{"schema_version":"canary-commons-benchmark-map/v1","dataset_version":"1.0.0","note":"Conceptual mapping only. Canary Commons cases test untrusted-content handling; existing runtime benchmark risk classes test related enforcement boundaries and are not equivalent measurements.","mappings":[{"threat_label":"indirect_prompt_injection","related_benchmark_risk_classes":["tool_poisoning"],"related_scenarios":["tool_poisoning_fixture"]},{"threat_label":"instruction_priority_override","related_benchmark_risk_classes":["tool_poisoning"],"related_scenarios":["tool_poisoning_fixture"]},{"threat_label":"authority_spoofing","related_benchmark_risk_classes":["approval_control"],"related_scenarios":["approve_blocked_action"]},{"threat_label":"synthetic_data_exfiltration","related_benchmark_risk_classes":["secret_access"],"related_scenarios":["read_fixture_env","read_fixture_npmrc","read_fixture_ssh_key"]},{"threat_label":"tool_misuse_request","related_benchmark_risk_classes":["risky_shell","mcp_server_change"],"related_scenarios":["execute_risky_shell","register_new_mcp_server","change_existing_mcp_server"]},{"threat_label":"persistence_request","related_benchmark_risk_classes":["mcp_server_change","approval_control"],"related_scenarios":["change_existing_mcp_server","approve_blocked_action"]}]}