mirror of
https://github.com/KeygraphHQ/shannon.git
synced 2026-10-09 09:41:07 +02:00
feat(preflight): add exploit-readiness probe and --validate-auth mode, and refresh suggested models (#476)
* feat(preflight): gate scans on an exploit-workload readiness probe
* feat: add --validate-auth to run authentication validation only
* feat: refuse reusing an auth-validation workspace for a scan
* chore: refresh suggested model IDs (Grok 4.7, OpenAI gpt-6-sol, Claude 5)
* fix(preflight): make the exploit-readiness probe trip the cyber safeguard reliably
* chore(preflight): update the exploit-readiness probe prompt
* feat: add --validate-model to run the preflight model checks only
* feat(cli): name cyber-access and app-login steps in the start loader
* feat(cli): refine start loader — skip app-login step when following, annotate preflight label
* feat(status): show Preflight and Cyber access verification rows for gated providers
* chore(preflight): suggest a fallback model in cyber-access remediation hints
* chore(preflight): drop env-var syntax from cyber-access fallback hints
* fix(preflight): separate finding heading from Target line in readiness probe
* refactor(preflight): rename exploit-readiness probe to cyber access verification
* fix(preflight): re-join finding heading with Target line in readiness probe
Reverts the heading/Target split from 22d84f2, gluing each finding's
heading back onto its Target line in the cyber-access probe's user
content.
* feat(validation): show a Checks summary in the validation log
* fix(cli): say a validation run failed, not that it could not start
* docs(ai-providers): replace broken Pi subscription link with /login steps
* feat(preflight): gate the openai-codex subscription on cyber access
This commit is contained in:
1 parent
a14c7944d8
commit
0ab7c0b41b
26 files changed
+759
-73
No files matched your search
@@ -75,6 +75,7 @@ import {
|
||||
runAuthVulnAgent,
|
||||
runAuthzExploitAgent,
|
||||
runAuthzVulnAgent,
|
||||
runCyberAccessVerification,
|
||||
runInjectionExploitAgent,
|
||||
runInjectionVulnAgent,
|
||||
runMiscellaneousExploitAgent,
|
||||
@@ -147,6 +148,7 @@ export const PENTEST_ACTIVITY_NAMES = Object.freeze([
|
||||
'runMiscellaneousExploitAgent',
|
||||
'runReportAgent',
|
||||
'runPreflightValidation',
|
||||
'runCyberAccessVerification',
|
||||
'runAuthenticationValidation',
|
||||
'initDeliverableGit',
|
||||
'syncPlaywrightStealthConfig',
|
||||
@@ -187,6 +189,7 @@ export const pentestActivities = Object.freeze({
|
||||
runMiscellaneousExploitAgent,
|
||||
runReportAgent,
|
||||
runPreflightValidation,
|
||||
runCyberAccessVerification,
|
||||
runAuthenticationValidation,
|
||||
initDeliverableGit,
|
||||
syncPlaywrightStealthConfig,
|
||||
@@ -247,6 +250,8 @@ interface CliArgs {
|
||||
configPath?: string;
|
||||
customerOutputPath?: string;
|
||||
pipelineTestingMode: boolean;
|
||||
authOnly: boolean;
|
||||
validateModel: boolean;
|
||||
resumeFromWorkspace?: string;
|
||||
}
|
||||
|
||||
@@ -261,7 +266,9 @@ function showUsage(): void {
|
||||
console.log(' --config <path> Configuration file path');
|
||||
console.log(' --workspace <name> Resume from existing workspace');
|
||||
console.log(' --output <path> Stable mounted path for final customer report copies');
|
||||
console.log(' --pipeline-testing Use minimal prompts for fast testing\n');
|
||||
console.log(' --pipeline-testing Use minimal prompts for fast testing');
|
||||
console.log(' --validate-auth Validate authentication only, then stop');
|
||||
console.log(' --validate-model Validate the AI model only, then stop\n');
|
||||
}
|
||||
|
||||
function parseCliArgs(argv: string[]): CliArgs {
|
||||
@@ -277,6 +284,8 @@ function parseCliArgs(argv: string[]): CliArgs {
|
||||
let configPath: string | undefined;
|
||||
let customerOutputPath: string | undefined;
|
||||
let pipelineTestingMode = false;
|
||||
let authOnly = false;
|
||||
let validateModel = false;
|
||||
let resumeFromWorkspace: string | undefined;
|
||||
|
||||
for (let i = 0; i < argv.length; i++) {
|
||||
@@ -313,6 +322,10 @@ function parseCliArgs(argv: string[]): CliArgs {
|
||||
}
|
||||
} else if (arg === '--pipeline-testing') {
|
||||
pipelineTestingMode = true;
|
||||
} else if (arg === '--validate-auth') {
|
||||
authOnly = true;
|
||||
} else if (arg === '--validate-model') {
|
||||
validateModel = true;
|
||||
} else if (arg && !arg.startsWith('-')) {
|
||||
if (!webUrl) {
|
||||
webUrl = arg;
|
||||
@@ -340,6 +353,8 @@ function parseCliArgs(argv: string[]): CliArgs {
|
||||
taskQueue,
|
||||
...(workflowId && { workflowId }),
|
||||
pipelineTestingMode,
|
||||
authOnly,
|
||||
validateModel,
|
||||
...(configPath && { configPath }),
|
||||
...(customerOutputPath && { customerOutputPath }),
|
||||
...(resumeFromWorkspace && { resumeFromWorkspace }),
|
||||
@@ -588,6 +603,8 @@ function buildPipelineInput(
|
||||
...(args.customerOutputPath !== undefined && { customerOutputPath: args.customerOutputPath }),
|
||||
...(orchestration.agenticSast !== undefined && { agenticSast: orchestration.agenticSast }),
|
||||
...(orchestration.exploit !== undefined && { exploit: orchestration.exploit }),
|
||||
...(args.authOnly && { authOnly: true }),
|
||||
...(args.validateModel && { validateModel: true }),
|
||||
};
|
||||
}
|
||||
|
||||
@@ -642,6 +659,10 @@ async function waitForWorkflowResult(
|
||||
}
|
||||
} else if (result.status === 'cancelled') {
|
||||
console.log('\nScan cancelled before it finished.');
|
||||
} else if (result.authOnly) {
|
||||
console.log('\nAuthentication validated. No pentest was run (--validate-auth).');
|
||||
} else if (result.validateModel) {
|
||||
console.log('\nModel validated. No pentest was run (--validate-model).');
|
||||
} else {
|
||||
console.log('\nScan completed.');
|
||||
}
|
||||
@@ -754,6 +775,11 @@ async function run(): Promise<void> {
|
||||
// 1. Parse CLI args
|
||||
const args = parseCliArgs(process.argv.slice(2));
|
||||
|
||||
// One scan per worker process, so an auth-only or model-validation run is a process-wide fact.
|
||||
// The log writers read these to frame the log as a validation rather than a pentest.
|
||||
if (args.authOnly) process.env.SHANNON_AUTH_ONLY = '1';
|
||||
if (args.validateModel) process.env.SHANNON_VALIDATE_MODEL = '1';
|
||||
|
||||
// 2. Connect to Temporal server
|
||||
const address = process.env.TEMPORAL_ADDRESS || 'localhost:7233';
|
||||
console.log(`Connecting to Temporal at ${address}...`);
|
||||
|
||||
Reference in new issue
Block a user