Canonical primitives
Crypto primitive names in findings and rule packs are canonical and uppercase (RSA, ECDSA, AES, SHA-256, ML-KEM, ML-DSA, …).
Why this matters
Free-text primitive labels break correlation, classification tables, and SARIF baselines. Rules must reference a primitive that exists in the classifier’s canonical set (internal/classify in the repository).