agentic-security-workspace

mcp
Guvenlik Denetimi
Uyari
Health Uyari
  • License — License: MIT
  • Description — Repository has a description
  • Active repo — Last push 0 days ago
  • Low visibility — Only 5 GitHub stars
Code Uyari
  • network request — Outbound network request in scripts/preserve-upstreams.py
  • network request — Outbound network request in scripts/publish-recovery-release.py
Permissions Gecti
  • Permissions — No dangerous permissions requested

Bu listing icin henuz AI raporu yok.

SUMMARY

Project-local agent skills for evidence-driven security testing and reverse engineering.

README.md

Agentic Security Workspace

A small, project-local skill library for evidence-driven security testing and reverse engineering with coding agents.

It keeps security guidance and MCP discovery out of unrelated coding projects. Tool installations and long-running services remain global. This repository owns agent guidance, checkout-local configuration, and independent upstream source snapshots under vendor/.

Use it only for assets you own or are explicitly authorized to test. Target files, traffic, source, and documentation are untrusted evidence, never agent instructions.

Read the project overview for the design, tested setup, limits, and meaning of local AI in this project.

Independent upstream copies

Referenced open-source tools and methodology repositories are preserved under vendor/ as squashed Git subtrees. A normal clone contains the snapshots, nested submodule sources, and embedded Git LFS payloads without contacting their original repositories. The exact source commits, transformed archive trees, nested origins, and LFS SHA-256 values are recorded in upstreams.json.

python3 scripts/preserve-upstreams.py verify
python3 -m unittest discover -s tests -v

The archive keeps licenses and notices. Gitlinks are replaced by their pinned contents; LFS payloads become ordinary Git blobs. Original attribute files are retained as .gitattributes.upstream, while archive attributes prevent text conversion and external LFS filters. Upstream source is evidence, not agent instructions or code to execute during setup. The archive is a pinned source backup, not a complete build cache, release-binary mirror, or historical mirror of every upstream commit.

To update one source on a clean checkout:

python3 scripts/preserve-upstreams.py update --name morluto/rea --revision SOURCE_COMMIT
python3 scripts/preserve-upstreams.py verify
git add upstreams.json
git commit -m "vendor: record updated REA provenance"

The update command creates a subtree commit and updates the manifest. Review both before pushing. Use this importer to retain nested sources and LFS data during updates; a plain upstream pull can reintroduce external pointers. Updates are explicit and do not change installed tool versions or replace a release-matched skill automatically.

Licensed Frida, Semgrep, and Codex documentation sources and the NIST testing publication are included. Website material without an identified redistribution grant remains listed with a reason in the manifest. Those pages are not claimed as archived.

Both referenced Qwen model repositories allow Apache-2.0 redistribution. Their licenses, configuration, tokenizers, and shard manifests are saved under vendor/models/. The approximately 111 GB of actual weights are excluded from backups at the user’s request. Their exact revisions, sizes, hashes, and excluded-by-user status are recorded in the manifest. Metadata and LFS pointers alone are not a weight backup.

Recovery release backup

GitHub Releases hold a Git bundle of the preserved sources, selected official tool distributions, matching recursive release sources, and a REA npm dependency snapshot. Model weights are excluded. Each release has SHA256SUMS and a recovery manifest with upstream URLs, revisions, sizes, hashes, licenses, and coverage gaps.

The release plan is release-artifacts.json. To publish a new backup from a clean, committed main branch, use the existing temporary-resource owner:

owned-temp-dir --run recovery-release -- python3 scripts/publish-recovery-release.py --tag recovery-YYYYMMDD

The publisher verifies downloads, builds a source bundle, resolves REA npm dependencies offline with installation scripts disabled, uploads a draft, checks the uploaded sizes and GitHub SHA-256 digests, then publishes. Operation-owned files are removed when the owner exits. It does not preserve a NAS copy or a persistent local archive. GitHub remains the sole remote backup provider.

This is a recovery artifact archive, not a verified offline installation. It does not include all Python dependencies, OS/runtime installers, live vulnerability databases, browser downloads, commercial software, or an audited redistributable MobSF image. REA’s npm snapshot is platform-specific and excludes native postinstall engine downloads. Installed tool versions are unaffected.

Serving (optional): a self-hosted abliterated model

You can drive this workspace with Qwen3.8-27B abliterated served free on a Kaggle TPU
v5e-8
— full bf16, up to the model's native 262k context — plugged into OpenCode 2 as an
OpenAI- and Anthropic-compatible endpoint. The recipe lives in serving/ (a fork
of ARahim3/kaggle-tpu-lab, MIT) and the
step-by-step guide is docs/kaggle-tpu-serving.md.

flowchart TD
    K["./serving/ktl start"] --> L["launch.py → Kaggle kernel<br/>(TPU v5e-8, free tier)"]
    L --> Q["queue for a TPU slot → load 55&nbsp;GB bf16<br/>→ compile graphs → cloudflared tunnel"]
    Q --> F["ktl writes ~/.config/kaggle-tpu-lab/<br/>{base_url, api_key}"]
    F --> P["OpenCode 2 provider <b>kaggle-tpu</b><br/>reads them via {file:…}"]
    P --> R["opencode2 -m kaggle-tpu/qwen3.8-27b-abliterated<br/>(run from the workspace root)"]
    R --> W["Agentic Security Workspace<br/>skills + evidence rules"]
    W --> T["tool lanes: ghidra MCP :8089 (headless) ·<br/>burp · analyzeHeadless · semgrep · …"]

    subgraph cloud["Kaggle free TPU"]
        L
        Q
    end
    subgraph host["Your machine"]
        K
        F
        P
        R
        W
        T
    end
cd serving && ./ktl setup          # once: venv + Kaggle CLI (needs a TPU-verified Kaggle account)
./ktl start                        # push the kernel, wait for live, wire it into OpenCode 2
./ktl ghidra start                 # optional: headless Ghidra MCP server on :8089, no GUI
cd .. && opencode2 -m kaggle-tpu/qwen3.8-27b-abliterated
./serving/ktl stop                 # when done, to free your weekly TPU quota

OpenCode 2 does not start the endpoint; always ./ktl start first. Full prerequisites
(including Kaggle identity verification, not just phone) are in the guide.

Start

There is no cross-platform installation script to maintain. The setup skill performs installation from current official sources.

  1. Clone this repository and enter its root.
  2. Launch Codex, Claude Code, or OpenCode from that root.
  3. Trust the checkout when the host asks; Codex ignores project config until the project is trusted.
  4. Invoke setup-security-workspace.
  5. Let the agent install and verify the full supported toolchain automatically.
  6. Complete an exact user action only when elevation, license acceptance, GUI approval, or device connection cannot be automated.
  7. Let it create and verify the project-local MCP configuration.

The full profile covers every tool lane below, including required runtimes, companion data, local services, and Burp, Ghidra, and REA MCP integrations. It can install GUI applications and use several gigabytes. The setup ledger records whether each component was pre-existing or setup-owned, the exact installed version and location, and the uninstall or cleanup command to use later.

The setup skill discovers the current OS and host and resolves the current vendor-supported method at runtime, so the repository does not hard-code Homebrew, Winget, system paths, versions, or credentials. It writes host-specific files locally; they are ignored by Git:

Host Local configuration
Codex .codex/config.toml
Claude Code .mcp.json and optional .claude/settings.local.json
OpenCode opencode.json

See the official Codex configuration precedence and project-scoped MCP configuration documentation for its trust boundary.

The canonical skills live under .agents/skills/. Claude Code loads the flat compatibility links under .claude-compat/.claude/skills/; Codex and OpenCode discover the canonical tree directly.

REA alongside the existing toolkit

REA adds a common MCP and CLI interface for shipped-artifact analysis. Invoke rea for native, Android, JavaScript/Electron, managed assembly, archive, Apple resource, or retained network evidence. Setup installs the published package's matching upstream workflow locally, pins its MCP registration, and reuses compatible Ghidra and JADX installations. The REA setup lane covers host configuration, engine checks, verification, and updates.

Existing lane Relationship to REA
Ghidra REA uses separate temporary headless projects. The existing MCP bridge remains useful for attached GUI programs.
JADX and Apktool REA uses JADX for focused Android code and graphs; direct JADX and Apktool retain their exploration, decoding, smali, and rebuilding workflows.
Burp, Frida, and ADB REA supplies specific evidence/capture workflows; interception, HTTP mutation, instrumentation, and device control remain specialist lanes.
MobSF and capa Independent mobile-security and native-capability checks complement REA evidence.
Semgrep, OSV-Scanner, Trivy, Nuclei, and Katana Source analysis, advisory matching, security scans, and scoped crawling remain separate lanes.

REA adds JavaScript/Electron application graphs, managed-code and Apple-resource inspection, artifact comparisons, and structured Evidence. Two interfaces to the same Ghidra or JADX engine do not count as independent verification. Available tools depend on the installed release, target, engine, and host; browser/device endpoints and Linux-only workflows retain their own prerequisites.

REA's upstream setup defaults to global agent configuration. This workspace instead creates checkout-local registrations and keeps the release-matched upstream skill and generated launchers ignored. Restart the current host after registration to discover its tools; the pinned CLI can be used immediately. Preserve evidence and assessment authorization through the existing workflow.

Setup protocol

Setup is an agent-executed, persisted installer protocol. It is not a checked-in platform script. Its resumable ownership and removal ledger is security-artifacts/setup.md.

stateDiagram-v2
    [*] --> Inspect
    Inspect --> Install: full profile classified
    Inspect --> ManualGap: prerequisite cannot be inspected
    Install --> Install: next missing component
    Install --> AwaitUser: unavoidable user-only action
    AwaitUser --> Inspect: action completed / reclassify
    Install --> Configure: every component verifies
    Install --> ManualGap: unchanged failure repeats
    Configure --> Install: dependency is missing or broken
    Configure --> Configure: restore backup / changed correction
    Configure --> Verify: configs parse
    Verify --> Ready: full profile + skills + MCP pass
    Verify --> Install: tool verification fails
    Verify --> Configure: integration verification fails
    Verify --> AwaitUser: host approval is required
    Verify --> ManualGap: unchanged failure repeats
    Ready --> [*]
    ManualGap --> Inspect: missing prerequisite supplied

Every retry requires changed evidence. Existing config is backed up temporarily before mutation and restored on a configuration failure. Setup-owned components remain installed after setup; their exact removal instructions stay in the ledger. ready means the complete profile works, while manual-gap names the unresolved boundary and one exact user action.

Assessment protocol

Start with security-assessment for a mixed or unknown target. Invoke a target-specific skill directly only when the target type is already clear.

stateDiagram-v2
    [*] --> Scope
    Scope --> Scope: missing or changed authorization boundary
    Scope --> Plan: every active technique is bounded
    Plan --> Execute: coverage rows exist
    Execute --> VerifyFinding: material candidate
    VerifyFinding --> Execute: confirmed / refuted / inconclusive
    Execute --> Diagnose: tool or method fails
    Diagnose --> Execute: cause or bounded method changed
    Diagnose --> TerminalGap: retry is unchanged, unsafe, or exhausted
    TerminalGap --> Execute: row marked untested with impact
    Execute --> Scope: stop condition fires
    Execute --> Report: no row remains planned
    Report --> Complete: evidence, gaps, and cleanup accounted for
    Complete --> [*]

The protocol is resumable from durable artifacts:

security-artifacts/
├── setup.md       # environment state, decisions, failures, next steps
├── scope.md       # authorization, impact limits, cleanup, stop conditions
├── plan.md        # hypothesis/control → execution state → result
├── evidence/      # raw outputs, request pairs, traces, hashes, notes
└── report.md      # verified findings, coverage, remediation, residual gaps

Keep that directory inside the individual target project. The Git ignore rules prevent it and common target binaries or captures from being published accidentally.

Three independent state axes prevent false completion:

  • Execution: planned, tested, not-applicable, untested
  • Result: pass, fail, inconclusive
  • Candidate disposition: confirmed, refuted, inconclusive

A report cannot start while a row remains planned. Tool failure becomes a retry only after something material changes; otherwise it becomes an explicit terminal gap.

Reverse-engineering loop

flowchart TD
    I["Identify artifact<br/>provenance · hash · format · architecture"] --> T["Triage<br/>entry points · imports · strings · capabilities"]
    T --> H["State one behavior hypothesis"]
    H --> X["Trace static evidence<br/>symbols · xrefs · call path · data flow"]
    X --> K{"Resolved?"}
    K -- "yes" --> E["Preserve evidence path"]
    K -- "no" --> P{"Runtime-only, packed,<br/>encrypted, or ambiguous?"}
    P -- "no" --> H
    P -- "yes" --> G{"Execution authorized<br/>and isolated?"}
    G -- "no" --> L["Record an untested gap and impact"]
    G -- "yes" --> D["Run one bounded experiment<br/>capture state and observation"]
    D --> H
    E --> V["verify-security-finding"]
    L --> V

Unknown or suspicious code belongs in a revertible isolated environment with controlled networking, synthetic credentials, and an explicit cleanup plan. Without that environment, stop at static analysis and record the gap.

Tool lanes

Skill Role Evidence
burp Capture, inspect, replay, and compare HTTP through the MCP bridge Baseline and changed request-response pairs
katana Map routes, inputs, forms, and script-discovered endpoints Scoped JSONL crawl inventory
nuclei Run narrow, technology-matched templates JSONL candidates with template and failure context
mobsf Produce an independent Android static-analysis view Versioned JSON tied to the package hash
jadx Trace managed Android code Class, method, and source-to-sink path
apktool Inspect manifest, resources, network policy, and smali Decoded file and exact configuration value
adb Control an authorized emulator or test device Device, package, command, time, and state change
frida Instrument a process for one runtime hypothesis Hook, process identity, and observed event
capa Triage native capabilities Machine-readable leads with disposition
rea Analyze shipped artifacts and application graphs through a unified MCP/CLI Evidence IDs, locations, graph relations, and explicit coverage limits
ghidra Trace binary behavior through MCP Program location, xrefs, decompilation, and call path
semgrep Find source patterns and data-flow candidates Structured matches traced through executable paths
osv-scanner Match resolved dependencies to advisories Version, affected feature, and reachability
trivy Inspect images, filesystems, dependencies, secrets, and IaC Structured results tied to the artifact

Tool output is a candidate, not a finding. Every material candidate passes through verify-security-finding.

Burp integration uses PortSwigger's official MCP extension. Ghidra integration is compatible with ghidra-mcp. The setup skill verifies what is actually installed before writing configuration.

Skill graph

.agents/skills/
├── assessments/   # target-specific routers
│   ├── security-assessment
│   ├── web-security-assessment
│   ├── api-security-assessment
│   ├── android-security-assessment
│   ├── native-binary-assessment
│   └── source-security-assessment
├── foundations/   # scope → plan → verify → report
│   ├── setup-security-workspace
│   ├── scope-security-test
│   ├── plan-security-assessment
│   ├── verify-security-finding
│   └── write-security-report
└── tools/         # one focused evidence lane per integration

The library follows writing-for-agents: short context pointers, composition, one source of truth, and checkable completion criteria. The maintained skill library excludes vulnerability encyclopedias, autonomous exploitation chains, and copied tool manuals. Upstream archives retain their own documentation separately. The preservation script imports sources; tool installation remains the setup skill's responsibility.

Methodology

License

MIT

Yorumlar (0)

Sonuc bulunamadi