feat: upgrade SAFE-UC-0002 (Personalized shopping sidekick) to draft#35
Merged
bishnubista merged 1 commit intoApr 25, 2026
Conversation
… to full draft First retail use case in the SAFE-AUCA registry, opening NAICS 44-45. 6-stage baseline-shape kill chain (after four consecutive expanded drafts at 0008, 0021, 0025, 0030) with two NOVEL stages: sponsor-disclosure transparency at S2, purchase-as-write-back gating at S4. SAFE-MCP mapping across 14 techniques within the 12 to 15 baseline target. Framework crosswalk spans FTC Reviews Rule (16 CFR Part 465 effective 21 October 2024), Endorsement Guides (16 CFR Part 255 revised June 2023), Click-to-Cancel Rule (Part 425 amended October 2024), ROSCA, CFPB Circular 2023-01, California ARL with AB 2863 (effective 1 July 2025), DSA Articles 25/27/28 with Commission July 2025 Guidelines, COPPA 2025 amendments, EU AI Act Article 50 (applies 2 August 2026), CCPA/CPRA ADMT regulations (finalised 23 September 2025), NIST AI 600-1, OWASP LLM Top 10 (2025), MITRE ATLAS, PCI DSS 4.0.1. Incident citations precision-framed: Moffatt v Air Canada (2024 BCCRT 149, 14 February 2024, $812 CAD), Chevy Tahoe prompt-injection demo (December 2023), FTC Operation AI Comply, FTC v Amazon Prime (June 2023 filing), FTC v Adobe (June 2024), EU Commission v Temu (October 2024), EU Commission v Shein (February 2026), TechCrunch Rufus independent review (March 2024), Bloomberg Klarna AI-to-human reversal (May 2025). All 69 URLs live-verified in Phase 2 (100 percent Tier A or B with 3 Tier C corroborated). Coined new workflow_family "Consumer retail and shopping assistants". Drafted under the no-em-dash human-technical-writer voice rule. Signed-off-by: arjunastha <arjun@astha.ai>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Promotes SAFE-UC-0002 from seed to full draft. First retail use case in the SAFE-AUCA registry, opening NAICS 44-45.
Changes
Citation accuracy
All 69 URLs independently live-verified in Phase 2 before commit (54 verification calls total). Tier coverage: 100 percent Tier A (28 URLs: regulators, judicial, government, standards) or Tier B (36 URLs: vendor first-party, GitHub canonical, arxiv, MITRE, OWASP, AI Incident Database) or Tier C (3 URLs: TechCrunch Rufus review, Bloomberg Klarna reversal, CBC Air Canada, all corroborated to Tier A or B). Zero Tier D citations.
Precision-critical facts verified: SAFE-T1402 "Stenography" typo preserved verbatim; FTC Reviews Rule (16 CFR Part 465) effective 21 October 2024 distinct from Endorsement Guides (16 CFR Part 255 revised June 2023); FTC Click-to-Cancel Rule October 2024 amends 16 CFR Part 425 Negative Option Rule (separate from Reviews Rule); California ARL 2024 amendment is AB 2863 (signed 24 September 2024, effective 1 July 2025), not AB 390; CFPB Circular 2023-01 dated 19 January 2023; Moffatt v Air Canada is BCCRT (Civil Resolution Tribunal), $812 CAD total, negligent misrepresentation; Chevy Tahoe prompt-injection demo by Chris Bakke December 2023 (not fraud, not enforceable sale); FTC v Amazon Prime June 2023 cited as the lawsuit filing; EU AI Act Article 50 applies from 2 August 2026; DSA Article 28 Guidelines published 14 July 2025; CPPA finalized ADMT regulations approved 23 September 2025 in force 1 January 2027.
Safety attestation
No exploit steps, no sensitive information, defender-friendly throughout. Voice-drift scan returned 0 DRIFT. Em-dash scan returned 0 hits after two targeted rewords in §7 kill-chain table headings. Drafted under the no-em-dash human-technical-writer voice rule. Every must, required, mandatory hit falls into the hard-safety whitelist (HITL gating, regulatory verbatim surfacing, attribution to human principal), factual-regulatory (quoting law verbatim), or structural template-inherited usage.
Requesting DSO review per CONTRIBUTING.md.