docs(llm-security): v8 Phase 2 — B10 docs consistency, counts pinned by test
Extends tests/lib/doc-consistency.test.mjs with 15 cases that derive every inventory count from source instead of trusting prose. Each count has one stated derivation; a doc surface that disagrees now fails the suite. Counts corrected (all were wrong before the test existed): - orchestrated scanners: docs said 10 (README, ci-cd-guide), CLAUDE.md said 12, the synthesizer agent said 9 — scan-orchestrator registers 14 - total scanners: README badge + 3 prose sites said 23; the counting rule in docs/scanner-reference.md (14 orchestrated + 8 standalone) yields 22 - knowledge files: README badge + prose said 22; knowledge/ holds 23 - output.mjs finding() prefix JSDoc listed 10 of the 17 prefixes actually passed to it (missing IDE, MCI, MEM, PST, SCR, TFA, WFL) - norwegian-context.md said "8 hooks, 10 scanners" -> 9 and 14 - ci-cd-guide "what gets scanned" table listed 10 of 14 rows; adds workflow, trigger abuse, signature, AST taint Two plan items changed after verifying against ground truth: - CLAUDE.md's synthesizer "(12 scanners)" was not a deliberate subset; the agent file itself claimed 9. Both bumped to 14. - compliance-mapping.md's "13 posture categories" is substantively correct — its matrix has exactly 13 data rows, and categories 14-16 are governance consumers of the file, not rows in it. The planned 13->16 bump would have made the document false. Wording clarified to "code-level" instead, and the test now pins row count against the stated claim. Framework currency (both verified against primary reporting): - EU AI Act: Digital Omnibus (EP 2026-06-16, Council 2026-06-29) deferred the high-risk obligations behind Art. 9/15 to 2027-12-02 (Annex III) and 2028-08-02 (Annex I); transparency still applies from 2026-08-02 - OWASP Agentic AI Top 10 labelled as the 2026 edition Also: CLAUDE.md Distribution section rewritten monorepo -> polyrepo (each plugin is its own repo; the catalog pins url + ref per plugin), and current-state test counts synced 2013 -> 2034. Release-note paragraphs keep their historical numbers. No scanner, hook, or command behaviour changes. Suite 2034/2034. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Wt4YQGoXwRja5K2Zmv8RZE
This commit is contained in:
parent
ff4d8e8a31
commit
0f1be986d0
8 changed files with 287 additions and 22 deletions
20
README.md
20
README.md
|
|
@ -10,13 +10,13 @@
|
|||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
A Claude Code plugin that provides security scanning, auditing, and threat modeling for agentic AI projects. Built on [OWASP LLM Top 10 (2025)](https://genai.owasp.org/llm-top-10/), [OWASP Agentic AI Top 10 (ASI01-ASI10)](https://genai.owasp.org/agentic-ai/), OWASP Skills Top 10 (AST01-AST10), MCP Top 10, and the [AI Agent Traps](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6372438) taxonomy (Google DeepMind, 2025), grounded in published research from ToxicSkills, ClawHavoc, MCPTox, Pillar Security, Invariant Labs, GHSL Security Lab, and Operant AI.
|
||||
A Claude Code plugin that provides security scanning, auditing, and threat modeling for agentic AI projects. Built on [OWASP LLM Top 10 (2025)](https://genai.owasp.org/llm-top-10/), [OWASP Agentic AI Top 10 (ASI01-ASI10, 2026 edition)](https://genai.owasp.org/agentic-ai/), OWASP Skills Top 10 (AST01-AST10), MCP Top 10, and the [AI Agent Traps](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6372438) taxonomy (Google DeepMind, 2025), grounded in published research from ToxicSkills, ClawHavoc, MCPTox, Pillar Security, Invariant Labs, GHSL Security Lab, and Operant AI.
|
||||
|
||||
---
|
||||
|
||||
|
|
@ -101,7 +101,7 @@ flowchart TB
|
|||
H4["PreCompact<br/>transcript scan"]
|
||||
end
|
||||
|
||||
subgraph Scanning["Deterministic analysis — 23 scanners"]
|
||||
subgraph Scanning["Deterministic analysis — 22 scanners"]
|
||||
direction LR
|
||||
S1["UNI · ENT · PRM · DEP<br/>TNT · GIT · NET · MEM · SCR · TFA"]
|
||||
S2["WFL workflow scanner"]
|
||||
|
|
@ -144,8 +144,8 @@ Each layer is independent. A failure in one (e.g. an injection that slips past t
|
|||
|---------|-------------|
|
||||
| `/security` | Router with quick-start guide |
|
||||
| `/security scan [path\|url]` | Supply-chain gate — ALLOW/WARNING/BLOCK verdict on skills, MCP servers, directories, or remote repos |
|
||||
| `/security scan [path\|url] --deep` | Adds 10 deterministic scanners on top of the LLM agents |
|
||||
| `/security deep-scan [path]` | Run only the 10 orchestrated deterministic scanners. Supports `--fail-on <severity>`, `--compact`, `--format sarif`, `--output-file <path>` |
|
||||
| `/security scan [path\|url] --deep` | Adds 14 deterministic scanners on top of the LLM agents |
|
||||
| `/security deep-scan [path]` | Run only the 14 orchestrated deterministic scanners. Supports `--fail-on <severity>`, `--compact`, `--format sarif`, `--output-file <path>` |
|
||||
| `/security audit` | Full project audit, A-F grade, prioritized action plan |
|
||||
| `/security plugin-audit [path\|url]` | Plugin trust assessment with Install/Review/Do Not Install verdict |
|
||||
| `/security mcp-audit [--live]` | Audit installed MCP server configs (`--live` adds runtime inspection) |
|
||||
|
|
@ -224,7 +224,7 @@ All hooks are Node.js `.mjs` for cross-platform compatibility (macOS, Linux, Win
|
|||
|
||||
## Deterministic scanners
|
||||
|
||||
23 scanners. Zero external dependencies. All output JSON.
|
||||
22 scanners. Zero external dependencies. All output JSON.
|
||||
|
||||
### Orchestrated (14) — run via `node scanners/scan-orchestrator.mjs <target>` or `/security deep-scan`
|
||||
|
||||
|
|
@ -424,8 +424,8 @@ These gaps are surfaced advisorily through `/security threat-model` and `/securi
|
|||
## Project scope
|
||||
|
||||
This is a **solo open-source project in stabilization mode** as of 2026-05-01.
|
||||
The current feature set (5 frameworks, 23 scanners, 9 hooks, 6 agents,
|
||||
20 commands, 22 knowledge files, 2013+ tests including a dedicated end-to-end suite) is the natural plateau for
|
||||
The current feature set (5 frameworks, 22 scanners, 9 hooks, 6 agents,
|
||||
20 commands, 23 knowledge files, 2034+ tests including a dedicated end-to-end suite) is the natural plateau for
|
||||
what a deterministic + advisory plugin can defend against without crossing
|
||||
into commercial-grade territory. Going forward, work focuses on:
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue