Auditor
A three-phase, fixed-taxonomy model review of authentication, authorization, input handling, crypto and code-execution paths; a finding counts only with a real path and line and a confidence of at least 0.8.
1.1.4: SPEED PASS: the chunks of the plan go to the model IN PARALLEL up to what the engine admits (ctx.ai.maxConcurrentCalls, 1 when the sandbox does not publish it) instead of one after another, and the answers are processed in plan order, so the verdict and the trace never depend on which answer arrives first. Measured on the attestation of social: 40 sequential calls of ~4 000 tokens with a four-token answer, the model busy well under a second per call and the rest orchestration. Selection, rubric, taxonomy, exclusions and decision rule unchanged. (1.1.3: requires an AI engine (spec.requiresEngine: true): the check needs judgement and is executed only when the organisation provides an engine; the core catalogue runs without one. (1.1.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.1.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (chunks shrink to what the rubric and the repository context leave). (1.1.0 adopted the three-phase review, exclusions and confidence threshold, method from anthropics/claude-code-security-review, MIT.))))
| const CATEGORIES = { 'input-validation': 'CWE-20', 'injection': 'CWE-74', 'path-traversal': 'CWE-22', 'authentication': 'CWE-287', 'authorization': 'CWE-862', 'session-management': 'CWE-613', 'cryptography': 'CWE-327', 'secrets-management': 'CWE-798', 'code-execution': 'CWE-94', 'data-exposure': 'CWE-200' }; |
| const CONFIDENCE_THRESHOLD = 0.8; // below it, nothing is reported |
| // excluded after the answer: denial of service, rate limiting, leaks outside C/C++, ReDoS, SSRF in HTML, markdown, speculative wording |
| // FAIL on HIGH; MEDIUM blocks only in Extended suites; LOW is informative |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.