ultrasafe-synthesizer

Solid

Pre-release security testing — retire-barrier fan-out sink. Aggregate the 7 attacker agents' findings (ai-llm / web-api / supply-chain / crypto / social-eng / methodology / threat-model) via BFT quorum 2f+1 cross-axis confirmation, diversity-enforced source independence (perspective × prompt_template_hash × seed 3-tuple distinct ≥ 3), ACH multi-hypothesis matrix, CIM tri-format export (SARIF 2.1.0 + STIX 2.1 + ATT&CK Navigator), then emit 3-layer hybrid synthesis report (OSCAL Assessment Result Layer 1 + Hyperbrief 9-section IR Layer 2 + Greatpractice tree candidate Layer 3) along with the iteration boundary record (resolved / regression / persistent / new 4-set diff + untested_classes[] coverage). Fires automatically at retire-barrier after all 7 attacker findings emit complete. v0.2.x advisory mode — report-only, publish 차단 없음.

AI & Automation 7 stars 0 forks Updated 5 days ago Apache-2.0

Install

View on GitHub

Quality Score: 81/100

Stars 20%
30
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Synthesizer (cross-axis) — Ultrasafe Attacker Skill v0.2.0 > **Role**: Pre-release simulated penetration testing의 retire-barrier 합성 단독. 7 attacker (agent 1-7) finding 의 cross-axis dedup + severity ranking + correlation + 3-layer report 생성 perspective. > **Tone**: synthesis-meta. *합성 결과의 정확성 > 합성 속도* — BFT quorum 미달 finding 은 `low-confidence draft` tier 로 강등, fabricate 금지. > **Position in fan-out**: Agent 8 (sink). Phase A (7 attacker 병렬 dispatch) 의 retire-barrier 직후 Phase B 의 informed best-response 단계 (Stackelberg follower, Ultrasafe §3.2) 로 진입. > **Output**: `ULTRASAFE_ITERATION_BOUNDARY` A2A intent emit (Constellation §13.16) + 3-layer report (OSCAL + Hyperbrief IR + Greatpractice candidate) + `clean_signal_4_condition_AND_gate_state` evaluation. v0.2.x **advisory mode** — `value.advisory: true` flag mandatory. --- ## §1 When to invoke ### §1.1 Primary triggers 본 skill 은 orchestrator 역할 (메인 에이전트의 Workflow fan-out + MCP `ultrasafe_run_fanout` — Ultrasafe.md §14.1 역할 매핑) 이 자동 dispatch — 사용자/다른 agent 가 직접 호출하지 않는 게 원칙이에요. 단 다음 시점에 발화: 1. **Retire-barrier auto-fire**: 7 attacker (agent 1-7) 모두 `ULTRASAFE_FINDING` emit 완료 + orchestrator 가 finding bag 을 finalize 한 직후. Tier 1-3 모든 release tier 에서 활성. 2. **Iteration boundary close**: 현재 iteration N 의 모든 finding 이 수렴 (각 attacker 의 dispatch timeout 도달 또는 explicit `done` signal) — clean-signal-gate 역할 (MCP `ultrasafe_clean_signal_check`) 호출 직전 단계. 3. **Re-synthesis on patch**: iteration N 에서 fix 적용 후 iteration N+1 진입 시점 — *직전 ...

Details

Author
SoliEstre
Repository
SoliEstre/EstreGenesis
Created
3 months ago
Last Updated
5 days ago
Language
JavaScript
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Solid

ultrasafe-web-api-attacker

Pre-release simulated penetration testing from the OWASP Top 10 / API contract / auth-bypass / SQLi / XSS / SSRF / CSRF / open-redirect / IDOR attacker perspective. Invoke during Ultrasafe ≥3-iteration fan-out when the axis-set includes `usf-web-sast-dast` or `usf-web-infra`, or when a PreToolUse trigger matches a publish-equivalent command (npm publish / pip upload / git push --tags public). Emits `ULTRASAFE_FINDING` A2A intent per finding (Constellation §13.16) with OSCAL-aligned payload + attack-path-graph flat-list candidate. v0.2.x advisory mode — report-only, no publish blocking; blocking promotion deferred to v0.3+.

7 Updated 5 days ago
SoliEstre
AI & Automation Solid

ultrasafe-ai-llm-redteam

Pre-release simulated penetration testing from the AI/LLM red-team perspective — direct/indirect prompt injection, model extraction, jailbreak, hallucination-leverage, agentic misalignment, alignment-faking probe. Model-invoked by the Ultrasafe orchestrator (Workflow fan-out, Phase B) during ≥3 iteration pre-release fuzz cycles, or when the publish PreToolUse hook (npm publish / pip upload / git push --tags to public) fires advisory-mode trigger. Emits findings via ULTRASAFE_FINDING A2A intent (Constellation §13.16) with `value.advisory: true` in v0.2.x (report-only, no publish block). Skip for purely local dev runs without LLM-integrated surface.

7 Updated 5 days ago
SoliEstre
AI & Automation Listed

ultrasafe-social-engineer

Pre-release security testing — simulated penetration from the social-engineering / human-factor attacker perspective. Use when the Ultrasafe orchestrator dispatches Agent 5 of the 8-agent fan-out at iteration N (`usf-social-eng` axis 포함 시), or when a publish-equivalent command triggers the PreToolUse hook and the `social-engineer` role is in the active axis set. Scans for phishing surface (credential prompts, OAuth UX traps), docs leak (README/CHANGELOG/commit messages exposing OPSEC slips, internal hostnames, sample tokens), human-factor exploitation (Cialdini 6 × Hadnagy 9 × FBI 8-elicitation cross-tuple), and A2A inbound Spotlighting bypass attempts. Emits findings via `ULTRASAFE_FINDING` Constellation intent (§13.16) — advisory mode in v0.2.x (report-only, publish 차단 없음). SKIP when iteration ≤ 0 (no baseline) or when axis-set excludes `usf-social-eng`.

7 Updated 5 days ago
SoliEstre