- Created `CONCEPTS.md` to track coverage of blueprint structures - Added 5 new PoCs: CFG, Constitution, Frontmatter, Mutation, and Orphan Branch - Registered all 15 experiments in `lab.ts` runner - Ensured zero-dependency Deno execution for tests Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com> Co-authored-by: mrteye <1945243+mrteye@users.noreply.github.com>
90 lines
2.5 KiB
TypeScript
90 lines
2.5 KiB
TypeScript
import {
|
|
assert,
|
|
assertEquals,
|
|
} from "https://deno.land/std@0.224.0/testing/asserts.ts";
|
|
|
|
/**
|
|
* Proof of Concept: Abstract Syntax Trees & Control Flow Graphs (CFGs)
|
|
*
|
|
* Demonstrates the Adversary agent consuming a simulated CFG to trace if
|
|
* unsanitized user input can reach a sensitive sink (e.g. a database query).
|
|
*/
|
|
|
|
// Simulates a JSON representation of a Control Flow Graph extracted from an AST.
|
|
// Paths map variable assignments and function calls.
|
|
const mockCFG = {
|
|
nodes: [
|
|
{ id: "1", type: "entry", source: "user_input" },
|
|
{ id: "2", type: "operation", action: "sanitize", target: "user_input" },
|
|
{ id: "3", type: "sink", action: "db_query", input: "user_input" },
|
|
{ id: "4", type: "entry", source: "raw_header" },
|
|
{ id: "5", type: "sink", action: "db_query", input: "raw_header" },
|
|
],
|
|
edges: [
|
|
{ from: "1", to: "2" }, // user_input goes to sanitize
|
|
{ from: "2", to: "3" }, // sanitized input goes to db
|
|
{ from: "4", to: "5" }, // raw_header goes straight to db
|
|
],
|
|
};
|
|
|
|
function analyzeSecurityPath(cfg: typeof mockCFG): string[] {
|
|
const vulnerabilities = [];
|
|
|
|
// Find all entry nodes
|
|
const entries = cfg.nodes.filter((n) => n.type === "entry");
|
|
|
|
for (const entry of entries) {
|
|
let currentNodeId = entry.id;
|
|
let isSanitized = false;
|
|
|
|
// Simple path traversal simulation
|
|
while (true) {
|
|
const outgoingEdge = cfg.edges.find((e) => e.from === currentNodeId);
|
|
if (!outgoingEdge) break;
|
|
|
|
const nextNode = cfg.nodes.find((n) => n.id === outgoingEdge.to);
|
|
if (!nextNode) break;
|
|
|
|
if (nextNode.action === "sanitize") {
|
|
isSanitized = true;
|
|
}
|
|
|
|
if (nextNode.type === "sink") {
|
|
if (!isSanitized) {
|
|
vulnerabilities.push(
|
|
`Vulnerability: Unsanitized input from '${entry.source}' reached sink '${nextNode.action}'`,
|
|
);
|
|
}
|
|
}
|
|
|
|
currentNodeId = nextNode.id;
|
|
}
|
|
}
|
|
|
|
return vulnerabilities;
|
|
}
|
|
|
|
if (import.meta.main) {
|
|
console.log("Running CFG Security Proving PoC tests...");
|
|
|
|
try {
|
|
const vulns = analyzeSecurityPath(mockCFG);
|
|
|
|
console.log("Adversary Agent CFG Analysis Results:");
|
|
vulns.forEach((v) => console.log(` - ${v}`));
|
|
|
|
assertEquals(vulns.length, 1);
|
|
assert(
|
|
vulns[0].includes("raw_header"),
|
|
"Expected raw_header to flag a vulnerability",
|
|
);
|
|
|
|
console.log(
|
|
"✅ CFG Security Proving PoC successful: Deterministic taint analysis simulated.",
|
|
);
|
|
} catch (err) {
|
|
console.error("❌ CFG Security Proving PoC failed:", err);
|
|
Deno.exit(1);
|
|
}
|
|
}
|