Auditor
Authenticated routes reject malformed, expired, replayed and downgraded credentials under fuzzed inputs.
1.0.4: `assess` mode cuts the candidate set to what the chosen ENGINE serves in ONE call (`ctx.ai.maxInputChars`, published by the engine per its catalogue budget; `ENGINE_CALL_MAX_CHARS` = 32 000 when an older sandbox does not publish it), instead of filling the call up to the TRANSPORT cap of the proxy (`spec.promptMaxChars`, unchanged at 120 000). On a 1 319-file checkout the old packing produced single prompts of 17 672 / 26 709 / 29 351 tokens and the platform GPU answered "CUDA out of memory": the check ended in `error`. Every call of the same run under ~24 000 characters was answered normally. The part aggregation of 1.0.1 is unchanged: a HIGH in any part is a FAIL, an unsatisfied part is a FAIL, undecided never passes. (1.0.3: requires an AI engine (spec.requiresEngine: true): the check needs judgement and is executed only when the organisation provides an engine; the core catalogue runs without one. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
| { id: 'downgrade-accepted', re: /\bjwt\.verify\s*\(\s*[^,\n]+,\s*[^,\n]+\s*\)/g, what: 'jwt.verify without an algorithms list' }, // -> FAIL |
| { id: 'downgrade-accepted', re: /algorithms\s*[:=]\s*\[[^\]]*['"]none['"]/g }, // -> FAIL |
| { id: 'expired-accepted', re: /ignoreExpiration\s*:\s*true|verify_exp['"]?\s*:\s*False|clockTolerance\s*:\s*(?:[3-9]\d{2}|\d{4,})/g }, // -> FAIL |
| // verifier without try/catch -> MEDIUM; one-time credential without consumption -> MEDIUM; then one assessment call over the four fuzz classes (>= 0.8) or FAIL |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.