Documentation
¶
Overview ¶
corpus.go — the embedded operator-decisions corpus.
//go:embed cannot traverse "..", so the embed directive must live in a .go file at a directory level whose subtree contains the corpus. The corpus is at <root>/agents/rules/operator-decisions.yaml, so ONLY the repo root qualifies. This is the sole production package at the root (hello_test.go is the external `mallcoplegion_test` package, which Go permits to coexist with `mallcoplegion` in the same directory).
The bytes are exposed so the production runtime loaders (core/agent's escalate-route floor and core/tools' operator-rules loader) can FALL BACK to a baked-in corpus when no on-disk corpus can be located — e.g. a standalone `/tmp/mallcop` binary with MALLCOP_REPO_ROOT unset and no project marker above it. This is a strict FALLBACK: an on-disk corpus (binary-walk hit or MALLCOP_REPO_ROOT) always wins, so dev edit-and-reload of the corpus is preserved. See the loaders' corpusBytes helpers.
This package imports ONLY "embed" — it carries no dependency that could let the floor path reach inference, so importing it from core/agent and core/tools does not violate either import-lint.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var OperatorDecisionsYAML []byte
OperatorDecisionsYAML is the byte-for-byte contents of agents/rules/operator-decisions.yaml at build time. Because //go:embed copies the exact file, these bytes are identical to the on-disk corpus the SHA pin (core/tools.expectedOperatorRulesSHA256) describes — by construction, with no separate copy that could drift. The embed==disk test makes that invariant explicit and catches a stale checked-in pin.
Functions ¶
This section is empty.
Types ¶
This section is empty.
Directories
¶
| Path | Synopsis |
|---|---|
|
cmd
|
|
|
baseline
command
Command baseline builds and queries mallcop baseline frequency tables.
|
Command baseline builds and queries mallcop baseline frequency tables. |
|
detector-config-drift
command
detector-config-drift reads events JSONL from stdin and emits findings JSONL to stdout for configuration change events: security group modifications, IAM policy changes, MFA disabling, and audit log modifications.
|
detector-config-drift reads events JSONL from stdin and emits findings JSONL to stdout for configuration change events: security group modifications, IAM policy changes, MFA disabling, and audit log modifications. |
|
detector-dependency-tamper
command
detector-dependency-tamper reads events JSONL from stdin and emits findings JSONL to stdout for dependency supply chain tampering: package version changes, unexpected additions, hash mismatches, and typosquatting indicators.
|
detector-dependency-tamper reads events JSONL from stdin and emits findings JSONL to stdout for dependency supply chain tampering: package version changes, unexpected additions, hash mismatches, and typosquatting indicators. |
|
detector-exfil-pattern
command
detector-exfil-pattern reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate data exfiltration: unusual outbound data volumes, bulk access to many resources in a short window, or download events that exceed baseline frequency thresholds.
|
detector-exfil-pattern reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate data exfiltration: unusual outbound data volumes, bulk access to many resources in a short window, or download events that exceed baseline frequency thresholds. |
|
detector-git-oops
command
detector-git-oops reads events JSONL from stdin and emits findings JSONL to stdout for dangerous git operations: force pushes, branch deletions, and commit messages containing secret-looking strings.
|
detector-git-oops reads events JSONL from stdin and emits findings JSONL to stdout for dangerous git operations: force pushes, branch deletions, and commit messages containing secret-looking strings. |
|
detector-injection-probe
command
detector-injection-probe reads events JSONL from stdin and emits findings JSONL to stdout for events that contain prompt injection attempts in their payload fields.
|
detector-injection-probe reads events JSONL from stdin and emits findings JSONL to stdout for events that contain prompt injection attempts in their payload fields. |
|
detector-malicious-skill
command
detector-malicious-skill reads events JSONL from stdin and emits findings JSONL to stdout for skill-related events that contain suspicious URLs, encoded payloads, or excessive permission requests.
|
detector-malicious-skill reads events JSONL from stdin and emits findings JSONL to stdout for skill-related events that contain suspicious URLs, encoded payloads, or excessive permission requests. |
|
detector-new-actor
command
detector-new-actor reads events JSONL from stdin, compares each actor against the baseline known-actors set, and emits findings JSONL to stdout for actors not seen in the baseline period.
|
detector-new-actor reads events JSONL from stdin, compares each actor against the baseline known-actors set, and emits findings JSONL to stdout for actors not seen in the baseline period. |
|
detector-priv-escalation
command
detector-priv-escalation reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate a privilege escalation — role grants, permission changes, or admin promotions — not already in the baseline.
|
detector-priv-escalation reads events JSONL from stdin and emits findings JSONL to stdout for events that indicate a privilege escalation — role grants, permission changes, or admin promotions — not already in the baseline. |
|
detector-rate-anomaly
command
detector-rate-anomaly reads events JSONL from stdin and emits findings JSONL to stdout for events that show API rate anomalies: burst requests, orders-of-magnitude jumps above baseline, or unusual endpoint access patterns.
|
detector-rate-anomaly reads events JSONL from stdin and emits findings JSONL to stdout for events that show API rate anomalies: burst requests, orders-of-magnitude jumps above baseline, or unusual endpoint access patterns. |
|
detector-secrets-exposure
command
detector-secrets-exposure reads events JSONL from stdin and emits findings JSONL to stdout when event payload fields contain secrets in cleartext: API keys, tokens, passwords, and credentials matching known formats.
|
detector-secrets-exposure reads events JSONL from stdin and emits findings JSONL to stdout when event payload fields contain secrets in cleartext: API keys, tokens, passwords, and credentials matching known formats. |
|
detector-unusual-login
command
detector-unusual-login reads events JSONL from stdin, compares each login event against a baseline of known user patterns, and emits findings JSONL to stdout for logins that deviate from baseline.
|
detector-unusual-login reads events JSONL from stdin, compares each login event against a baseline of known user patterns, and emits findings JSONL to stdout for logins that deviate from baseline. |
|
detector-unusual-timing
command
detector-unusual-timing reads events JSONL from stdin and emits findings JSONL to stdout for events that occur at UTC hours not seen for that actor in the baseline period.
|
detector-unusual-timing reads events JSONL from stdin and emits findings JSONL to stdout for events that occur at UTC hours not seen for that actor in the baseline period. |
|
detector-volume-anomaly
command
detector-volume-anomaly reads events JSONL from stdin, counts events per (source, event_type) group, and emits findings JSONL to stdout when the observed count exceeds 3× the baseline count for that group.
|
detector-volume-anomaly reads events JSONL from stdin, counts events per (source, event_type) group, and emits findings JSONL to stdout when the observed count exceeds 3× the baseline count for that group. |
|
exam-render-chart
command
cmd/exam-render-chart renders charts/exam.toml.tmpl into a ready-to-boot legion chart for a specific exam run.
|
cmd/exam-render-chart renders charts/exam.toml.tmpl into a ready-to-boot legion chart for a specific exam run. |
|
exam-seed
command
Command exam-seed walks exams/scenarios/, loads each YAML via internal/exam.Load, materializes fixture files, and posts work:create messages to a campfire for each scenario plus one final exam:report item.
|
Command exam-seed walks exams/scenarios/, loads each YAML via internal/exam.Load, materializes fixture files, and posts work:create messages to a campfire for each scenario plus one final exam:report item. |
|
exam-transcript-dump
command
cmd/exam-transcript-dump renders a judge-visible Markdown transcript from exam fixture data and a heal disposition's resolution JSON.
|
cmd/exam-transcript-dump renders a judge-visible Markdown transcript from exam fixture data and a heal disposition's resolution JSON. |
|
mallcop
command
Command mallcop is the customer-facing CLI for running mallcop scans.
|
Command mallcop is the customer-facing CLI for running mallcop scans. |
|
mallcop-academy
command
forge_usage.go — per-scenario Forge usage querying for mallcop-academy.
|
forge_usage.go — per-scenario Forge usage querying for mallcop-academy. |
|
mallcop-checklist-verify
command
Command mallcop-checklist-verify is a veracity-gate hook CLI that blocks a disposition from closing a bead unless it has emitted all required Pre-Resolution Checklist items to the engagement campfire.
|
Command mallcop-checklist-verify is a veracity-gate hook CLI that blocks a disposition from closing a bead unless it has emitted all required Pre-Resolution Checklist items to the engagement campfire. |
|
mallcop-coverage-tripwire
command
|
|
|
mallcop-credential-theft-verify
command
Command mallcop-credential-theft-verify is a veracity-gate hook binary that enforces the Credential Theft Test rule from the investigate disposition.
|
Command mallcop-credential-theft-verify is a veracity-gate hook binary that enforces the Credential Theft Test rule from the investigate disposition. |
|
mallcop-eval
command
Command mallcop-eval runs the portable eval harness over the SHA-pinned scenario corpus and prints the report as JSON.
|
Command mallcop-eval runs the portable eval harness over the SHA-pinned scenario corpus and prints the report as JSON. |
|
mallcop-exam-report
command
Command mallcop-exam-report aggregates judge:verdict messages from a campfire into a structured exam report (report.json + report.md).
|
Command mallcop-exam-report aggregates judge:verdict messages from a campfire into a structured exam report (report.json + report.md). |
|
mallcop-finding-context
command
|
|
|
mallcop-investigate-tools
command
Package main implements mallcop-investigate-tools — a single read-only binary used by the investigate (and triage) dispositions to query fixture data without network egress or shell escapes.
|
Package main implements mallcop-investigate-tools — a single read-only binary used by the investigate (and triage) dispositions to query fixture data without network egress or shell escapes. |
|
notify-email
command
|
|
|
notify-slack
command
|
|
|
notify-teams
command
|
|
|
notify-telegram
command
|
|
|
connect
|
|
|
github
Package github is the portable GitHub Connector: it pulls org activity from the GitHub API and normalizes it to []event.Event so the detector floor (core/detect) and the rest of the scan pipeline run unchanged.
|
Package github is the portable GitHub Connector: it pulls org activity from the GitHub API and normalizes it to []event.Event so the detector floor (core/detect) and the rest of the scan pipeline run unchanged. |
|
core
|
|
|
agent
Package agent holds the SECURITY-CRITICAL pre-LLM floor for finding resolution plus the minimal anthropic.Client interface the agent loop (built in a later wave) consumes.
|
Package agent holds the SECURITY-CRITICAL pre-LLM floor for finding resolution plus the minimal anthropic.Client interface the agent loop (built in a later wave) consumes. |
|
connect
Package connect is the INPUT seam of the scan pipeline: it turns a source of raw activity into the normalized []event.Event the detector floor consumes.
|
Package connect is the INPUT seam of the scan pipeline: it turns a source of raw activity into the normalized []event.Event the detector floor consumes. |
|
detect
Package detect provides offline, deterministic security detection over a corpus of normalized events.
|
Package detect provides offline, deterministic security detection over a corpus of normalized events. |
|
eval
artifacts.go — write the harness's per-scenario result JSON, per-scenario TRANSCRIPTS, and the classifier summary to disk (§4.4 result JSON, §4.7 transcript audit).
|
artifacts.go — write the harness's per-scenario result JSON, per-scenario TRANSCRIPTS, and the classifier summary to disk (§4.4 result JSON, §4.7 transcript audit). |
|
inference
Package inference holds the network seam that satisfies core/agent.Client.
|
Package inference holds the network seam that satisfies core/agent.Client. |
|
lint
Package lint hosts the repo-level import-lint guard for the core/ tree.
|
Package lint hosts the repo-level import-lint guard for the core/ tree. |
|
observe
Package observe holds the THREE pure observable force-escalate predicates the cascade's structural-confidence gate scores, plus every helper / threshold / map they read — extracted VERBATIM from core/eval/scenario_tools.go so that the eval scenarioToolRunner AND the production core/toolrun.Runner call ONE shared implementation and get BYTE-IDENTICAL booleans + details.
|
Package observe holds the THREE pure observable force-escalate predicates the cascade's structural-confidence gate scores, plus every helper / threshold / map they read — extracted VERBATIM from core/eval/scenario_tools.go so that the eval scenarioToolRunner AND the production core/toolrun.Runner call ONE shared implementation and get BYTE-IDENTICAL booleans + details. |
|
pipeline
Package pipeline is the ORCHESTRATOR that assembles the four core seams into one agentic scan cycle:
|
Package pipeline is the ORCHESTRATOR that assembles the four core seams into one agentic scan cycle: |
|
store
Package store is the git-repo source of truth for mallcop's six append-only streams: events, findings, resolutions, baseline, conversation, and directives.
|
Package store is the git-repo source of truth for mallcop's six append-only streams: events, findings, resolutions, baseline, conversation, and directives. |
|
toolrun
Package toolrun is the PRODUCTION ToolRunner — the live agent.ToolRunner the scan pipeline wires into the cascade (CascadeOptions.Tools).
|
Package toolrun is the PRODUCTION ToolRunner — the live agent.ToolRunner the scan pipeline wires into the cascade (CascadeOptions.Tools). |
|
tools
casefold.go — case-insensitive structured-record parsing at the boundary (portable-agent-architecture.md §3.7).
|
casefold.go — case-insensitive structured-record parsing at the boundary (portable-agent-architecture.md §3.7). |
|
internal
|
|
|
exam
Package exam provides types and loader logic for mallcop exam scenarios.
|
Package exam provides types and loader logic for mallcop exam scenarios. |
|
testutil/cannedbackend
Package cannedbackend provides a minimal HTTP server that mimics Forge's /v1/chat/completions and /v1/messages endpoints for integration and e2e tests.
|
Package cannedbackend provides a minimal HTTP server that mimics Forge's /v1/chat/completions and /v1/messages endpoints for integration and e2e tests. |
|
pkg
|
|
|
ghauth
Package ghauth mints GitHub App installation access tokens with a stdlib-only RS256 JWT.
|
Package ghauth mints GitHub App installation access tokens with a stdlib-only RS256 JWT. |