feat(typesafe): confirmation-loop agent + --typesafe flag (on/off/auto) for A/B

TypeSafe cannot BE an LLM agent — System One does not generate text or call
tools. But it can be the decision brain of a code-owned confirmation loop, and
that is what typesafe_agent.rs is: an ADDITIONAL confirmation strategy.

typesafe_agent.rs — for enumerable classes (XSS, SQLi, open-redirect, path
traversal, SSRF, IDOR): code lists candidate payloads, a TypeSafe Choice picks
the next one given what's been tried, the replay engine sends it for real, a
TypeSafe Noul judges the response, loop until confirmed or exhausted. Edge/WAF
answers are refused. Pure parts (class table, payload templating, id-swap, OAST
substitution, query encoding) are unit-tested; the networked loop is integration.

Wired as a pipeline pass that runs ONLY on findings the LLM path left
unconfirmed or in needs-review (the recall lever) — it can raise a finding to
confirmed with a calibrated probability, never downgrades (the deterministic
layer owns that).

--typesafe on|off|auto (global flag) resolves into the env the pipeline reads,
governing adjudication, CVSS re-grade, agent pruning and this loop together.
`off` runs the identical pipeline without TypeSafe; meta.json records
"typesafe": true|false so a with/without pair is a clean A/B measurement. Web
console gets the same toggle.

381 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 5 committed 2026-09-19 18:15:10 -03:00
1 parent 48c38d4798
commit 8e84656f4f
8 files changed
+475

No files matched your search

+2
View File
@@ -646,6 +646,7 @@ function buildArgs(body) {
if (body.oobHttp) args.push('--oob-http', body.oobHttp);
if (body.oobDns) args.push('--oob-dns', body.oobDns);
if (body.sms) args.push('--sms', body.sms);
if (body.typesafe) args.push('--typesafe', body.typesafe);
if (body.intercept && body.intercept !== 'off') args.push('--intercept', body.intercept);
if (body.sandbox) args.push('--sandbox', body.sandbox === 'default' ? '' : body.sandbox);
if (body.revalidatePoc) args.push('--revalidate-poc');
@@ -722,6 +723,7 @@ function authArgs(body) {
if (body.oobHttp) args.push('--oob-http', body.oobHttp);
if (body.oobDns) args.push('--oob-dns', body.oobDns);
if (body.sms) args.push('--sms', body.sms);
if (body.typesafe) args.push('--typesafe', body.typesafe);
if (body.intercept && body.intercept !== 'off') args.push('--intercept', body.intercept);
if (body.sandbox) args.push('--sandbox', body.sandbox === 'default' ? '' : body.sandbox);
if (body.revalidatePoc) args.push('--revalidate-poc');