Commit Graph
87 Commits
Author SHA1 Message Date
jiawenlai1109 1fd08f50ee fix(audio_generator): clean up temp file when gTTS save() fails
generate_audio_cross_platform() created the temp MP3 via tts.save() one
statement *before* the try/finally that was supposed to remove it, so any
exception raised by the save itself escaped the cleanup and left
temp_audio_<hex>.mp3 in the current working directory.

gTTS.save() performs an outbound HTTP request, which is exactly the path that
fails offline or behind egress restrictions, and .gitignore does not cover the
temp_audio_* pattern - so every such run litters the working tree.

Move the save inside the existing try. Success-path behaviour is unchanged, and
this now matches how generate_audio_mac_wav() in the same file already guards
its two temp paths.

Verified on Ubuntu 22.04 / Python 3.14.7, same offline-failing test before and
after: leaked temp_audio_*.mp3 count went 1 -> 0, test result unchanged
(1 failed, gTTSError: Failed to connect). black --check passes; rest of the
module is 1 passed, 1 skipped, 1 pre-existing offline failure.
2026-09-22 17:55:01 +08:00
Alexander Myasoedov a49706457c fix: pc 2026-09-07 14:03:57 +03:00
Alexander Myasoedov 35379d1124 fix: build 2026-09-07 13:35:20 +03:00
Alexander Myasoedov fd43b13bb7 fix: syntax error 2026-09-07 13:24:28 +03:00
TianHengZhuang ad41e09a2c docs: add module docstrings 2026-09-07 11:06:45 +08:00
TianHengZhuang 39fa5b34c0 docs: add module docstrings 2026-09-07 11:06:38 +08:00
TianHengZhuang d41039773e docs: add module docstrings 2026-09-07 11:06:32 +08:00
TianHengZhuang c78f4ced91 docs: add module docstrings 2026-09-07 11:06:25 +08:00
TianHengZhuang 66a38574a5 docs: add ModuleProtocol 2026-09-07 11:05:40 +08:00
Alexander Myasoedov 3b1067c317 fix(pc): 2026-08-18 18:49:56 +03:00
Alexander Myasoedov 43922ced3d Merge pull request #330 from ChrisJr404/code-block-stenography
Add code_block stenography transform (embed prompt in a docstring)
2026-08-18 18:37:40 +03:00
Chris (ChrisJr404) 79f450bbae Tag probe datasets with OWASP LLM Top 10 categories in the scan UI 2026-08-17 23:49:11 -04:00
Chris (ChrisJr404) 95c14c3ee5 Add code_block stenography transform that hides prompts in a Python docstring 2026-08-17 21:57:08 -04:00
Alexander Myasoedov 42615e506a fix(build): 2026-06-23 10:20:10 +03:00
Nakshatra Mote 6dec776700 Fix matplotlib warnings and TclError in image generator 2026-06-15 14:44:16 +05:30
zhanz5 f25520869f merge: resolve conflict with upstream msoedov/agentic_security
Merged upstream/main into fix/cost-calculation-model-aware.

Conflict resolved in cost_module.py:
- Kept upstream's updated PRICING table (2026-06-03 verified prices)
- Kept upstream's DEFAULT_MODEL = "claude-sonnet"
- Kept upstream's 50/50 input/output token split
- Preserved our float | None return type for unknown models
- Preserved our logger.warning instead of raise ValueError
2026-06-05 14:15:08 +08:00
zhanz5 02b68b06ee fix: make cost calculation model-aware instead of hardcoded to deepseek-chat
Previously, calculate_cost() was always called without a model parameter,
causing all scans to report costs based on deepseek-chat pricing regardless
of the actual target model (e.g. gpt-4, claude-3-opus).

Changes:

- http_spec.py: Add 'model_name' property to LLMSpec that extracts the
  model field from the JSON request body. Returns 'unknown' if the body
  is not valid JSON or has no 'model' field.

- probe_data/image_generator.py: Add 'model_name' pass-through property
  to RequestAdapter, delegating to the underlying LLMSpec.

- probe_data/audio_generator.py: Same as above - add 'model_name'
  pass-through property to RequestAdapter.

- probe_actor/cost_module.py:
  - Change return type from float to float | None.
  - Unknown models now log a warning and return None instead of raising
    ValueError, so scans are not interrupted by unsupported model names.
  - Add logger import for the warning message.

- probe_actor/fuzzer.py: Pass model_name to calculate_cost() in both
  scan_module() and perform_many_shot_scan() using
  getattr(request_factory, 'model_name', 'unknown').

- primitives/models.py: Update ScanResult.cost type from float to
  float | None to accommodate unknown model pricing.
2026-06-05 13:59:59 +08:00
Alexander Myasoedov 7b8d238254 Merge pull request #305 from zhanz5/fix/remove-duplicate-probedataset-msj
fix: remove duplicate ProbeDataset class from msj_data.py
2026-06-04 17:47:17 +03:00
zhanz5 5e5469a1a7 fix: remove duplicate ProbeDataset class from msj_data.py
msj_data.py contained a full copy of the ProbeDataset dataclass that
was already defined canonically in probe_data/models.py, violating DRY
and leaving a stale TODO comment in the source.

Changes:
- probe_data/msj_data.py: delete the 19-line duplicate ProbeDataset
  definition and the now-unused 'from dataclasses import dataclass'
  import; replace with a single re-export:
    from agentic_security.probe_data.models import ProbeDataset
  All call-sites inside the file (load_dataset_generic, prepare_prompts)
  continue to work unchanged because the field signatures are identical.
  The TODO comment is removed as the refactor is now complete.

No changes required in consumers (fuzzer.py, test_msj_data.py) because
they access ProbeDataset through msj_data's re-export.
2026-06-04 21:46:22 +08:00
zhanz5 4a5c2ddb54 fix: implement scan-csv route to actually use uploaded CSV data
The /scan-csv endpoint was reading the uploaded CSV file but discarding
the content (TODO comment), resulting in scans that ran with zero prompts.

Changes:
- routes/scan.py: parse uploaded CSV via parse_csv_content(), pass the
  extracted prompts as inline_datasets to the Scan model; also fix the
  maxBudget query parameter being silently ignored (hardcoded to 1000).
- probe_data/data.py: add parse_csv_content(bytes) -> ProbeDataset that
  looks for a 'prompt' column first, falls back to the first text column,
  and raises ValueError when no suitable column is found.
- primitives/models.py: add inline_datasets: list[dict] field to Scan
  model for carrying uploaded prompts through the scan pipeline.
- probe_actor/fuzzer.py: perform_single_shot_scan now accepts
  inline_datasets and appends them as ProbeDataset objects to the scan
  modules; scan_router transparently forwards the field.
2026-06-03 17:56:58 +08:00
Alexander Myasoedov e38365c904 Merge pull request #290 from ykd007/feat/google-sheets-dataset-support
feat(datasets): support Google Sheets URLs in dataset loader
2026-05-14 19:20:49 +03:00
ykd007 dc24d91250 style: apply black formatting 2026-05-14 21:34:14 +05:30
Alexander Myasoedov a0b2b9ec70 feat(py upgrade): 2026-05-14 18:56:24 +03:00
ykd007 68ef73e528 fix: move import re to module level 2026-05-14 15:04:20 +05:30
ykd007 b4a5a5dc5a feat(datasets): support Google Sheets URLs in dataset loader 2026-05-14 15:02:24 +05:30
Alexander Myasoedov a9adb22458 fix(pc): 2025-12-24 08:16:21 +02:00
Alexander Myasoedov 48125bd106 feat(add executor): 2025-12-24 08:10:08 +02:00
Alexander Myasoedov d56b406e1a fix(tests runtime): 2025-12-09 20:00:04 +02:00
Alexander Myasoedov 9a4fb05491 fix(pc): 2025-11-30 18:50:00 +02:00
DavdaJames a02aed2c2b changes done by pre-commit hooks 2025-08-10 14:33:25 +05:30
Alexander Myasoedov 926c583a17 fix(csv ds loading): 2025-05-27 13:41:10 +03:00
Alexander Myasoedov c5c5ae2e4b fix(makedir): 2025-05-19 12:29:28 +03:00
Hanyin 335787d40e refactor: standardize CSV loading from ./datasets and improve robustness
- Load all CSVs from ./datasets directory
- Add encoding_errors='ignore' for resilient CSV parsing
- Ensure prompt generators are converted to lists before sampling
2025-05-19 16:19:38 +08:00
Alexander Myasoedov 35fd373cb2 fix(pc): 2025-04-02 13:33:20 +03:00
Alexander Myasoedov f2b95a0040 fix(tests): 2025-04-02 13:31:36 +03:00
Alexander Myasoedov da63270142 fix(pc): 2025-03-18 17:40:23 +02:00
Ismail mach d3ccea76b6 Auto-fix: formatting, bug fixes, import sorting, and type check improvements
Signed-off-by: ikhanganin <ismailmac39@gmail.com>
2025-03-18 15:12:00 +00:00
Alexander Myasoedov 8e5a53eaa3 fix(pc): 2025-03-13 18:42:16 +02:00
Alexander Myasoedov f4271ef2a1 fix(csv loader): 2025-03-13 18:32:22 +02:00
Alexander Myasoedov feb1becb3e feat(update registry): 2025-03-13 18:26:54 +02:00
Alexander Myasoedov 7b44a2f510 feat(add csv utils): 2025-03-13 18:26:27 +02:00
Alexander Myasoedov 37a6e7a5bc fix(data loaders): 2025-03-13 18:12:33 +02:00
Alexander Myasoedov 91c99e642f fix(pc): 2025-03-10 13:25:17 +02:00
Alexander Myasoedov 1226e2059d Merge branch 'main' of github.com:msoedov/agentic_security 2025-03-10 13:24:42 +02:00
Alexander Myasoedov c94aa54e41 Merge pull request #172 from nemanjaASE/issue-157-error-handling
Added error handling for subprocess.run calls by logging errors and raising AudioGenerationError.
2025-03-10 13:23:20 +02:00
nemanjaASE 6e6abae680 Added error handling for subprocess.run calls by logging errors and raising AudioGenerationError.
Ensured cleanup of temporary files even if an error occurs.
2025-03-09 22:26:07 +01:00
Alexander Myasoedov 56984c7078 fix(mcp server): 2025-03-09 21:23:02 +02:00
Alexander Myasoedov e2cb909329 refactor(data module): 2025-03-09 17:10:14 +02:00
Alexander Myasoedov d646ecd61b feat(add logutils): 2025-03-08 12:35:16 +02:00
Alexander Myasoedov 801a330e27 feat(add fe is_active logic): 2025-03-02 22:55:21 +02:00