Skip to content

Commit 3486fd2

Browse files
committed
Repoint dedupe loop filter, update review packet, and refine calibration and retry logic
- Repointed @mantis-dedupe loop filter to read from workspace/archive/findings_pass_*/*.json instead of workspace/learnings.jsonl. - Updated @mantis-dedupe instructions to filter out any findings already processed in previous passes of the run (regardless of status), with an exception for findings with the same UUID (retries). - Updated references to review_packet.md in @mantis-meta-agent and README to use review_packet-latest.md and review_packet_pass_<N>.md. - Updated @mantis-calibrate to determine attacker position by boundary barrier, not transport (including physical, home LAN, and local networks), tracing back to the first untrusted principal. - Introduced Principle of Marginal Capability as a general, non-exhaustive guiding principle for calibration, and updated related rules. - Added Trusted-Controller-Mediated Interface rules (LOW, MEDIUM, HIGH caps) to generalize marginal capability. - Added Reachability-in-Practice modifier to reduce likelihood_score for uncommon/non-default usage. - Replaced Same-Tenant cap with Self-Contained Blast Radius cap under MEDIUM caps, defining domain isolation bounds and exceptions. - Updated @mantis-plan to copy retry-eligible findings (failed repro, failed patch) directly back to workspace/findings/ instead of scheduling them in plan.json, bypassing the researcher. - Added support for loopN_findings fallback naming convention for archives in @mantis-dedupe and @mantis-plan. TAG=agy CONV=e491ff6c-5e42-42b9-8098-9156f757d276 Change-Id: If341f99449d70b77ac025ad8177c3d187a1ddaec
1 parent c5020a9 commit 3486fd2

5 files changed

Lines changed: 210 additions & 90 deletions

File tree

‎README_AGENTS.md‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,7 @@ graph TD
6969
FilePlan[("workspace/plan.json")]
7070
FileFind[("workspace/findings/*.json")]
7171
FileLearn[("workspace/learnings.jsonl")]
72-
FileRpt[/"workspace/report/review_packet.md"/]
72+
FileRpt[/"workspace/report/review_packet-latest.md"/]
7373
7474
Meta --> Hist
7575
Hist --> Sum
@@ -178,7 +178,8 @@ graph TD
178178
`workspace/learnings.jsonl` inbox.
179179
16. **`/mantis-report` (Reporter):** Generates a human-readable security review
180180
packet containing verified/reproduced findings, evidence, risk rationales,
181-
and patch information at `workspace/report/review_packet.md`.
181+
and patch information at `workspace/report/review_packet-latest.md` (and
182+
archives to `review_packet_pass_<N>.md`).
182183

183184
--------------------------------------------------------------------------------
184185

‎mantis-calibrate/SKILL.md‎

Lines changed: 134 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -135,6 +135,15 @@ Execute the calibration as follows:
135135
- 2: Theoretical and highly complex (requires local access, strict
136136
timing).
137137
- 1: Strictly theoretical risk with no known exploit path.
138+
- **Reachability-in-Practice Modifier:** After determining the base
139+
likelihood, reduce the `likelihood_score` by **1 or 2** (but not
140+
below 1.0) if the exploit path relies on uncommon or non-default
141+
usage patterns. This applies if:
142+
- The specific tainted parameter is populated from attacker input
143+
only during rare API calls, uncommon configuration fields, or in
144+
data formats rarely processed in the wild.
145+
- The vulnerability requires non-standard or administrative-only
146+
configurations that are rarely enabled in practice.
138147
- **Context Multiplier (0.1 - 1.0):**
139148
- If `status` is **FALSE_POSITIVE** or **NEEDS_RESEARCH**, or if
140149
`production_viability` is **NON_VIABLE**: Drop this finding
@@ -171,6 +180,38 @@ Execute the calibration as follows:
171180
`"PRIVILEGED"`
172181
- **Evaluate Attacker Position (declared in finding):**
173182
- Read `attacker_position` from the finding JSON.
183+
- **Determine by Barrier, Not Transport:** The
184+
`attacker_position` must represent the outermost
185+
boundary that the **first untrusted principal** (the
186+
ultimate human attacker or external threat actor) must
187+
cross to reach the interface. Do not key on the
188+
transport protocol (e.g., HTTP, gRPC, IPC) or the
189+
immediate protocol peer.
190+
- **Trace Back to Untrusted Actor:** If the immediate
191+
peer interacting with the interface is a
192+
trusted-by-design component (e.g., an internal
193+
proxy, gateway, message queue, or master
194+
controller), you must trace back the data flow to
195+
find the outermost boundary where the untrusted
196+
actor first enters the system.
197+
- If the interface is bound to `localhost` or uses
198+
local IPC (unix sockets, pipes, shared memory), the
199+
position is `"LOCAL"`, even if it uses HTTP/TCP
200+
under the hood.
201+
- If the interface is only reachable within a private
202+
network (VPC, corporate network, home LAN, local
203+
network, internal cluster control plane), the
204+
position is `"INTERNAL_NETWORK"` (or `"IN_CLUSTER"`
205+
if restricted to pod-to-pod), even if it is a web
206+
service.
207+
- The position is only `"EXTERNAL"` if the interface
208+
is directly reachable from the public internet.
209+
- If the interface requires physical contact, hardware
210+
interaction (e.g., JTAG, debug probes, chip
211+
decapping), or local wireless proximity (e.g., NFC,
212+
Bluetooth), the position must be
213+
`"PHYSICAL_TEMPORARY"` or `"PHYSICAL_LONG_TERM"`,
214+
regardless of the protocol used.
174215
- **Normalize Free-text:** If the value is present but is
175216
a free-text string that does not exactly match one of
176217
the valid enum values (e.g. legacy phrasings), you
@@ -289,17 +330,29 @@ Execute the calibration as follows:
289330

290331
3. **Critical Sanity Triage (Downgrading & Capping Findings):** Before
291332
determining the final priority, perform a second-level sanity check on the
292-
quality of the finding, its context, and accumulated evidence. Check if the
293-
`THREAT_MODEL.md` defines any `Calibration Overrides` (e.g., `LIFT_CAP:
294-
PHYSICAL_LONG_TERM`). If an override exists for a finding's position or
295-
component, it takes precedence and lifts the corresponding cap. Otherwise,
296-
the caps and downgrades below override any upgrades calculated in Section 2
297-
(including the Security Control Bypass upgrade), and you **MUST**
298-
force-downgrade or cap the finding's priority and score if it meets any of
299-
the following criteria. **Important: A cap (HIGH or MEDIUM) only limits the
300-
maximum allowed score/priority. It must NOT upgrade a lower score/priority
301-
(e.g., a finding with a score of 5.0 is naturally MEDIUM and must remain
302-
MEDIUM, even if it is subject to a cap at HIGH).**
333+
quality of the finding, its context, and accumulated evidence.
334+
335+
**Core Principle - Marginal Capability:** The final severity and priority of
336+
a finding are strictly bounded by the *marginal capability* gained by the
337+
attacker over their prerequisite position. If the exploit does not grant the
338+
attacker significant new control, access, or capabilities beyond what is
339+
already inherent to their starting position (or already possessed via
340+
legitimate means), the finding must be capped or downgraded. **This
341+
principle applies generally to all findings; the specific rules listed below
342+
are common applications of this principle but are not exhaustive.**
343+
344+
Check if the `THREAT_MODEL.md` defines any `Calibration Overrides` (e.g.,
345+
`LIFT_CAP: PHYSICAL_LONG_TERM`). If an override exists for a finding's
346+
position or component, it takes precedence and lifts the corresponding cap.
347+
Otherwise, the caps and downgrades below (and general applications of the
348+
Marginal Capability principle) override any upgrades calculated in Section 2
349+
(including the Security Control Bypass upgrade). You **MUST** apply the
350+
specific caps and downgrades below, and should also apply the general
351+
principle to cap or downgrade other findings that offer low marginal
352+
capability. **Important: A cap (HIGH or MEDIUM) only limits the maximum
353+
allowed score/priority. It must NOT upgrade a lower score/priority (e.g., a
354+
finding with a score of 5.0 is naturally MEDIUM and must remain MEDIUM, even
355+
if it is subject to a cap at HIGH).**
303356

304357
**Precedence:** Evaluate ALL rules below. If multiple caps apply, the **most
305358
restrictive** wins (Force-LOW > cap-MEDIUM > cap-HIGH). Record every rule
@@ -335,29 +388,41 @@ Execute the calibration as follows:
335388
- **Prerequisite Shell Access (Equivalent Primitives):** The attacker
336389
already possesses local shell access on the target container or host
337390
with the **same or higher** privilege level than the exploit
338-
provides, rendering the gained access redundant (e.g., exploiting a
339-
bug to get a standard user shell when already logged in as a
340-
standard user, or exploiting a local buffer overflow to run commands
341-
as root when already running as root). This does NOT apply to
342-
low-to-high privilege escalation (e.g., standard user to root),
343-
which should cap at MEDIUM.
391+
provides, rendering the gained access redundant under the Principle
392+
of Marginal Capability (e.g., exploiting a bug to get a standard
393+
user shell when already logged in as a standard user, or exploiting
394+
a local buffer overflow to run commands as root when already running
395+
as root). This does NOT apply to low-to-high privilege escalation
396+
(e.g., standard user to root), which should cap at MEDIUM.
344397

345398
- **Physical Long-Term / Laboratory Access:** If the attack requires
346399
long-term physical access to the device or specialized laboratory
347400
equipment (e.g., fault injection, side-channel analysis, chip
348401
decapping). Force-downgrade to **LOW (2.0)** due to the extreme
349402
execution barrier and requirement for physical possession.
350403

404+
- **Trusted-Controller-Mediated Interface (Zero Delta):** If the
405+
vulnerable interface is reachable only from a component that holds
406+
designed-in authoritative control over the target (e.g.,
407+
orchestrator->worker, driver->device firmware, protocol
408+
master->slave, hypervisor->guest, management plane->data plane
409+
node), and the exploit grants **zero marginal capability** (i.e.,
410+
the controller could already achieve the identical effect or level
411+
of compromise via its standard, legitimate interface),
412+
force-downgrade to **LOW (2.0)**. (This generalizes the *Standard
413+
Host-to-Guest Attacks* rule below).
414+
351415
- **Standard Host-to-Guest Attacks:** If the attacker position is
352416
`HOST_SYSTEM` (host hypervisor attacking guest) on standard
353417
deployments (non-Confidential Computing). Force-downgrade to **LOW
354-
(2.0)** (equivalent primitives), as the host OS/hypervisor already
355-
possesses total control over the guest by design. **Default
356-
assumption:** treat as non-Confidential Computing (this rule fires)
357-
UNLESS the Threat Model, code path, or finding description
358-
explicitly names Confidential Computing, guest enclaves, TEE, SEV,
359-
TDX, SGX, or attestation (in which case apply the CC Host Attacks
360-
cap-HIGH rule instead).
418+
(2.0)** as the host OS/hypervisor already possesses total control
419+
over the guest by design, meaning the exploit offers zero marginal
420+
capability over the prerequisite position (equivalent primitives).
421+
**Default assumption:** treat as non-Confidential Computing (this
422+
rule fires) UNLESS the Threat Model, code path, or finding
423+
description explicitly names Confidential Computing, guest enclaves,
424+
TEE, SEV, TDX, SGX, or attestation (in which case apply the CC Host
425+
Attacks cap-HIGH rule instead).
361426

362427
* **Force-Cap to HIGH (Cap at 7.9 / Maximum HIGH Priority):**
363428

@@ -413,23 +478,56 @@ Execute the calibration as follows:
413478
against host-level compromise. (If not a CC deployment, see the
414479
Standard Host-to-Guest Attacks rule under LOW).
415480

481+
- **Trusted-Controller-Mediated Interface (Critical Bypass):** If the
482+
vulnerable interface is reachable only from a designed-in
483+
authoritative controller, and the exploit allows that controller to
484+
bypass target-side **documented security controls** or
485+
**safety-of-life limits** it was designed to respect, cap at **HIGH
486+
(7.9)**. (If the exploit allows lateral reach into a different trust
487+
domain or achieves persistence surviving controller re-provisioning,
488+
do not cap).
489+
416490
* **Force-Cap to MEDIUM (Cap at 5.9 / Maximum MEDIUM Priority):**
417491

418492
- **Local Attack Vector:** Vulnerabilities requiring local shell
419493
access (e.g., local privilege escalation, SUID exploitation) without
420494
VM escape. (Downgrade to LOW/2.0 if it only affects a single user's
421495
isolated data).
422-
- **Intra-Customer / Same-Tenant:** Attacks restricted to the same
423-
tenant boundary the attacker already controls, with no cross-tenant
424-
escalation or host compromise.
496+
- **Self-Contained Blast Radius:** If the maximum impact of the
497+
exploit is confined to resources, data, or execution contexts that
498+
the triggering principal already owns or has full designed-in
499+
authority over — their own account, tenant, project, namespace,
500+
container, VM, device, or single-user installation — and does not
501+
cross any isolation boundary between mutually-distrusting
502+
principals, cap at **MEDIUM (5.9)**.
503+
- The exploit may grant genuinely new capability within that
504+
domain (e.g., API-user -> shell in their own container), but the
505+
deployment's core isolation guarantees to other parties still
506+
hold. This is a blast-radius bound, distinct from the Marginal
507+
Capability principle (which bounds by new capability; this
508+
bounds by who is affected).
509+
- Do **NOT** apply this cap if the exploit:
510+
- reaches another principal's resources (cross-tenant,
511+
cross-user, cross-account),
512+
- touches shared or multi-party infrastructure (shared cache,
513+
shared filesystem, operator control plane, co-tenant
514+
side-channel),
515+
- places the attacker's domain upstream of others (build node,
516+
CI runner, package registry, model-serving host — i.e., a
517+
supply-chain position), or
518+
- persists in a way that survives the principal's own resource
519+
lifecycle and could later affect a different principal
520+
reusing that slot.
425521
- **Rarely Exposed Components:** Findings in components documented as
426522
'rarely exposed' or 'unlikely to be user controlled'.
427523
- **Equivalent Primitives (No Boundary Breach):** The attacker profile
428524
capable of triggering the vulnerability already possesses equivalent
429525
access, privileges, or capabilities (primitives) through standard
430526
system features (e.g., an admin exploiting a bug to download a file
431-
they can already download via the UI). Cap at **MEDIUM (5.9)** to
432-
maintain visibility for defense-in-depth cleanup.
527+
they can already download via the UI). Because this offers low
528+
marginal capability over their prerequisite position, cap at
529+
**MEDIUM (5.9)** to maintain visibility for defense-in-depth
530+
cleanup.
433531
- **Documented Insecure Configurations:** Non-default configurations
434532
that are explicitly documented in public manuals as insecure,
435533
diagnostic-only, or strictly non-production. Cap at **MEDIUM
@@ -446,6 +544,13 @@ Execute the calibration as follows:
446544
(5.9)**, unless the exploit results in escaping the container
447545
boundary (to host node) or cross-tenant escalation.
448546

547+
- **Trusted-Controller-Mediated Interface (Standard Bypass):** If the
548+
vulnerable interface is reachable only from a designed-in
549+
authoritative controller, and the exploit allows that controller to
550+
bypass target-side **standard safety or sanity limits** (but not
551+
critical safety-of-life or documented security controls) it was
552+
expected to respect, cap at **MEDIUM (5.9)**.
553+
449554
4. **Determine Priority:**
450555

451556
- **CRITICAL (8.0 - 10.0):** Immediate action required. Very high hazard

0 commit comments

Comments
 (0)