Skip to content

Add catalog aliases and optional TypeSafe authoring tools - #109

Merged
404SecNotFound merged 1 commit into
mainfrom
codex/typesafe-authoring-search
Sep 27, 2026
Merged

404SecNotFound merged 1 commit into
mainfrom
codex/typesafe-authoring-search

Conversation

@404SecNotFound

Copy link
Copy Markdown
Owner

Summary

Catalog search now finds descriptions such as one server many services (REP-002) and first seen by this workstation (REP-008). The local filter searches objectives and 80 reviewed aliases across 26 techniques, preserving its phrase matching and log-type filters. Aliases are validated catalog metadata and exposed by /api/catalog.

The separate source-checkout command python -m tools.typesafe_authoring offers technique discovery (find) and coverage-claim review (review). It previews the exact payload by default; explicit --live makes one TypeSafe request using TYPESAFE_API_KEY. Results include catalog evidence, probabilities, uncertainty flags, and a human-review requirement. The client refuses redirects and confined web-terminal use, validates responses, bounds response size, and sanitizes failures without retries.

Includes the installed MIT-licensed TypeSafe skill, the 60-case synthetic pilot/challenge results, compressed complete API records, and two live checks of the new companion. The evidence motivates an authoring prototype, not a production-accuracy claim.

Verification

  • .venv/bin/pytest --tb=short: 2,102 passed, including CEF golden, loopback transport, and 54 companion tests without live credentials.
  • Frontend npm test: 250 passed; npm run build: passed.
  • Black and Ruff over replicant tests tools experiments/typesafe/run.py: passed. Mypy over replicant tools experiments/typesafe/run.py: passed.
  • Built and inspected the wheel: all 26 techniques and 80 aliases are present; tools/, experiments/, and .agents/ are excluded.
  • Executed the actual TypeScript filter against all 80 authored aliases: 80/80 intended entries found, versus 0/80 with the previous search fields. This measures authored-alias coverage, not held-out accuracy.
  • Two live CLI checks returned expected choices: REP-002 discovery and contradicted for REP-020 WHOIS registration-age scoring. Discovery's 0.74 existence judgment triggered the weak-match warning despite high Choice confidence. Exported metadata was verified identical to the public catalog before the calls; inputs and outputs are recorded under experiments/typesafe/.

Documentation impact

Updated README usage, CHANGELOG, NOTICE, blueprint catalog/API and authoring notes, and the deployment boundary. Added docs/typesafe-authoring.md for CLI, network, output, and failure contracts, plus a dated implementation addendum to the original experiment report. Runtime generation and scenario advisory contracts are unaffected because no runtime surface imports the companion.

  • Maintained documentation changed alongside the behavior, or unaffected surfaces are explained above.
  • CHANGELOG.md records the operator-visible change.
  • Historical decision records were preserved or received a dated addendum.
  • Documentation claims were checked against the implemented behavior.

Scope boundary

TypeSafe access is optional authoring tooling outside the wheel and service. The deterministic core, collector-only runtime egress, manifests, and code-derived scenario advisory remain intact. Suggestions never execute techniques, edit catalog entries, or generate detection rules. The evaluation uses synthetic requests and public metadata; it establishes neither production detection performance nor vendor validation. Scenario suggestions and new scenario composition are outside this PR.

@404SecNotFound
404SecNotFound merged commit ef97905 into main Sep 27, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant