Include the root cause or CWE in published CVEs so that design flaws can be analysed across the industry, even though complete records take extra time; CISA's Stakeholder-Specific Vulnerability Categorization is referenced for vulnerability management.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.