Commit Graph
747 Commits
Author SHA1 Message Date
jiawenlai1109 1fd08f50ee fix(audio_generator): clean up temp file when gTTS save() fails
generate_audio_cross_platform() created the temp MP3 via tts.save() one
statement *before* the try/finally that was supposed to remove it, so any
exception raised by the save itself escaped the cleanup and left
temp_audio_<hex>.mp3 in the current working directory.

gTTS.save() performs an outbound HTTP request, which is exactly the path that
fails offline or behind egress restrictions, and .gitignore does not cover the
temp_audio_* pattern - so every such run litters the working tree.

Move the save inside the existing try. Success-path behaviour is unchanged, and
this now matches how generate_audio_mac_wav() in the same file already guards
its two temp paths.

Verified on Ubuntu 22.04 / Python 3.14.7, same offline-failing test before and
after: leaked temp_audio_*.mp3 count went 1 -> 0, test result unchanged
(1 failed, gTTSError: Failed to connect). black --check passes; rest of the
module is 1 passed, 1 skipped, 1 pre-existing offline failure.
2026-09-22 17:55:01 +08:00
Alexander Myasoedov 2340bc2f5a Merge pull request #345 from Anai-Guo/fix/hybrid-classifier-self-annotation
fix(refusal_classifier): quote self-referential annotation to fix import NameError
2026-09-11 10:08:39 +03:00
Tai An 6f221d5c62 fix(refusal_classifier): quote self-referential return annotation to fix import NameError 2026-09-11 00:07:19 -07:00
Alexander MyasoedovandClaude Fable 5.1 1f2413e2b0 fix: ci pre-commit poetry env
Install poetry before setup-python and enable the poetry cache so
setup-python activates the 3.14 interpreter. With virtualenvs.create=false
poetry otherwise installs into the runner's system Python 3.12 and fails
uninstalling Debian dist-packages.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Bk6CFfaN3YJFZ6yztQja7D
2026-09-07 14:08:49 +03:00
Alexander Myasoedov a49706457c fix: pc 2026-09-07 14:03:57 +03:00
Alexander Myasoedov 5a9e80b9af fix: cosmetic 2026-09-07 14:03:57 +03:00
Alexander Myasoedov 3e6b184c4f fix: template fix 2026-09-07 14:03:57 +03:00
Alexander Myasoedov f286ebf21a fix: docs 2026-09-07 14:03:57 +03:00
Alexander Myasoedov b5aa075927 Merge pull request #340 from rwinkelman/feat/scan-cli-spec-309
feat(cli): add stateless scan command for agent-invocable runs (#309)
2026-09-07 13:36:03 +03:00
Alexander Myasoedov 35379d1124 fix: build 2026-09-07 13:35:20 +03:00
Alexander Myasoedov fd43b13bb7 fix: syntax error 2026-09-07 13:24:28 +03:00
Alexander Myasoedov c75df250c7 Merge pull request #343 from TianHengZhuang/main
docs: document module interface and add ModuleProtocol
2026-09-07 13:16:03 +03:00
Alexander Myasoedov 80015fd803 Merge pull request #342 from Sabina8205/docs/cli-reference
docs: add CLI reference and correct configuration filename
2026-09-07 13:14:19 +03:00
TianHengZhuang ad41e09a2c docs: add module docstrings 2026-09-07 11:06:45 +08:00
TianHengZhuang 39fa5b34c0 docs: add module docstrings 2026-09-07 11:06:38 +08:00
TianHengZhuang d41039773e docs: add module docstrings 2026-09-07 11:06:32 +08:00
TianHengZhuang c78f4ced91 docs: add module docstrings 2026-09-07 11:06:25 +08:00
TianHengZhuang 587cbe53f3 docs: fix external_module.md examples 2026-09-07 11:05:46 +08:00
TianHengZhuang 66a38574a5 docs: add ModuleProtocol 2026-09-07 11:05:40 +08:00
Sabina8205 dd97599863 docs: add CLI reference and correct configuration filename 2026-09-02 19:21:07 +08:00
Shadow e9f4491930 style: format scan_cli for black pre-commit 2026-09-01 23:34:54 +07:00
Shadow d12b14acd6 feat(cli): add stateless scan command for agent-invocable runs (#309)
Expose `agentic_security scan --spec` to stream JSONL results from stdin, a
file, or inline HTTP spec text without agesec.toml or the web server.
2026-09-01 20:29:38 +07:00
Alexander Myasoedov 73f84b7aa8 Merge pull request #338 from rwinkelman/fix/scan-route-logging-199
feat: add structured logging to scan API routes (#199)
2026-09-01 16:16:22 +03:00
Ray Winkelman 35ae256729 feat: add structured logging to scan API routes (#199)
Log verify/scan/stop/scan-csv entry points and outcomes for easier debugging.
MCP was removed per #306; this covers the equivalent HTTP scan surface.
2026-09-01 15:25:20 +07:00
Alexander Myasoedov 797180ca3a Merge pull request #336 from rwinkelman/fix/verify-integration-error-status-173
fix(ui): mark integration verify failure on network errors
2026-08-31 14:17:34 +03:00
Ray Winkelman 723460768f fix(ui): mark integration verify failure on network errors
Fixes #173
2026-08-29 16:04:18 +07:00
Alexander Myasoedov 1ef131421e feat: move to python 3.14 baseline, patch remaining dependabot alerts
- requires-python >=3.14, pyupgrade --py314-plus, Dockerfile python:3.14-slim
- test matrix 3.14 only
- fastapi ^0.141.1 + starlette 1.6.0 (unblocks 5 starlette alerts)
- python-multipart ^0.0.31 (4 alerts)
- fix TemplateResponse for starlette 1.x request-first signature
- drop teyit hook: abandoned, incompatible with python 3.14
2026-08-18 19:14:05 +03:00
Alexander Myasoedov 11024e6fca fix(deps): patch 47 dependabot alerts via lock bump 2026-08-18 19:07:13 +03:00
Alexander Myasoedov 2f128ae16c fix(deps): bump pyarrow to 25.0.1 for cp314 wheels 2026-08-18 19:01:16 +03:00
Alexander Myasoedov 3b1067c317 fix(pc): 2026-08-18 18:49:56 +03:00
Alexander Myasoedov 27c160eaa3 Merge pull request #326 from chiruu12/fix/hybrid-classifier-guards
fix(hybrid): guard zero total weight and log skipped detectors
2026-08-18 18:40:07 +03:00
Alexander Myasoedov de16779806 Merge pull request #328 from feiiiiii5/fix-circuit-breaker-half-open
fix(circuit-breaker): reopen on failure during half-open probation
2026-08-18 18:39:03 +03:00
Alexander Myasoedov 017ba7c168 Merge pull request #329 from feiiiiii5/fix-p95-percentile-index
fix(executor): compute p95 latency as a real 95th percentile
2026-08-18 18:38:25 +03:00
Alexander Myasoedov 43922ced3d Merge pull request #330 from ChrisJr404/code-block-stenography
Add code_block stenography transform (embed prompt in a docstring)
2026-08-18 18:37:40 +03:00
Alexander Myasoedov 14e45f3788 Merge pull request #331 from ChrisJr404/feat/owasp-llm-badges
Add OWASP LLM Top 10 category badges to the scan UI
2026-08-18 18:36:50 +03:00
Chris (ChrisJr404) 79f450bbae Tag probe datasets with OWASP LLM Top 10 categories in the scan UI 2026-08-17 23:49:11 -04:00
Chris (ChrisJr404) 95c14c3ee5 Add code_block stenography transform that hides prompts in a Python docstring 2026-08-17 21:57:08 -04:00
fei cf3498264f fix(executor): compute p95 latency as a real 95th percentile
ExecutorMetrics.get_stats picked the p95 element with
int(n * 0.95), which collapses to the last index (the maximum)
for any batch of 20 or fewer requests, so the reported p95 was
actually the worst-case latency for typical scan batches. Use
ceil(n * 0.95) - 1, the standard nearest-rank index.
2026-08-16 18:39:10 +08:00
fei fcd1fd20ae fix(circuit-breaker): reopen on failure during half-open probation
record_failure ignored the half_open state: the minimum-sample gate
(total >= 10) and the success counter meant a failure during
probation neither re-opened the circuit nor prevented it from
closing. One failure followed by three successes closed the circuit
with the failure forgotten. Trip back to open on the first half-open
failure, with fresh counters.
2026-08-16 18:23:29 +08:00
chiruu12 2f411b90dc fix(hybrid): guard zero total weight and log skipped detectors 2026-08-14 17:04:47 +05:30
Alexander Myasoedov c8458d73c5 Merge pull request #320 from DevamShah/fix-cors-credentials-and-icon-traversal
fix: wildcard CORS + credentials spec violation, path-traversal guard on /icons proxy
2026-07-31 19:27:20 +03:00
Alexander Myasoedov 42615e506a fix(build): 2026-06-23 10:20:10 +03:00
Alexander Myasoedov e6459a551a Merge pull request #321 from DevamShah/config-pluggable-detectors
feat: config-pluggable refusal classifiers and leak detectors
2026-06-23 10:12:26 +03:00
Devam Shah d28c4b4b1e feat: config-pluggable refusal classifiers and leak detectors
PIIDetector and SandboxEscapeDetector were wired directly in
probe_actor/refusal.py and the refusal classifier manager was populated from
a hardcoded list, so the only way to toggle a bundled detector or add an
organization-specific signature was to patch the module.

Add a DetectorRegistry mapping plugin names to factories, assembled from an
agentic_security.toml [detectors] section via build_from_config. Custom
detectors load by import path ("pkg.module:ClassName"). refusal.py gains
build_refusal_manager(config=None) reading the [detectors] table; all public
symbols are preserved. Built-in leak detectors ship registered but disabled,
so default refusal_heuristic behaviour is unchanged.

Closes #82

Signed-off-by: Devam Shah <devamshah91@gmail.com>
2026-06-22 19:40:33 +05:30
Devam Shah dd59704fdf fix: wildcard CORS + credentials spec violation, path-traversal guard on /icons proxy
CORS: drop allow_credentials=True. With allow_origins=['*'] Starlette reflects
the request Origin and emits Access-Control-Allow-Credentials: true on any
credentialed request — a reflect-any-origin hole. The app authenticates with
Bearer tokens in the Authorization header, so credentialed CORS was never needed.

/icons/{icon_name}: validate against a strict allowlist (re.fullmatch
[A-Za-z0-9._-]+\.png) and assert the resolved path stays inside ICONS_DIR before
any filesystem write or outbound fetch. Closes the path-traversal / arbitrary-write
(CWE-22) and controlled-URL (CWE-73) surface on the unsanitized icon_name.

Adds CORS middleware tests and icon-name validation tests (traversal, encoded
slash, null byte, trailing newline, wrong extension).

Closes #298

Signed-off-by: Devam Shah <devamshah91@gmail.com>
2026-06-22 10:10:43 +05:30
Alexander Myasoedov 8e12141df8 Merge pull request #318 from nakshaatraa/docs/fuzzer-module-docstring
docs: add module-level docstring and document constants in fuzzer.py
2026-06-15 12:55:19 +03:00
Alexander Myasoedov b90b80a0af Merge pull request #317 from nakshaatraa/fix/image-generator-matplotlib-warnings
fix: set matplotlib Agg backend and sanitize prompt whitespace
2026-06-15 12:54:41 +03:00
Alexander Myasoedov b827a0b186 Merge pull request #316 from jasoncobra3/chore/delete-agno-dead-code-v2
chore: delete Agno dead code (Phase 1)
2026-06-15 12:52:19 +03:00
Nakshatra Mote 30566b9d4d Add module-level docstring and document constants in fuzzer.py 2026-06-15 14:44:55 +05:30
Nakshatra Mote 6dec776700 Fix matplotlib warnings and TclError in image generator 2026-06-15 14:44:16 +05:30