module-evidencelisted
Install: claude install-skill matis-dev/m-skills
# Module: Evidence and Identifiers
**Loaded by:** `security-architect` · `accessibility-architect` · `search-optimization-architect` · `product-architect` · `documentation-architect` · `marketing-architect`. Read it whenever a run cites a standard, a study, or a number; do not restate its content in a skill file.
**Why this is a module and not just Guidelines §15:** §15 forbids inventing facts. These are the domains where an invented fact does not stay in the conversation — a CWE number ends up in a ticket, a WCAG criterion ends up in a VPAT or a procurement answer, a market size ends up in a board deck, a benchmark ends up in a README a stranger acts on. The rule is the same; the blast radius is what earns the extra discipline.
---
## 1. Never Invent an Identifier
An OWASP category, a CWE number, a WCAG success criterion, an RFC, a CVE, a spec section. If you are not **certain** of the identifier:
> **Describe the weakness or barrier precisely, and omit the number.**
A described finding with no ID is honest work. A confident wrong `CWE-000` is a defect worse than silence, because the number is exactly the part a human downstream will trust without checking.
Two corollaries:
- **Levels and names are part of the identifier.** An AAA criterion quoted as an AA requirement is wrong even though the number is right. A renamed category quoted under its old name is wrong even though it exists.
- **Re-verify before repeating.** A figure you read in a file six months ago is no