Skip to content
Merged
6 changes: 6 additions & 0 deletions docs/design/2026-09-27-abusekit-design.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,12 @@ see account churn, tiers failed open when a scorer was unavailable, and request
cover reads or replay. This revision fixes those and tightens every place an implementer would have
had to guess. Changes from r1 are marked **[r2]**.

**Amendment (proposed 2026-09-29, revision 7):** [`2026-09-29-generic-feature-packs.md`](2026-09-29-generic-feature-packs.md)
makes the binary domain-neutral (email becomes a YAML reference pack), renames the built-in features once into namespaced packs enabled per tenant, adds
product-declared vocabularies (types, field kinds, link kinds, subject kinds) with pseudonymising
redaction, and adds bounded declarative custom features in YAML. It amends §4.2, §4.3, §4.5, §4.6, §4.8
and §4.10 below, and keeps e2a's feature values, risks and tiers bit-identical.

## 1. Problem statement

In September 2026 a single operator ran two phishing campaigns through e2a. The first churned
Expand Down
Loading
Loading