Default Routing Table
Stage-to-model assignments for the Hunt/Validate/Score pipeline
hunt
Fable 5
anthropic
validate
Fable 5
anthropic
score
Claude Opus 4.8
anthropic
gapfill
Claude Opus 4.8
anthropic
Model Roster
Frontier models mapped to Vercel AI Gateway
Fable 5
fable5
Validate Pin
Primary Hunt + Validate
anthropic
AI Gateway Model
anthropic/claude-fable-5Harness Model ID
claude-fable-5Input:$3/M
Output:$15/M
Anthropic Mythos-class frontier model for general hunt + validate use. Known refusal classes (operator trust required): auth-bypass, CORS, SSRF, OIDC-logic, injection, agent-impersonation.
Claude Opus 4.8
opus48
Scorer of record + gapfill
anthropic
AI Gateway Model
anthropic/claude-opus-4.8Harness Model ID
claude-opus-4-8Input:$15/M
Output:$75/M
Scorer of record for the comparative scorecard (spec § 6). Recommended for auth/SSRF/OIDC/CORS logic tasks when Fable 5 is blocked (dual-model pattern).
GPT-5.5
gpt55
Cross-validation
openai
AI Gateway Model
openai/gpt-5.5Harness Model ID
gpt-5.5Input:$7/M
Output:$28/M
OpenAI frontier model for cross-model validation and scoring diversity.
Attack Class Taxonomy
44 attack classes across 8 security frameworks
OWASP Top 10:2025
11 classes
Injection
injection
Broken Access Control
broken-access-control
Cryptographic Failures
cryptographic-failures
Security Misconfiguration
security-misconfiguration
Supply Chain Failures
supply-chain-failures
Authentication Failures
auth-failures
Server-Side Request Forgery
ssrf
Secrets in Code
secrets-in-code
IaC Privilege Escalation
iac-privilege-escalation
Header / CSP Hygiene
header-csp-hygiene
Mishandling of Exceptional Conditions
exceptional-conditions
MCP Server Security
8 classes
MCP Tool Poisoning
mcp-tool-poisoning
MCP Rug Pull
mcp-rug-pull
MCP Tool Shadowing
mcp-tool-shadowing
MCP Indirect Injection
mcp-indirect-injection
MCP Session Hijacking
mcp-session-hijacking
MCP DNS Rebinding
mcp-dns-rebinding
MCP OAuth RCE
mcp-oauth-rce
MCP Resource Exhaustion
mcp-resource-exhaustion
RAG / Vector DB Attacks
4 classes
RAG Retrieval Poisoning
rag-retrieval-poisoning
RAG Embedding Inversion
rag-embedding-inversion
RAG Tenant Boundary Violation
rag-tenant-boundary-violation
RAG Indirect Injection
rag-indirect-injection
OWASP Agentic Top 10:2026
7 classes
Agent Goal Hijacking
agent-goal-hijacking
Insecure Tool Execution
insecure-tool-execution
Memory Poisoning
memory-poisoning
Excessive Agency
excessive-agency
Agent Identity Abuse
agent-identity-abuse
Insecure Inter-Agent Comms
insecure-inter-agent-comms
Unbounded Autonomy
unbounded-autonomy
MITRE ATLAS v5.4.0 + Emerging
2 classes
MCP Escape to Host
mcp-escape-to-host
Emergent Offensive Reasoning
emergent-offensive-reasoning
OWASP API Security Top 10:2023
5 classes
API Broken Object Level Authz
api-bola
API Broken Function Level Authz
api-bfla
API Mass Assignment
api-mass-assignment
Zombie / Shadow Endpoint
api-zombie-shadow-endpoint
WebSocket Abuse
websocket-abuse
OWASP Business Logic Abuse:2025
1 classes
Business Logic Abuse
business-logic-abuse
NHI / Container / CI-CD
4 classes
Non-Human Identity Abuse
non-human-identity-abuse
Container Runtime Escape
container-runtime-escape
K8s RBAC Lateral Movement
k8s-rbac-lateral-movement
CI/CD Pipeline Poisoning
cicd-pipeline-poisoning
LLM / AI Pipeline
2 classes
LLM Model Weight Backdoor
llm-model-weight-backdoor
LLM Inference Data Exfil
llm-inference-data-exfil
Framework Reference
Security framework sources and documentation
OWASP
11
OWASP Top 10:2025
OWASP Foundation
MCP
8
MCP Server Security
NSA CSI / OWASP MCP Top 10
RAG
4
RAG / Vector DB Attacks
USENIX Security 2025
Agentic
7
OWASP Agentic Top 10:2026
genai.owasp.org / AIUC-1
ATLAS
2
MITRE ATLAS v5.4.0 + Emerging
MITRE ATLAS (Feb 2026)
API
5
OWASP API Security Top 10:2023
OWASP API Security
BLA
1
OWASP Business Logic Abuse:2025
OWASP BLA Top 10
NHI
4
NHI / Container / CI-CD
NIST SP 800-207 / MITRE ATT&CK / SLSA
LLM
2
LLM / AI Pipeline
NIST AI 100-2:2025 / MITRE ATLAS