Documentation
¶
Overview ¶
corpus.go — the embedded operator-decisions corpus.
//go:embed cannot traverse "..", so the embed directive must live in a .go file at a directory level whose subtree contains the corpus. The corpus is at <root>/agents/rules/operator-decisions.yaml, so ONLY the repo root qualifies. This is the sole production package at the root (hello_test.go is the external `mallcop_test` package, which Go permits to coexist with `mallcop` in the same directory).
The bytes are exposed so the production runtime loaders (core/agent's escalate-route floor and core/tools' operator-rules loader) can FALL BACK to a baked-in corpus when no on-disk corpus can be located — e.g. a standalone `/tmp/mallcop` binary with MALLCOP_REPO_ROOT unset and no project marker above it. This is a strict FALLBACK: an on-disk corpus (binary-walk hit or MALLCOP_REPO_ROOT) always wins, so dev edit-and-reload of the corpus is preserved. See the loaders' corpusBytes helpers.
This package imports ONLY "embed" — it carries no dependency that could let the floor path reach inference, so importing it from core/agent and core/tools does not violate either import-lint.
corpusembed.go — the embedded eval scenario corpus.
//go:embed cannot traverse "..", so — exactly like corpus.go (operator-decisions) — this embed directive must live in a .go file at the repo root: the only directory whose subtree contains exams/scenarios AND is package mallcop (the sole production package at the root; hello_test.go is the external mallcop_test package, which Go permits to coexist here).
ScenariosFS carries the exact on-disk exams/scenarios subtree at build time, EXCLUDING files/dirs whose name begins with "." or "_" — go:embed's default directory-embed behavior, which is the SAME leading-underscore skip core/eval's disk walker applies by hand (scanCorpus / hasUnderscoreComponent in core/eval/corpus.go). That means exams/scenarios/_schema.yaml and the exams/scenarios/_test/ subtree are excluded from BOTH the disk scan and this embed — so the pinned corpus (count 58 + manifest sha in exams/scenarios/corpus.pin, itself embedded since it does not start with "_") verifies IDENTICALLY against either source. See core/eval/corpus.go's LoadEmbedded and the embed==disk parity test (core/tools/embed_corpus_test.go pattern, mirrored for this corpus).
This lets a SHIPPED mallcop binary run `mallcop eval` / exam-detect from the compiled-in reference corpus even in a customer deploy repo that carries no exams/scenarios directory on disk — core/eval.RepoRoot() finds a repo marker (go.mod or .git) belonging to the CUSTOMER repo, which has no corpus; the on-disk Load then fails to find exams/scenarios and the caller falls back to this embed. An on-disk corpus, when present, always wins over the embed (dev edit-and-reload is preserved) — see core/eval/corpus.go's disk-first precedence, the same pattern core/tools' operator-decisions loader uses.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var OperatorDecisionsYAML []byte
OperatorDecisionsYAML is the byte-for-byte contents of agents/rules/operator-decisions.yaml at build time. Because //go:embed copies the exact file, these bytes are identical to the on-disk corpus the SHA pin (core/tools.expectedOperatorRulesSHA256) describes — by construction, with no separate copy that could drift. The embed==disk test makes that invariant explicit and catches a stale checked-in pin.
var ScenariosFS embed.FS
ScenariosFS is the exams/scenarios subtree embedded at build time, rooted at the repo root — so paths inside read "exams/scenarios/...", matching the relative paths core/eval's disk walker produces from a repoRoot-based os.DirFS(repoRoot). Underscore- and dot-prefixed files/dirs are excluded by go:embed's directory-embed default (verified equivalent to hasUnderscoreComponent's any-depth skip).
Functions ¶
This section is empty.
Types ¶
This section is empty.
Directories
¶
| Path | Synopsis |
|---|---|
|
Deploy-repo scaffold + creation (mallcoppro-f3b): `mallcop init --create-repo owner/name` turns the plain local scaffold runInit already writes (mallcop.yaml, store/, events.jsonl) into a customer DEPLOYMENT repo pushed to a real GitHub repository, so the customer never compiles mallcop locally — a scheduled GitHub Action does.
|
Deploy-repo scaffold + creation (mallcoppro-f3b): `mallcop init --create-repo owner/name` turns the plain local scaffold runInit already writes (mallcop.yaml, store/, events.jsonl) into a customer DEPLOYMENT repo pushed to a real GitHub repository, so the customer never compiles mallcop locally — a scheduled GitHub Action does. |
|
cmd
|
|
|
baseline
command
Command baseline builds and queries mallcop baseline frequency tables.
|
Command baseline builds and queries mallcop baseline frequency tables. |
|
detector-config-drift
command
detector-config-drift reads events JSONL from stdin and emits findings JSONL to stdout for configuration change events: security group modifications, IAM policy changes, MFA disabling, and audit log modifications.
|
detector-config-drift reads events JSONL from stdin and emits findings JSONL to stdout for configuration change events: security group modifications, IAM policy changes, MFA disabling, and audit log modifications. |
|
detector-dependency-tamper
command
detector-dependency-tamper reads events JSONL from stdin and emits findings JSONL to stdout for dependency supply chain tampering: package version changes, unexpected additions, hash mismatches, and typosquatting indicators.
|
detector-dependency-tamper reads events JSONL from stdin and emits findings JSONL to stdout for dependency supply chain tampering: package version changes, unexpected additions, hash mismatches, and typosquatting indicators. |
|
detector-exfil-pattern
command
detector-exfil-pattern reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate data exfiltration: unusual outbound data volumes, bulk access to many resources in a short window, or download events that exceed baseline frequency thresholds.
|
detector-exfil-pattern reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate data exfiltration: unusual outbound data volumes, bulk access to many resources in a short window, or download events that exceed baseline frequency thresholds. |
|
detector-git-oops
command
detector-git-oops reads events JSONL from stdin and emits findings JSONL to stdout for dangerous git operations: force pushes, branch deletions, and commit messages containing secret-looking strings.
|
detector-git-oops reads events JSONL from stdin and emits findings JSONL to stdout for dangerous git operations: force pushes, branch deletions, and commit messages containing secret-looking strings. |
|
detector-injection-probe
command
detector-injection-probe reads events JSONL from stdin and emits findings JSONL to stdout for events that contain prompt injection attempts in their payload fields.
|
detector-injection-probe reads events JSONL from stdin and emits findings JSONL to stdout for events that contain prompt injection attempts in their payload fields. |
|
detector-malicious-skill
command
detector-malicious-skill reads events JSONL from stdin and emits findings JSONL to stdout for skill-related events that contain suspicious URLs, encoded payloads, or excessive permission requests.
|
detector-malicious-skill reads events JSONL from stdin and emits findings JSONL to stdout for skill-related events that contain suspicious URLs, encoded payloads, or excessive permission requests. |
|
detector-new-actor
command
detector-new-actor reads events JSONL from stdin, compares each actor against the baseline known-actors set, and emits findings JSONL to stdout for actors not seen in the baseline period.
|
detector-new-actor reads events JSONL from stdin, compares each actor against the baseline known-actors set, and emits findings JSONL to stdout for actors not seen in the baseline period. |
|
detector-priv-escalation
command
detector-priv-escalation reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate a privilege escalation — role grants, permission changes, or admin promotions — not already in the baseline.
|
detector-priv-escalation reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate a privilege escalation — role grants, permission changes, or admin promotions — not already in the baseline. |
|
detector-rate-anomaly
command
detector-rate-anomaly reads events JSONL from stdin and emits findings JSONL to stdout for events that show API rate anomalies: burst requests, orders-of-magnitude jumps above baseline, or unusual endpoint access patterns.
|
detector-rate-anomaly reads events JSONL from stdin and emits findings JSONL to stdout for events that show API rate anomalies: burst requests, orders-of-magnitude jumps above baseline, or unusual endpoint access patterns. |
|
detector-secrets-exposure
command
detector-secrets-exposure reads events JSONL from stdin and emits findings JSONL to stdout when event payload fields contain secrets in cleartext: API keys, tokens, passwords, and credentials matching known formats.
|
detector-secrets-exposure reads events JSONL from stdin and emits findings JSONL to stdout when event payload fields contain secrets in cleartext: API keys, tokens, passwords, and credentials matching known formats. |
|
detector-unusual-login
command
detector-unusual-login reads events JSONL from stdin, compares each login event against a baseline of known user patterns, and emits findings JSONL to stdout for logins that deviate from baseline.
|
detector-unusual-login reads events JSONL from stdin, compares each login event against a baseline of known user patterns, and emits findings JSONL to stdout for logins that deviate from baseline. |
|
detector-unusual-timing
command
detector-unusual-timing reads events JSONL from stdin and emits ONE finding JSONL line per distinct (actor, UTC hour) group whose hour is not seen for that actor in the baseline period (mallcoppro-d73 — collapsed from one finding per matching event, which used to fan out N findings for N events sharing a single novel actor-hour).
|
detector-unusual-timing reads events JSONL from stdin and emits ONE finding JSONL line per distinct (actor, UTC hour) group whose hour is not seen for that actor in the baseline period (mallcoppro-d73 — collapsed from one finding per matching event, which used to fan out N findings for N events sharing a single novel actor-hour). |
|
detector-volume-anomaly
command
detector-volume-anomaly reads events JSONL from stdin, counts events per (source, event_type) group, and emits findings JSONL to stdout when the observed count exceeds 3× the baseline count for that group.
|
detector-volume-anomaly reads events JSONL from stdin, counts events per (source, event_type) group, and emits findings JSONL to stdout when the observed count exceeds 3× the baseline count for that group. |
|
exam-transcript-dump
command
cmd/exam-transcript-dump renders a judge-visible Markdown transcript from exam fixture data and a heal disposition's resolution JSON.
|
cmd/exam-transcript-dump renders a judge-visible Markdown transcript from exam fixture data and a heal disposition's resolution JSON. |
|
mallcop
command
Command mallcop is the customer-facing CLI for running mallcop scans.
|
Command mallcop is the customer-facing CLI for running mallcop scans. |
|
mallcop-coverage-tripwire
command
|
|
|
mallcop-credential-theft-verify
command
Command mallcop-credential-theft-verify is a veracity-gate hook binary that enforces the Credential Theft Test rule from the investigate disposition.
|
Command mallcop-credential-theft-verify is a veracity-gate hook binary that enforces the Credential Theft Test rule from the investigate disposition. |
|
mallcop-eval
command
Command mallcop-eval runs the portable eval harness over the SHA-pinned scenario corpus and prints the report as JSON.
|
Command mallcop-eval runs the portable eval harness over the SHA-pinned scenario corpus and prints the report as JSON. |
|
mallcop-exam-report
command
Command mallcop-exam-report aggregates judge:verdict messages from a campfire into a structured exam report (report.json + report.md).
|
Command mallcop-exam-report aggregates judge:verdict messages from a campfire into a structured exam report (report.json + report.md). |
|
mallcop-finding-context
command
|
|
|
notify-discord
command
Command notify-discord is the Discord outbound notification adapter.
|
Command notify-discord is the Discord outbound notification adapter. |
|
notify-email
command
|
|
|
notify-slack
command
|
|
|
notify-teams
command
|
|
|
notify-telegram
command
|
|
|
connect
|
|
|
exec
Package exec is the process-boundary cloud Connector: it runs a sibling connector binary (from the separate mallcop-connectors module) as a child process, reads the normalized event JSONL the sibling writes to stdout, and captures the incremental cursor the sibling writes to stderr — so that `mallcop scan` auto-pulls a cloud source in one pass instead of the manual `mallcop-connector-aws > events.jsonl` two-step.
|
Package exec is the process-boundary cloud Connector: it runs a sibling connector binary (from the separate mallcop-connectors module) as a child process, reads the normalized event JSONL the sibling writes to stdout, and captures the incremental cursor the sibling writes to stderr — so that `mallcop scan` auto-pulls a cloud source in one pass instead of the manual `mallcop-connector-aws > events.jsonl` two-step. |
|
github
Package github is the portable GitHub Connector: it pulls org activity from the GitHub API and normalizes it to []event.Event so the detector floor (core/detect) and the rest of the scan pipeline run unchanged.
|
Package github is the portable GitHub Connector: it pulls org activity from the GitHub API and normalizes it to []event.Event so the detector floor (core/detect) and the rest of the scan pipeline run unchanged. |
|
overlay
Package overlay is the shared LEARNED-MAPPING overlay: a widen-only data layer that maps a connector's raw action string to a known event_type, consulted ONLY when the connector's own classification fell through to its default bucket ("<sourceID>_other").
|
Package overlay is the shared LEARNED-MAPPING overlay: a widen-only data layer that maps a connector's raw action string to a known event_type, consulted ONLY when the connector's own classification fell through to its default bucket ("<sourceID>_other"). |
|
core
|
|
|
agent
Package agent holds the SECURITY-CRITICAL pre-LLM floor for finding resolution plus the minimal anthropic.Client interface the agent loop (built in a later wave) consumes.
|
Package agent holds the SECURITY-CRITICAL pre-LLM floor for finding resolution plus the minimal anthropic.Client interface the agent loop (built in a later wave) consumes. |
|
cases
Package cases COLLAPSES recurring escalated findings — the SAME (finding type, actor, primary entity) recurring across scans — into one durable Case object per cluster, projected to store/cases.json (mallcoppro-554).
|
Package cases COLLAPSES recurring escalated findings — the SAME (finding type, actor, primary entity) recurring across scans — into one durable Case object per cluster, projected to store/cases.json (mallcoppro-554). |
|
collect
Package collect is the OFFLINE, DETERMINISTIC feedstock-collector half of the self-extension loop.
|
Package collect is the OFFLINE, DETERMINISTIC feedstock-collector half of the self-extension loop. |
|
config
Package config is the loader for mallcop.yaml — the one file mallcop reads.
|
Package config is the loader for mallcop.yaml — the one file mallcop reads. |
|
connect
Package connect is the INPUT seam of the scan pipeline: it turns a source of raw activity into the normalized []event.Event the detector floor consumes.
|
Package connect is the INPUT seam of the scan pipeline: it turns a source of raw activity into the normalized []event.Event the detector floor consumes. |
|
detect
Package detect provides offline, deterministic security detection over a corpus of normalized events.
|
Package detect provides offline, deterministic security detection over a corpus of normalized events. |
|
detect/authored
Package authored is the human-bootstrapped REGISTRATION AGGREGATOR for agent-authored detectors (K7 L1).
|
Package authored is the human-bootstrapped REGISTRATION AGGREGATOR for agent-authored detectors (K7 L1). |
|
detect/authored/deployflood
Package deployflood is an agent-authored detector that fires on a genuine VOLUME anomaly in github.deployment events — a real flood of deployments by one actor, not the mere presence of a deployment.
|
Package deployflood is an agent-authored detector that fires on a genuine VOLUME anomaly in github.deployment events — a real flood of deployments by one actor, not the mere presence of a deployment. |
|
detect/authored/synthmarker
Package synthmarker is the REFERENCE agent-authored detector.
|
Package synthmarker is the REFERENCE agent-authored detector. |
|
eval
artifacts.go — write the harness's per-scenario result JSON, per-scenario TRANSCRIPTS, and the classifier summary to disk (§4.4 result JSON, §4.7 transcript audit).
|
artifacts.go — write the harness's per-scenario result JSON, per-scenario TRANSCRIPTS, and the classifier summary to disk (§4.4 result JSON, §4.7 transcript audit). |
|
inference
Package inference holds the network seam that satisfies core/agent.Client.
|
Package inference holds the network seam that satisfies core/agent.Client. |
|
inquest
assemble.go — deterministic evidence assembly.
|
assemble.go — deterministic evidence assembly. |
|
investigate
evaltools.go — the "run-eval" and "flag-like-this" chat tools (mallcoppro- a2f / C9): the recall-first eval and its corpus-growth twin, reachable conversationally.
|
evaltools.go — the "run-eval" and "flag-like-this" chat tools (mallcoppro- a2f / C9): the recall-first eval and its corpus-growth twin, reachable conversationally. |
|
lint
Package lint hosts the repo-level import-lint guard for the core/ tree.
|
Package lint hosts the repo-level import-lint guard for the core/ tree. |
|
observe
Package observe holds the THREE pure observable force-escalate predicates the cascade's structural-confidence gate scores, plus every helper / threshold / map they read — extracted VERBATIM from core/eval/scenario_tools.go so that the eval scenarioToolRunner AND the production core/toolrun.Runner call ONE shared implementation and get BYTE-IDENTICAL booleans + details.
|
Package observe holds the THREE pure observable force-escalate predicates the cascade's structural-confidence gate scores, plus every helper / threshold / map they read — extracted VERBATIM from core/eval/scenario_tools.go so that the eval scenarioToolRunner AND the production core/toolrun.Runner call ONE shared implementation and get BYTE-IDENTICAL booleans + details. |
|
pipeline
Package pipeline is the ORCHESTRATOR that assembles the four core seams into one agentic scan cycle:
|
Package pipeline is the ORCHESTRATOR that assembles the four core seams into one agentic scan cycle: |
|
store
Package store is the git-repo source of truth for mallcop's seven append-only streams: events, findings, resolutions, baseline, conversation, directives, and scans.
|
Package store is the git-repo source of truth for mallcop's seven append-only streams: events, findings, resolutions, baseline, conversation, directives, and scans. |
|
toolrun
Package toolrun is the PRODUCTION ToolRunner — the live agent.ToolRunner the scan pipeline wires into the cascade (CascadeOptions.Tools).
|
Package toolrun is the PRODUCTION ToolRunner — the live agent.ToolRunner the scan pipeline wires into the cascade (CascadeOptions.Tools). |
|
tools
casefold.go — case-insensitive structured-record parsing at the boundary (portable-agent-architecture.md §3.7).
|
casefold.go — case-insensitive structured-record parsing at the boundary (portable-agent-architecture.md §3.7). |
|
Package detecthost is the wazero-based HOST runtime for wasip1 WASM detector sidecars.
|
Package detecthost is the wazero-based HOST runtime for wasip1 WASM detector sidecars. |
|
examples
|
|
|
sidecar-detector
command
Command sidecar-detector is the example wasip1 sidecar main: it is compiled with GOOS=wasip1 GOARCH=wasm and run inside the wazero host (github.com/mallcop-app/mallcop/detecthost), never invoked as a native binary.
|
Command sidecar-detector is the example wasip1 sidecar main: it is compiled with GOOS=wasip1 GOARCH=wasm and run inside the wazero host (github.com/mallcop-app/mallcop/detecthost), never invoked as a native binary. |
|
sidecar-detector/exampledetector
Package exampledetector is the trivial rule used to PROVE the wasip1 sidecar delivery path end to end (mallcoppro-f70): the same detect.Detector implementation is run two ways — in-process (an ordinary Go call) and wrapped by detecthost as a real, compiled .wasm sidecar — and the two runs must produce byte-identical findings.
|
Package exampledetector is the trivial rule used to PROVE the wasip1 sidecar delivery path end to end (mallcoppro-f70): the same detect.Detector implementation is run two ways — in-process (an ordinary Go call) and wrapped by detecthost as a real, compiled .wasm sidecar — and the two runs must produce byte-identical findings. |
|
internal
|
|
|
exam
Package exam provides types and loader logic for mallcop exam scenarios.
|
Package exam provides types and loader logic for mallcop exam scenarios. |
|
testutil/cannedbackend
Package cannedbackend provides a minimal HTTP server that mimics Forge's /v1/chat/completions and /v1/messages endpoints for integration and e2e tests.
|
Package cannedbackend provides a minimal HTTP server that mimics Forge's /v1/chat/completions and /v1/messages endpoints for integration and e2e tests. |
|
pkg
|
|
|
detectorhost
Package detectorhost is the GUEST-side harness for a WASM detector sidecar.
|
Package detectorhost is the GUEST-side harness for a WASM detector sidecar. |
|
ghauth
Package ghauth mints GitHub App installation access tokens with a stdlib-only RS256 JWT.
|
Package ghauth mints GitHub App installation access tokens with a stdlib-only RS256 JWT. |
|
notify
Package notify holds the reusable outbound-notification send paths shared by the cmd/notify-* adapter binaries and the scan pipeline's gated emit step.
|
Package notify holds the reusable outbound-notification send paths shared by the cmd/notify-* adapter binaries and the scan pipeline's gated emit step. |
|
selfext
|
|
|
autonomy
Package autonomy is the engine-side DUPLICATE of mallcop's core/config.Learning.Autonomy enum, over the PROCESS BOUNDARY: this engine keeps a local copy rather than importing the collector (see engine/gate.go), so the operator-owned dial value crosses as a plain string (a CLI flag on the operator binary's selfext command, mirrored from mallcop.yaml's learning.autonomy) and this package is the single place that string is parsed and interpreted.
|
Package autonomy is the engine-side DUPLICATE of mallcop's core/config.Learning.Autonomy enum, over the PROCESS BOUNDARY: this engine keeps a local copy rather than importing the collector (see engine/gate.go), so the operator-owned dial value crosses as a plain string (a CLI flag on the operator binary's selfext command, mirrored from mallcop.yaml's learning.autonomy) and this package is the single place that string is parsed and interpreted. |
|
contribback
Package contribback opens the SECOND pull request in mallcop's self-extension loop.
|
Package contribback opens the SECOND pull request in mallcop's self-extension loop. |
|
engine
Package engine is the orchestration loop for mallcop's self-extension code-authoring engine.
|
Package engine is the orchestration loop for mallcop's self-extension code-authoring engine. |
|
gharuntime
Package gharuntime holds the embedded GitHub Actions templates that make up the mallcop self-extension CODE-lane runtime, plus the scaffolder that writes them into an operator's fork of mallcop-app/mallcop.
|
Package gharuntime holds the embedded GitHub Actions templates that make up the mallcop self-extension CODE-lane runtime, plus the scaffolder that writes them into an operator's fork of mallcop-app/mallcop. |
|
jail
Package jail applies OS-enforced, fail-closed confinement to the headless opencode code-authoring child of mallcop's self-extension loop.
|
Package jail applies OS-enforced, fail-closed confinement to the headless opencode code-authoring child of mallcop's self-extension loop. |
|
opencode
Package opencode is the headless code-authoring adapter for mallcop's self-extension loop.
|
Package opencode is the headless code-authoring adapter for mallcop's self-extension loop. |
|
proposer
Package proposer is the add-only coverage PROPOSER for mallcop's self-extension loop — the DATA-lane sibling of the opencode code-authoring engine (the engine package).
|
Package proposer is the add-only coverage PROPOSER for mallcop's self-extension loop — the DATA-lane sibling of the opencode code-authoring engine (the engine package). |
|
redact
Package redact scrubs secret-bearing key tokens (metered run keys and BYOI vendor keys) from transcripts and diffs before they are persisted to disk.
|
Package redact scrubs secret-bearing key tokens (metered run keys and BYOI vendor keys) from transcripts and diffs before they are persisted to disk. |
|
router
Package router is the AUTONOMY ROUTER for mallcop's self-extension loop.
|
Package router is the AUTONOMY ROUTER for mallcop's self-extension loop. |
|
sandbox
Package sandbox provides a git-worktree write jail and an env-scrubbed subprocess environment for mallcop's self-extension code-authoring engine.
|
Package sandbox provides a git-worktree write jail and an env-scrubbed subprocess environment for mallcop's self-extension code-authoring engine. |
|
session
Package session is the runtime SEAM that supplies inference credentials to mallcop's self-extension generative lanes (the opencode author engine and the add-only proposer) and, on the metered rail ONLY, the BILLING preamble around each run.
|
Package session is the runtime SEAM that supplies inference credentials to mallcop's self-extension generative lanes (the opencode author engine and the add-only proposer) and, on the metered rail ONLY, the BILLING preamble around each run. |
|
streamshim
Package streamshim bridges a streaming-only inference client (opencode, which always sends `stream: true`) to a NON-streaming upstream (an inference endpoint that hard-501s streaming: "Reject streaming — 501").
|
Package streamshim bridges a streaming-only inference client (opencode, which always sends `stream: true`) to a NON-streaming upstream (an inference endpoint that hard-501s streaming: "Reject streaming — 501"). |