CRE 0,CRE 1,CRE 2,CRE 3,CRE 4,AVE|name,AVE|id,AVE|hyperlink,AVE|description 636-660|Technical application security controls,126-668|Secure data storage,223-780|Secret storage,774-888|Do not store secrets in the code,,Hardcoded credentials in agent component - API keys and secrets exposed in skill files,AVE-2026-00047,https://github.com/aveproject/ave/blob/main/records/AVE-2026-00047.json,"direct match, independently confirmed" 636-660|Technical application security controls,278-646|Secure communication,228-551|TLS,430-636|Verify TLS certificates and trust chain,,TLS certificate verification disabled in agent component configuration,AVE-2026-00061,https://github.com/aveproject/ave/blob/main/records/AVE-2026-00061.json,"direct match, independently confirmed" 636-660|Technical application security controls,503-455|Input and output protection,130-550|File handling,451-082|File execution,675-168|Sanitize filename metadata from untrusted origin if processing is required,Path traversal via unsanitized path parameter in MCP resource/file-handler implementation,AVE-2026-00053,https://github.com/aveproject/ave/blob/main/records/AVE-2026-00053.json,"direct match, independently confirmed"