Findings contract: findings.json now uses three verdict branches -
confirmed, needs_validation, and rejected - with complete traces,
bounded local evidence, and severity capped at demonstrated impact.
Coverage: reconnaissance seeds a deterministic coverage ledger with
canonical collision-checked unit IDs, append-only attempt provenance,
explicit per-state field invariants, and prior-run carry rules that
revalidate unchanged confirmations and turn deferred, blocked, and
out-of-scope prior units into current work. Coverage-critic waves,
critic-inclusive budget reservation, and an explicit incomplete-run
state replace silent coverage claims.
Ten domain companions (AI/LLM, web protocol and auth, client-side,
memory safety and binary, cloud and deployment, data isolation and
lifecycle, desktop/mobile/local IPC, protocols/RPC/messaging, resource
exhaustion, supply chain and release) share one section schema and are
copied verbatim into hunter prompts alongside the ordinary attack
classes.
Safety: target-controlled execution requires an OS-enforced sandbox
with no external network, an allowlisted empty environment, resource
limits, and scratch-only writes; missing controls retain the lead as
needs_validation. Artifact promotion is a single canonical procedure -
descriptor-anchored no-follow walks, regular-file and size checks,
exclusive creation - stated once in SKILL.md and embedded byte-identical
in the hunter and verifier prompts. Audit output defaults outside the
target repository.
Validators: validate-findings.cjs is hardened (visible-prose vs exact
payload separation, platform-unsafe path rejection, canonical Set-based
uniqueness, pre-parse structural limits, no-follow input, fatal UTF-8,
sanitized capped error output) and a new zero-dependency
validate-coverage-ledger.cjs enforces the ledger contract with the same
input and output safety. Both ship with test suites (65 tests) and a
cross-validator consistency test.
Prompting: instruction conflicts resolved, explicit stop conditions and
terminal states, exploration depth bounds, schema branches included in
subagent prompts with literal return envelopes, and malformed-result
handling that preserves verifier independence.
Validated end to end with a live budget-limited audit run against an
internal repository: both validators passed and the run reported honest
partial coverage.
Cross-file coherence pass driven by a whole-skill review (blind cold-read +
consistency + workflow/schema + density auditors):
- Severity: document that findings.json uses the schema's lowercase enum (the
UPPERCASE prose tiers are labels, not JSON values) and define an INFORMATIONAL
tier so prose and schema agree; drop "hardening gaps" from LOW.
- Finding bar: make HUNTING.md's validation rules the canonical bar that SKILL
points to and Phase 3 re-applies adversarially; resolve the learn-field-names
contradiction (not a finding on its own, matching HUNTING).
- Naming: rename the companion "Verification discipline" heading to "Validation
rules" (matching HUNTING) and reserve "verification" for Phase 6; unify on
"hardening note"; retitle RECONNAISSANCE.md to "# Reconnaissance".
- Scope: state that dynamic confirmation is in scope where the target is
buildable — extract suspect code into a minimal harness to test a hypothesis —
and that unbuildable claims are "requires deployment testing", not confirmed.
- Generalize the Phase 6 verifier beyond HTTP (CLI/native/syscall/tool entry
points); document the schema-required intended_behavior and confidence fields.
- Include Phase 1 in SKILL's subagent-write list.
New domain companion files, each following the MEMORY-SAFETY-AND-BINARY.md
template (when-to-use / fenced core discipline / tagged classes / universal
moves / verification bar):
- AI-AND-LLM.md — prompt-injection, agent/tool, and output-handling classes
- WEB-PROTOCOL-AND-AUTH.md — HTTP framing/cache and auth-protocol classes
- CLIENT-SIDE.md — DOM-injection, messaging-trust, UI-redress, prototype pollution
Integration:
- ATTACK-CLASSES.md routes AI/LLM, HTTP-protocol/auth, and client-side targets
to the companions; the inline client-side bullet is replaced by a routed file
- SKILL.md workflow and README file table list all companions