{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp09_archetype_breadth150_20260804","research_id":"eoa_inverse_innovation_exp09_light_prior_art_20260804","cell_id":"anchoring_reset__computer_science","search_lanes":{"direct_problem_and_intervention":{"queries":["vulnerability triage anchoring bias CVSS score study","cybersecurity vulnerability severity score anchoring effect analysts","blind independent assessment before seeing score anchoring debiasing software vulnerability triage","vulnerability assessment blind review severity score workflow"],"source_ids":["SRC3","SRC4"],"no_result_note":"No retained source evaluated the exact combination of masking a scanner score, recording a service-context estimate, revealing the score, and repairing downstream workflow fields."},"synonyms_and_historical_terms":{"queries":["anchoring CVSS","anchoring heuristic blind obedience CVSS vulnerability","security threat scoring independently before sharing anchoring","bug bounty triage hide severity score independent assessment"],"source_ids":["SRC3","SRC4"],"no_result_note":null},"products_practices_and_standards":{"queries":["risk based vulnerability management CVSS asset context compensating controls standard","FedRAMP continuous vulnerability management CVSS context reachability exploitability","CVSS environmental threat metrics vulnerability prioritization","STRIDE DREAD threat scoring anchoring independent scores"],"source_ids":["SRC1","SRC2","SRC4"],"no_result_note":null},"component_combination":{"queries":["vulnerability severity source inconsistency downstream prioritization independent assessment","vulnerability triage CVSS context exploitability impact remediation deadline audit trail","pre-score independent security risk assessment compare scores discuss divergence","vulnerability scanner score asset criticality reachability compensating controls remediation scheduling"],"source_ids":["SRC1","SRC2","SRC3","SRC4"],"no_result_note":"The component practices were found separately or in adjacent security-scoring workflows, but not as the proposal's complete exposure-order and downstream-inheritance control."}},"sources":[{"source_id":"SRC1","title":"RFC-0012 FedRAMP Continuous Vulnerability Management Standard","publisher":"FedRAMP","url":"https://www.fedramp.gov/rfcs/0012/","source_type":"OFFICIAL_STANDARD","claims_supported":["FedRAMP requires vulnerability reports to include reachability, exploitability, potential impact, mitigation or remediation plans, measures taken, and a changelog.","Providers must adjust vulnerability risk and severity using both CVSS base scores and context including criticality, reachability, exploitability, detectability, prevalence, and mitigation.","The standard connects assessed vulnerability state to remediation timeframes while cautioning against unnecessary disclosure of sensitive vulnerability information."]},{"source_id":"SRC2","title":"Common Vulnerability Scoring System version 4.0: User Guide","publisher":"Forum of Incident Response and Security Teams (FIRST)","url":"https://www.first.org/cvss/user-guide","source_type":"OFFICIAL_STANDARD","claims_supported":["CVSS Base measures intrinsic severity rather than organizational risk and should not be used alone for risk assessment.","Environmental and Threat metrics are the consumer's responsibility and can incorporate deployment context, asset data, exposure, threat intelligence, and compensating controls.","FIRST recommends enriching scanner results with asset information and distinguishes Base-only scores from context-enriched scores."]},{"source_id":"SRC3","title":"An Investigation into Inconsistency of Software Vulnerability Severity across Data Sources","publisher":"IEEE SANER 2022; manuscript hosted by arXiv","url":"https://arxiv.org/abs/2112.10356","source_type":"PRIMARY_RESEARCH","claims_supported":["The empirical study found weak agreement among independently produced vulnerability-severity rankings across reporting sources.","Initial severity underestimation was associated with lower prioritization, showing that early severity information can affect remediation triage.","Severity-source inconsistency affected downstream tasks and degraded downstream severity-prediction performance by as much as 77% in the study."]},{"source_id":"SRC4","title":"How to Build a STRIDE Threat Model for Application Security","publisher":"Inventive HQ","url":"https://inventivehq.com/knowledge-base/security-compliance/how-to-build-a-stride-threat-model","source_type":"TRADE_PROFESSIONAL","claims_supported":["The application-security practice identifies anchoring when the first proposed threat score influences later scores.","It recommends that participants record scores independently before sharing, then compare scores and discuss divergences.","It links the resulting risk tier to remediation plans, owners, target dates, backlog items, and release decisions."]}],"problem_evidence":{"status":"PARTLY_SUPPORTED","finding":"The problem is visible in related manifestations: official standards warn that Base scores alone are not risk assessments and require contextual adjustment, while primary research shows inconsistent early severity judgments can alter prioritization and downstream results. An adjacent application-security practice explicitly recognizes first-score anchoring. However, the retained evidence does not directly demonstrate that scanner-score exposure causally anchors organizational vulnerability triagers, so the proposal's precise mechanism remains unconfirmed.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"closest_prior_art":[{"name":"CVSS v4 Environmental and Threat enrichment","source_ids":["SRC2"],"overlap":"Adds deployment-specific environmental factors, threat intelligence, asset data, exposure, and controls to a generic Base score and supports more defensible prioritization.","remaining_difference":"It does not require a contextual priority estimate before the Base score is displayed, measure reveal-induced movement, or repair ticket and release artifacts inherited before review."},{"name":"FedRAMP context-adjusted continuous vulnerability management","source_ids":["SRC1"],"overlap":"Requires contextual exploitability and impact assessment, auditable vulnerability reports, changelogs, and context-linked remediation timeframes.","remaining_difference":"It does not prescribe score masking, a pre-anchor judgment window, blind-versus-visible comparison, or an explicit downstream-anchor reset."},{"name":"Independent-before-sharing application-security threat scoring","source_ids":["SRC4"],"overlap":"Recognizes first-score anchoring and uses independent initial scores followed by comparison and discussion; risk tiers flow into remediation and release work.","remaining_difference":"It concerns collaborative STRIDE/DREAD threat modeling rather than automated-scanner vulnerability intake, and it lacks score-reveal measurement, uncertainty bands, masked adjudication, and systematic repair of already populated downstream fields."},{"name":"Independent vulnerability-severity assessments across reporting sources","source_ids":["SRC3"],"overlap":"Provides independent severity judgments, documents disagreement, and demonstrates consequences for prioritization and downstream tasks.","remaining_difference":"It is an observational study of reporting sources, not a controlled exposure-order intervention within one triage workflow."}],"prior_art_disposition":"ADJACENT_PRIOR_ART","contrastive_claim_remaining":"In scanner-driven vulnerability intake, obtaining and timestamping a context-only priority and uncertainty assessment before score exposure, then revealing and comparing the scanner score and explicitly revising inherited deadlines and workflow fields, will reduce anchor-proximal judgment movement and improve agreement with masked authorized adjudication relative to ordinary score-visible contextual review.","contrastive_claim_falsifier":"The claim is falsified if credible score masking produces no material difference in priority, confidence, rationale, or downstream-field choices versus score-visible review, or if any differences fail to improve alignment with a predefined evidence rubric and masked authorized adjudication after accounting for missing information and policy disagreement.","gates":{"adequate_source_search":{"status":"PASS","rationale":"The bounded search covered the direct formulation, anchoring and independent-assessment terminology, official vulnerability-management standards, adjacent security practices, and combinations involving context, severity, prioritization, and downstream workflow. Four opened sources from four publishers include two official standards and primary research.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"supported_problem":{"status":"PASS","rationale":"The evidence partly supports the problem: generic severity scores require context, early severity errors affect prioritization, and first-score anchoring is recognized in adjacent application-security scoring. Direct causal evidence for scanner-score anchoring in vulnerability triage remains absent.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"distinct_testable_claim":{"status":"PASS","rationale":"The remaining contrast is operational and falsifiable: pre-exposure contextual assessment plus reveal comparison and downstream repair can be compared against score-visible contextual assessment using predefined outcomes.","source_ids":["SRC1","SRC2","SRC3","SRC4"]},"bounded_next_test":{"status":"PASS","rationale":"The proposed 12-finding or two-week randomized shadow pilot is bounded, preserves production decisions, and measures reveal-related movement, evidence quality, time burden, masked-adjudicator agreement, and prospective downstream differences. Its small sample is appropriate for feasibility and signal detection, not an effectiveness conclusion.","source_ids":["SRC3","SRC4"]},"no_obvious_safety_or_authority_stop":{"status":"PASS","rationale":"The pilot leaves production priorities, deadlines, scanner configuration, and release decisions unchanged; retains the authorized risk owner; excludes incidents; and includes stops for impaired urgent handling, failed masking, access-rule conflicts, and leakage into production. Sensitive vulnerability information must remain limited to necessary parties.","source_ids":["SRC1"]}},"screen_survival":true,"world_novelty_boundary":"This bounded public-web screen found adjacent standards, research, and practices but no opened source containing the proposal's complete workflow. That result establishes neither world novelty nor patentability, market size, expert acceptance, implementation value, or absence of undiscovered proprietary, patent, non-indexed, differently worded, or later prior art."}