14 Commits
Author SHA1 Message Date
Dan Jones c1c8a8c147 Clarify guidance and full audit modes 2026-09-14 20:28:54 +01:00
literally-dan d24bc26917 Merge pull request #12 from cloudflare/harden-audit-workflow-and-validators
Rework the audit workflow, findings contract, and validators end to end
2026-09-10 12:45:47 +01:00
literally-dan 158eb44803 Rework the audit workflow, findings contract, and validators end to end
Findings contract: findings.json now uses three verdict branches -
confirmed, needs_validation, and rejected - with complete traces,
bounded local evidence, and severity capped at demonstrated impact.

Coverage: reconnaissance seeds a deterministic coverage ledger with
canonical collision-checked unit IDs, append-only attempt provenance,
explicit per-state field invariants, and prior-run carry rules that
revalidate unchanged confirmations and turn deferred, blocked, and
out-of-scope prior units into current work. Coverage-critic waves,
critic-inclusive budget reservation, and an explicit incomplete-run
state replace silent coverage claims.

Ten domain companions (AI/LLM, web protocol and auth, client-side,
memory safety and binary, cloud and deployment, data isolation and
lifecycle, desktop/mobile/local IPC, protocols/RPC/messaging, resource
exhaustion, supply chain and release) share one section schema and are
copied verbatim into hunter prompts alongside the ordinary attack
classes.

Safety: target-controlled execution requires an OS-enforced sandbox
with no external network, an allowlisted empty environment, resource
limits, and scratch-only writes; missing controls retain the lead as
needs_validation. Artifact promotion is a single canonical procedure -
descriptor-anchored no-follow walks, regular-file and size checks,
exclusive creation - stated once in SKILL.md and embedded byte-identical
in the hunter and verifier prompts. Audit output defaults outside the
target repository.

Validators: validate-findings.cjs is hardened (visible-prose vs exact
payload separation, platform-unsafe path rejection, canonical Set-based
uniqueness, pre-parse structural limits, no-follow input, fatal UTF-8,
sanitized capped error output) and a new zero-dependency
validate-coverage-ledger.cjs enforces the ledger contract with the same
input and output safety. Both ship with test suites (65 tests) and a
cross-validator consistency test.

Prompting: instruction conflicts resolved, explicit stop conditions and
terminal states, exploration depth bounds, schema branches included in
subagent prompts with literal return envelopes, and malformed-result
handling that preserves verifier independence.

Validated end to end with a live budget-limited audit run against an
internal repository: both validators passed and the run reported honest
partial coverage.
2026-09-10 11:11:38 +01:00
literally-dan 8bac42001d Merge pull request #6 from cloudflare/add-ai-web-protocol-attack-classes
Add ai web protocol attack classes
2026-07-06 14:36:00 +01:00
Dan Jones c1239b9037 Bring the whole skill into one coherent house style
Cross-file coherence pass driven by a whole-skill review (blind cold-read +
consistency + workflow/schema + density auditors):

- Severity: document that findings.json uses the schema's lowercase enum (the
  UPPERCASE prose tiers are labels, not JSON values) and define an INFORMATIONAL
  tier so prose and schema agree; drop "hardening gaps" from LOW.
- Finding bar: make HUNTING.md's validation rules the canonical bar that SKILL
  points to and Phase 3 re-applies adversarially; resolve the learn-field-names
  contradiction (not a finding on its own, matching HUNTING).
- Naming: rename the companion "Verification discipline" heading to "Validation
  rules" (matching HUNTING) and reserve "verification" for Phase 6; unify on
  "hardening note"; retitle RECONNAISSANCE.md to "# Reconnaissance".
- Scope: state that dynamic confirmation is in scope where the target is
  buildable — extract suspect code into a minimal harness to test a hypothesis —
  and that unbuildable claims are "requires deployment testing", not confirmed.
- Generalize the Phase 6 verifier beyond HTTP (CLI/native/syscall/tool entry
  points); document the schema-required intended_behavior and confidence fields.
- Include Phase 1 in SKILL's subagent-write list.
2026-07-06 14:25:33 +01:00
Dan Jones b6b3f15a81 Add AI/LLM, HTTP-protocol/auth, and client-side attack-class companions
New domain companion files, each following the MEMORY-SAFETY-AND-BINARY.md
template (when-to-use / fenced core discipline / tagged classes / universal
moves / verification bar):
- AI-AND-LLM.md — prompt-injection, agent/tool, and output-handling classes
- WEB-PROTOCOL-AND-AUTH.md — HTTP framing/cache and auth-protocol classes
- CLIENT-SIDE.md — DOM-injection, messaging-trust, UI-redress, prototype pollution

Integration:
- ATTACK-CLASSES.md routes AI/LLM, HTTP-protocol/auth, and client-side targets
  to the companions; the inline client-side bullet is replaced by a routed file
- SKILL.md workflow and README file table list all companions
2026-07-06 14:25:33 +01:00
literally-dan 642fbadc37 Merge pull request #3 from kennysarnoski-jarvis/add-memory-safety-and-binary
Add memory-safety, binary, and kernel hunting classes for native targets
2026-07-04 09:19:58 +01:00
Dan Jones 78d28faf8e fix: move MEMORY-SAFETY-AND-BINARY.md to skills/security-audit/ 2026-07-04 09:19:40 +01:00
kennysarnoski f5c2df0a3f Add memory-safety, binary, and kernel hunting classes for native targets 2026-07-04 09:16:24 +01:00
literally-dan fc70eadbf6 Merge pull request #4 from CooperSheroy/catalina/validate-trace-sequence-20260702
fix: validate trace step ordering
2026-07-03 12:35:33 +01:00
CooperSheroy 71e15497c7 fix: validate trace step ordering 2026-07-02 09:04:16 +05:30
literally-dan f75f9a0056 Merge pull request #2 from lambda0xyz/fix/skill-directory-structure
fix: move skill files to separate folder to make it compatible with npx skills add
2026-06-29 14:48:05 +01:00
lambda0xyz 75be8dd130 fix: move skill files to separate folder to make it compatible with npx skills add 2026-06-24 23:08:20 +03:00
Dan Jones 4de1ac8012 Initial commit 2026-06-18 17:20:36 +01:00