feat(decision): pluggable System One backend — TypeSafe (hosted) or Laya (local)

Laya (github.com/NandhaKishorM/laya) is the same System One abstraction as
TypeSafe — identical choice/score/noul primitives — but local, open-source
(Apache 2.0) and free. Added it as a swappable backend, entirely additively:
the hosted TypeSafe path is byte-for-byte unchanged (key alone → same endpoint,
model, bearer as before).

- typesafe.rs: endpoint/model/bearer are now instance fields with env overrides
  (NEUROSPLOIT_DECISION_ENDPOINT / _MODEL). Defaults are the hosted TypeSafe API.
  from_env() now also activates when a local endpoint is configured (no key).
  backend_label() names the active backend in the run banner.
- tools/laya_shim.py: a stdlib HTTP shim that loads Laya and exposes the exact
  POST /systemone contract the client already speaks. Model downloads on first
  use (HF cache); no key; evidence stays on the box.
- CLI: --decision-backend typesafe|laya. `laya` installs laya if missing, starts
  the shim, waits for readiness, and points the client at it — all optional,
  only when the operator selects it.

383 tests; the hosted TypeSafe behaviour is untouched.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUP
2026-09-20 19:27:14 -03:00
co-authored by Claude Opus 5
parent d752e252e6
commit 56b2c80ae4
6 changed files with 285 additions and 10 deletions
+13
View File
@@ -506,6 +506,19 @@ neurosploit run https://app --typesafe off # the identical pipeline, no TypeS
records `"typesafe": true|false` — a clean with/without measurement you can run
against your own target.
**Pluggable decision backend.** The calibrated System One layer runs against
either backend, chosen with `--decision-backend`:
- `typesafe` — the hosted API (set `TYPESAFE_API_KEY`).
- `laya` — [Laya](https://github.com/NandhaKishorM/laya), a local, open-source
System One engine (Apache 2.0) with the same primitives. Picking it downloads
the model on first use, runs it on this machine, needs no API key, and keeps
the engagement's evidence on the box — the right choice for air-gapped or OT
work. It starts a small local shim (`tools/laya_shim.py`) automatically.
Both speak the same contract, so adjudication, CVSS grading, agent pruning and
the confirmation loop behave identically whichever you pick.
### Scope-evasion resistance, evidence integrity, untrusted output
Three hardening passes, all enforced in code: