diff --git a/resources/specs/claude-false-positive-filtering.md b/resources/specs/claude-false-positive-filtering.md index 384e1d48..f6eebbf0 100644 --- a/resources/specs/claude-false-positive-filtering.md +++ b/resources/specs/claude-false-positive-filtering.md @@ -63,3 +63,4 @@ 29. Keep custom backend findings only when the issue is in Mongoose’s backend interface, default backend, documented backend contract, or common backend implementation. 30. When uncertain, keep findings with clear external input, reachable code path, and concrete impact in Mongoose library/protocol/driver code; filter internal-access, impossible-state, local-misuse, generic-hardening, and speculative reports. 31. For dashboard reports, do not infer unauthenticated access from a route-specific check alone; account for the broader authentication flow. Keep concrete reachable bugs such as path traversal, unsafe decoded paths, or file read/write/delete issues. +32. Filter reports regarding DNS transaction ID predictability or lack of strict question-name matching in DNS response processing, as these are acknowledged design limitations of the current implementation. \ No newline at end of file