Auditor
Each device holds its own keys; adding or revoking a device never exposes private keys to the server.
1.0.4: `assess` mode cuts the candidate set to what the chosen ENGINE serves in ONE call (`ctx.ai.maxInputChars`, published by the engine per its catalogue budget; `ENGINE_CALL_MAX_CHARS` = 32 000 when an older sandbox does not publish it), instead of filling the call up to the TRANSPORT cap of the proxy (`spec.promptMaxChars`, unchanged at 120 000). On a 1 319-file checkout the old packing produced single prompts of 17 672 / 26 709 / 29 351 tokens and the platform GPU answered "CUDA out of memory": the check ended in `error`. Every call of the same run under ~24 000 characters was answered normally. The part aggregation of 1.0.1 is unchanged: a HIGH in any part is a FAIL, an unsatisfied part is a FAIL, undecided never passes. (1.0.3: requires an AI engine (spec.requiresEngine: true): the check needs judgement and is executed only when the organisation provides an engine; the core catalogue runs without one. (1.0.2: applies only to a real messaging feature: a message or conversation model, a chat transport (socket, channel or pub/sub events of a conversation), a messaging protocol library (Signal, MLS, Olm/Megolm, XMPP) or a chat UI; messaging vocabulary alone (an error message pushed to a queue, a notification channel, a case signal route) is not-applicable with the reason; never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
| const PRIVATE_EXPORT = /exportKey\s*\(\s*['"](?:pkcs8|jwk|raw)['"]\s*,\s*\w*(?:privateKey|secretKey|priv)\w*\)|private_bytes\(|toPKCS8|exportPrivateKey/; // followed by a send/upload without device-side encryption -> FAIL |
| const REVOCATION_EFFECT = /invalidate|revoke\w*|sessions?\.(?:delete|remove)|rotate\w*|rekey|revokedAt|isRevoked/i; // absent in a revoke path -> MEDIUM |
| // no device model -> not applicable; then one assessment call over the device files (>= 0.8) or FAIL |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.