Taxonomy
What an agent can do to you.
Severity is about what an action costs if it turns out to be wrong, not
how likely it is to be wrong and not how bad the skill is. A great many
of these actions are ordinary practice at one company and forbidden at
the next; severity is the size of the bet, and whether you want to take
it is your policy, not our verdict. Approvals is how many times a person has to
approve an action on one resource before it stops asking, and it is
derived, not chosen: N = ceil(ln 0.05 / ln(1 - eps)), where
eps falls as severity rises. The arithmetic is here.
The cliff at 75
This is the part that is a judgement rather than a calculation, so it is stated in the open where it can be argued with. An action above that line has no lane and makes no progress toward one. A person looks, every time, however well it went before.
Where these came from
The classes describe consequences, not vulnerabilities. That is the
difference between this and a CVE feed: there is nothing to patch in
rm -rf. It does exactly what it says, and the question is
whether this agent may do it here, now, without asking.
The list is fixed and public so that a verdict means the same thing in the index, in the scanner and in the gateway. The open dataset uses these keys, and so does oats-scan.