRvOiPBYXVALuJtL77rXNz9Onk2o2e7RImPmxjq3iS1Ck4lhUJ3AlKkVpn8Zb/1+Nkq5BJVbvY0T3wPr/FdT76bncpX5NTcdnj2JXb2ZLd1ZC+Iw/d89vxwWPVepXaygF0gojePtvHsOukazg9sbb8+rQXbrqBKAP/hOJDtUemOWFa0wuqdjOikyr3snmE3zE8QUsqz7VZRbeDt9HDQ8bF7hyMMyaxe3r+YC/m/cDnUZK4Qv2uAR5aS9A87DYr33LBsKbKGTrJ5FX6XTCUSUzJYhZWbg5Su4mTjo+aZzAd9rH7mEC/brJB5gDLAUef8ajFuS6tYfd8gNMJdxXvVkbpSYVfTyn+/Zpb7Rz+oRkY6BgybVBcld08sr3JAHHBQ0mdoFyMNnX3r8X2HsjE8qX0U5iY01yam4uCKF+e7kv7mZSUozU/5OU7bonE2xB8fgnbnuizKq91YYA+Z2LUkWyJ+3WHl1k/G9CqY9PXYBpzUI7hIEr/XyeXC1oLlWr4p2yzxt/8EQGTf8Srobiox4kUD1TILsDxGqp7jhwOD/mV0ozDVGX1L1voHullEvItyRw96WwNnIxSPCTeQp2yTTXlJw74BP+TAix+oLNPQejMt1SFrya0fA+l2tXCP0YrF8/zDiooQAEAl9QDrZHKVUZtkbqhgUveamfSyCHNSBcxwmB+DKobbZihhhf/1nHF7cHk68F7MK158DgnGbwPC9NtjTs+yrFXuxLn+PirhhVdcanFS5YK2hl150u5YbML9IcU9RP6HcJfRM9Lnusow+RWK6u/VQ35n9Z4a5JABiokzBouPD7Jsj/esuXSw/ljzk9Z7hA81DVhz0c5aqt2JdGJZs1Zy6eJVeMDYEHu28TVaOWjZXG8kiCR+3ZcTWH1Pi6HhJTsUqdvpWEyzdb4jkv7oMfREuteN93bZLLqoTEr2FZ+SJN0vM06LVgp694iJiMildYCl04MUfyo926TNuR/ImaaYRewz/UOJM9FVICNFZUu8f4iGflMRp32eAv8o7VBInlho8sbEtuuvlfWBjfsVgGkmxC6suKzOWysVIEKAWEmBoJ7z8Y/Hxv/pOzwhoFqW9ERI4oEgYoktUm60fb1AmchW33pnomGydNQBAY+TJIHrqhpMmqfVUyFZQ48m5ZcMjcbtrIHCrf56jIg5aJt8a0Vr+x8tFtV79hGOKA5KIGIXs5avNzhaGx/tl7u+RGDSkaq9SEIEHdpfdDUlgbeJs92c4JdqQSQ5hW9XkcmAAnLRpFknYd+fKCH5f9GUeFjW2rNlXMp/HbmAFAL66waM1ljcdsdMmjpZDSIuK74vfN8igEy3cGhuXw88PaUVnDY57dnC3+Tik0wWtN45rrMH5Cmjfx6M2RZaeUWx6S7gh/wmRMkcIo3/Pbv9CodLcwHdZA6+ZW0U0yji90RM3IjDCvsGXxdpHg08sqNGi5ZSLYysSTd47hG8B+PMjMKGqtiXv33zEs5+wbP2lX3cS0RptEoh/G8xd94Eoo/UAa4YmZ4CCBeyk3KOb6AaNE4mwPZynam22ribQHybOUPmHAa1uuCYsY/5BI3NMWkJQifOjTWNHATY2yieC/OCapBUrZ+SL2sXju2gGqvblGVSMcouWrgO09egQyih4GMSswwMasxkgaB8ZAQ7K0n5TLuyNEuEmrDSEhks587gXCcfYFnQkkt540O9gFQNsAmYyj1TeLhmNHV8pZ5YsQPO5oAB5h6oxW0VTvIHwV2LPzXGInyj5dg61rLV1u0Fhvsaxh2g3vlaske4OuyYkZu6d14nKDSLswp6gNbw3+EFXZ0AQAa7CJsZ+8eqV+n3XDNAgahXJrZVUeicSIlWV5UTXGY3WS5+ftmcolntNtClqFuI1k/YfrQ3dp98io5I9dG5c2ICdi8gpQIddHwKLm+othGnnS8NHcyIBjNfumtUbTYRZNe+Ev1dDAn64DsIyL2xb+S6YHlxWgfUjla/9Z2Ja2MIYbLWDKqq5huh/7/sKtqljD0hMGkrAAJGmHCCFAX0LA9OkZky8jxok150atlhMYl+GsKdMpxus4bDCphDkq1vErpKDCsFGsE2cuprZXwo20jKQSHkiF4f7tRDq6pxJfkHoBd26aI/uBlspxLogp/mQy29EbvRR0qfReRtulhWunkwWcb7IO3N3xjAJuLqdDwp1tDbCChd0cA6IJ0PQBSMHipchzeNb8jCP5sjMVyUzGjf8ypgEMbA2aIkRfmofN32yeay68wGdp0w3tnt9nGPYDWQZvL2nxcS5+LnCEkySeZt1n/lkkGK1Pmg3q9caGkZMLev5GDaMl06QiLL6bb9wcxNI4nG3NGAJTK0sOqRlzwun7uCxxk2JnuOOscKD/pWhfiXMcrDA2u/8Oey2uoOgpn/1NSQ50CYYNS2lsc48dXjpY8WYWOgvOLoa4SX1ib41MBdWxpZUdVLpaAAB5o/w1QaAd71aEzgoU9ojviz+o9wx/7YO4qN2G5K1ib3dJK+gzRX+1sHQAkEYknlDrA0qH0dutWQiNtmeCRmXDSmYcNJLWd1IojwC24HwtRczqBekZWHioO7Sn160R57IVqTLoWetnfS13i4mfIUmhubEo88WiDZJGykYqTzE2ixqmv17HSEt3v9W7rm9NYY/WAVDkJEqGS7Dcy6VNtTe4yYN1fmjYuo/MyKM6eW17haHiBTfXgg/MFVKwO9Fg08RGbbDJduo2OgQhVYYZxK7o5YIre332+igxY9cHQboW3HS8EJ2vxu8oRkyqcRC3NYQEqqlIpmfEALz6o7tdrWmUcH17SvkXAjECaw5El+h6698BKNaegnj/k/rnfPY0c6MphkEU2jehrWXe16PHPwIz2jSfEBx0ua0tiu6Uavsrj8B/2aCE9wXGRf8FCVsj+05KkrtLxNuwwuM7ZcN1BWH4cf3HVjhfbLj1firawIEohH9rKw0F3l+rwOetg6Qqr+rdCs+SjalsR9SIVjWt6WFCPTWKO2SslCL+dFGq93jXGorcxEBGgv46eC9OsXF7y28ywIGs5R3jGTz9ORK06NoB9UaJbWjufmvwSlAtg29q5Q22d9iu99XoMjKO98vm0dw1KAALYh2epvtB3T2OM4wp5jUmtbePlHXBCTFelwVl0DkeQWnAGWrmCtGeZVBDRWsEJfz7xLb8vay/A3wHDi3sw00JmzjpAjauZHkHqZwm2G5QPim9IpXB4OFcdWEQHuYRBojPmrUjp5/WCPe92pdQ/UNhD94F9OS3/alLZ58AzVf8/6FMmdP82ZdPmThdBm1ryx3b9nkKAaJYr6BZybnvDLCwMj22OuqHyfNWXMsIL0cBON14xu0rWYzRhOjhSb0Ay5T1C9TjBWJdPSRFlIclR8qrkaoK5vegyETLOQHmu8aQ62FrwqC6Ai6BqrH0Jcp3Ri+Qy8YCce98xJ3xTl4WAJmcTQQQ2aMLsH43OV9V+MR7tR2YXwHGMyBiD0luPhiHU2rqB4/HtZC3Sg1fAiau4QjM6Hm57jtXMY+F4wZgMOk3W9t8oeSctIZWCdoUAuIL1rficRVaOSb19tF3LN7KqUI0EnQtHgwDSCtTlTfunxeNC9RtCgVcwVpaPcd/9jsGRrDqxZF0pcc6hA6O6v/N9FDkZKbmEwFqRvCBZR377Y8QPil72xzWCY3/gR+LJi1OrB+wIMIQ2khU/ag1qdNsyfDjw20mqLR4hdGkImfMBRgVcPqKflLvj8sXK9YG4Fu7PNQlXVaAB2JxjtuM6EDQTbVv8MyrfC01oqUEtM/XWEL8jG/lXvYTr9cECsW8AUr3+yS8DkzCfrWJ8AcnsvQdQRlg8gXzfU0lnAPNgXAFDIbt5MB27xOPe+oLkqfT74Y66Qc3J+RbqrxmFdL4fF6Ll+xcK9K9lMpbBnePSv3sScxMZOq2qAQIA98yEvG/2VpEE2KYsGFtZX0q6fhLUZhClSDC54hos1PRcn89JiucWbNdRYbNaRCLziS0Cmc/mZ2q53sLjFogNcWT/RirQawwCJv641dZ147n9apUBCWPMDmvzDv99l1yu8pJl61at7FWXJTco28zTFA5TIdDCiGBjWf9ZUDsHs2HkAT1qCR1OFsEF/04kgcRNLmUG4FY9uLH6wBt4Xy0NERUCCfI4BP2hMfWaSvVxRUjrc93OQ2wjsCuE/IVnUKdiPNUIIkMj1a1aWJ/2kR4TXdQJu4kKPDuws2ygkIKCsAhM4m9kEi2TJDaPZTxhO8wXVnSVpSGG/FjURRDq4vU2fAAaN4xcWYdNBV7hEXpNFXYViTtzUMWjFf7aqYp7aBsj2tLiYCFoj3kQQJPnygiZyRi7EZPxcKYB6IgeOTt/DxYU3XxIdCIJLEO/x1vZXOb5s/yt3BAVg6GTtmKf9jjoVpSyJCe0WK2uiLvAZDNWrFVVVlf8+WNHzLuUmts5q0pVJ23b0VC431NX+KoWWSzPP9amkpNiRU/ERgb7zwlvjpRoi+XZO3DMSnDQXir2CvT8pIAXfDJhYjb8adj7MeQ72QDPuu2vdsNR+N84bIVet7UYHougsXWSTPUZMNvj6MfrDlnQCNvpPUjew9W2MriKFGHqdol8wSUtsGJCHb+GD9I0OrqAv4Fc279czRMXO32g95KepfYnEQytkv3tQoFWy8Kh3QueIC0u3qIPgMnQJHzKreGoQniLVhxO+Xb0Gl+iIirsZ/DDquVWChcZ8VZTJyGpZJ7mXzWmv7oX675/Z1hIykETnCYedLmD/hn8+tkXaPW9zajRTr3AiI+mCpry8YEQBQXBPU46DvP8DK250VUAx6GH/IJv/amMWuknAWvPI1uEvRy7ZohHH6z3lapwkiuB9+5+FPI0i9nmzCNWRTuShevbkLOXST3mp7XszYRkDPhaTjqlQxEuE//9rySSH1l7hwGbvM/lJp17tKdnTJkKddiMRqXgROtOneTVtu21Mf5YpzTRAZmAiHEK6ZmIid8AdIC6koyZfgztW0Lqz/Dc8zHr2J/Z79D4PMuQEM0T0IapS5OwozTyrKzBW8IhPIux/uqZDSljZLvwDDAn+KqFWceVXfmvJZ3/9DNlPxMhqxRPygAKYkAm1K++1jF0JLL3GoHoCP2vEB1aT/BH/TiPlCNS6Ic5n/x1utN0XJHN2ygPaCxFvbcZIDfotB6OTixJdNWeGcWQGrqxNNCjsoJLim5PFXB396weszN3zZLAQ8F2OTAMVBPNaxh6h7K0v1HScj5SIrxrywQzKMvv+7CX4/a2rIwm6mB2i+9fHaLYuHC/0PQsgtAaUSBBLVUpJi05qphpsiKMHmCNhmEQiLbkP4H2h5io4mj3IKc0FNxZNhg8wtS0yyWx+rc+TTL3EnaneefIz9U1EF6CCmYV+Z/69GrUDZU9EXHXvXbbytwlN/KvoIv2/5zihzqqUrgLLRFc2h2BQWH92HqVDbrC+gUpoOD9mOuMYzjDF+wj6+Z4b8YTYeIhncmsHkQsbdvbZQ18fFoJWX+Poxkjoe8MDccykO8wGS9gx5nlusd/w88y6t0LSCBkcZGTHK2ghpSaYPM4NBtCADC5lq4kJFxwJGRvU1RppFpWiF1yXQJjcUOu+uiQTdcoM+tcPMVzMyi/NHJFf7qMmGyiEYOJmoZuVKU/b039dXKsHU2Bzb/vUxq3+E+UKHlkYKoXfnHdPHxXmOQS1NpGMJBHw4A7gfRjIMKL2LqNhnyZwffGaL4nFwLvmGfQtpwgvaTL9As+HuMBIPvvjb6e1GlrKY3WdwkHQ4gMNdCOL9ZAWDh74egkTevxvhQ4gMxCij5hk7XPe8CNIVOeQaqtqhAgC8XvywUjHaTh+wPzLS6kE5CE2FdOEZzdnuqkidGCsQ51E6v53qga91iHA9mLkaUG0UkBANKb3ekPjiW4NmBpx9rod7sQbhUOeZxcyjsZvD2wdP+BZ95598PgoTDFPlYMejJjMJ6xOMylrm9YCKjcdNIsOm+AVg8aH1h3q4J1Myhcz48dHUizwb/GNqEhD9P/TJ+ViFpSNKpy96ZFEVzSt9qgbQHkpKLmUYCP1EySJXx5HypFBwfsbSmO121ecrjVn5FIEFslP2Ch+BlFcN88nMz97BHeZerjTY9n3fvbcXad1PgkO/r5V2ym/9jTe+THDE7aSx0heLtsd1OnTuhs9of9j3/SD3j3tBU5/F/4x4qTqPXPuvT4aBGF7w1QjaWhXmvg0/XfqiWumI24UuT5qXCA4b+J2Ls1AlcR/85O8/jG3pn7MWkkTpY8lQL18esbeg8lX/0zMzr9dFJiscbxHz+lz1btV9OVbSr0UrNCvqlsYEar1iF7eZ73ZovlvyLI/aPFlfSzAGtQKBluOUQJB2QAPJLedRVrHmPLvQwyVGoyKleOWpD6XNqa3qF09XsmksM17zbIgj1Gbs7tn2WFF/4ZocvQaJpfE+dWIG/K1APXB0jx7p4T/11ClVVfF2MvVBe8BUFTUDJfen221icv3vu7QUzC6NNLXLEt4d1THYnyqdEO3WI+v4Z5uhai9CiHk0mf3mPif8N0mH4iX8qLDRaKGXcbn76h0lB2L0NqkPNRXdRBtecMSA782h6+Y24Ro5jYR1Vo3h4ZKalZ/SQlEbW/+UnqBy/HXiion7c1j6b+a3sg60gsWRs+295SKbl1igk+aGl+5rfHFO0bkZ8zQ+fYwK6Yv7r+KHT6ObmgkTNqwd1dzIIPOgnPKCPg35Qh+WsPztp2lp/OkrZ30J7MJQMZgKYAA4aAFy8MrRJfVPhO1ehWlcKzqMwU2tRyvkltigUH/X2f/lLWo5wXIqhbxzbRvagVPWwt4jpIntSjcaxgyY7TXCJEQG2pQrSLkgxrd8Wi7zph8XTTxTSJ+D8t9snF9Gb3DFFY07qKAq225/A4PLXAdoxoJK0TTkZt9VfaCrMXtVZbH5ZOVbNulV8dJEeTev1RpaDUpGM32ZSfN/x5gdRhue1MBOXzcQGsQUqr1GLpSiWAqIDKK5OP5QFMUVMEiJS62UIvLjZ4+ott8yiZZcMGfAeaUg/Zbuj1gWylogxcdgF/226d/af9Yc1eIbi81gYaHoanlHaJXEC3chncAr1hYmVSbXRTjpM4BieuINqNr8LGk5Lx0KQDKTT4qCHdcMbUiauQH8/PpDDZ3rp9DJAwp0VVe0phIkl8NYfyQTF4Kj7pDeNJ6NwlFBEZYtmj49J+3PmsCqQCv9v02IW7V8ZLzJRS1Wxan3U5CD7bfJHuAcmdREz4+8cPw7VDsOVymLTJ34Km/1Q1mU5NHNLs14iByijGwG2M1jFWOXRiXtBcNAb/3DPg5HA9F4E0GJWVXzTyDtzurgNH1SltTBsTJewr2SF6wxIAHO+xlvgQG1DXSkLJ3E6Bm2ynTtbOOFrFONaS2RGmDEqV0PZUK9KzXt8YHYcnsvOBNyQ4X9vih08ZNqKocDkZGRzp7/OFPdUsA/Bq7+S3ipY2DIdZ/SHd7zsrjP8bFXtzmxKFbvD2eR7pkdv2iNgrr/NMiF9wWOyHn6g/TuwVJZDvN8OBldGPlSMihGcAcpL7gTdPccTd2JP8mwMvRiemlsNI5qadGGoyNqn/aSBMU+TSARf2UYLX2ClMzH93KJIyWNPOganWyogNpTfhr5tzXr/fc99qespzs8gC8AL88kOw/dise5xmAPnB93wdlT9DySvCJhQlCwBQVBvj1gz/D+gXQQ9uCeDoASh3gTRv3dcjRPe2PMl6rMbW86KDHLcVGV91ibvbEujGMTlJV29UT8saH1iSoODb3AhNysIp9wnJ5/9qHLJ1wMA2mUUokih4WNzxY4oP7birflob4p6OdEz8IjRlrUAcjB83h5Yd7r6w3wcsEHlVMVB2mqbJqLu4LEGoUgco3Ddso0u25sMT9szP9Q5MKRHdwkJx80l5k7+5nf3FjWpObsDVcH2gqjhQ5Yj+RDb6KCXb0+6pPxEHWmae/yfiu9t4MiwRsrWE9DSd9oOYHX6eq0/wdInvmVdMx3DYmmC6StSJeop4ZqT5nh/knP1sX7DTKU3RHrvtw5d3wYOmFUPf/+0e4U80W4DIw4nBQJqWPj2T2dIVON0xj+IX8fyfuu67V+P9KQVaTgH39XdHGe0OFKvGO7neX+AyPvH4xgKsZa4ou18ZaRKNe3G3iw1cHF6GGD8oAoJfN9OPPzqCoRG/nAM0WMdIEEjEoATIcUWh5IZKKW67pn0hem1mvfbcV5enO2cb84x7Hz9VSiXJosQdSCp1j5s2Tu9JjQ1Zi3L3Hbf9MLt12pSgOFluvIJeYlmUrqABQRmevBTtp1BF4pEagThd4EBALmtZI0VnUTrXTnCgPQGw3m8cTkSX0Rqpo/MZp5C/5KUB3cpJsXycqcHGhtbeBlrpaQCsBJDjeUKcel5kUfCUCGyRp9idqx+GYMQxj+yzapkRQci3MdrZ1erHCImVkl1qhra0ekLbDbdwLhiJKE5j7jobREon3I7HqhcfHT4KMNu1YEw9DmYYHI/eyV+JZHC8t2EIXpmNaq1xQHkMQH0amgX7Cy+SBn4s5kYdP3BmBnIW9qRFcs7gHjHc7y58FRwPul8D6cSzuZofXMZCw+RsiY=",
  "type": "AgentGovernanceReceipt",
  "verify_pubkey_b64": "ig6AWna3kodv7bngRvd6hJ+AbhXGznIh6dhFlA2pfPQ="
}
