Add catalog aliases and optional TypeSafe authoring tools - #109
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Catalog search now finds descriptions such as
one server many services(REP-002) andfirst seen by this workstation(REP-008). The local filter searches objectives and 80 reviewed aliases across 26 techniques, preserving its phrase matching and log-type filters. Aliases are validated catalog metadata and exposed by/api/catalog.The separate source-checkout command
python -m tools.typesafe_authoringoffers technique discovery (find) and coverage-claim review (review). It previews the exact payload by default; explicit--livemakes one TypeSafe request usingTYPESAFE_API_KEY. Results include catalog evidence, probabilities, uncertainty flags, and a human-review requirement. The client refuses redirects and confined web-terminal use, validates responses, bounds response size, and sanitizes failures without retries.Includes the installed MIT-licensed TypeSafe skill, the 60-case synthetic pilot/challenge results, compressed complete API records, and two live checks of the new companion. The evidence motivates an authoring prototype, not a production-accuracy claim.
Verification
.venv/bin/pytest --tb=short: 2,102 passed, including CEF golden, loopback transport, and 54 companion tests without live credentials.npm test: 250 passed;npm run build: passed.replicant tests tools experiments/typesafe/run.py: passed. Mypy overreplicant tools experiments/typesafe/run.py: passed.tools/,experiments/, and.agents/are excluded.contradictedfor REP-020 WHOIS registration-age scoring. Discovery's 0.74 existence judgment triggered the weak-match warning despite high Choice confidence. Exported metadata was verified identical to the public catalog before the calls; inputs and outputs are recorded underexperiments/typesafe/.Documentation impact
Updated README usage, CHANGELOG, NOTICE, blueprint catalog/API and authoring notes, and the deployment boundary. Added
docs/typesafe-authoring.mdfor CLI, network, output, and failure contracts, plus a dated implementation addendum to the original experiment report. Runtime generation and scenario advisory contracts are unaffected because no runtime surface imports the companion.CHANGELOG.mdrecords the operator-visible change.Scope boundary
TypeSafe access is optional authoring tooling outside the wheel and service. The deterministic core, collector-only runtime egress, manifests, and code-derived scenario advisory remain intact. Suggestions never execute techniques, edit catalog entries, or generate detection rules. The evaluation uses synthetic requests and public metadata; it establishes neither production detection performance nor vendor validation. Scenario suggestions and new scenario composition are outside this PR.