Skip to content

Commit bf29290

Browse files
committed
Add support for binary and firmware analysis
TAG=agy CONV=802ab86c-1a4a-43d0-b4a6-10ff3c9bde3b Change-Id: I3aa6a4c9442a03d16a2ee9830894cdd6cab2cf59
1 parent 5c1171e commit bf29290

6 files changed

Lines changed: 57 additions & 7 deletions

File tree

‎README.md‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,12 @@ for:
3333
* **Data & ML Pipelines**: Auditing training data ingress, model serialization
3434
formats (e.g., Pickle vulnerabilities), or boundary constraints between data
3535
science notebooks and production.
36+
* **Compiled Binaries & Firmware (Gray-Box Auditing)**: Pointing the suite at
37+
compiled release artifacts (using tools like `unblob`, `Ghidra`, `radare2`,
38+
`qemu`, or `unicorn`) without providing source code. The intent of this mode
39+
is to emulate a third-party security researcher, allowing you to see exactly
40+
what vulnerabilities are discoverable by adversaries who only have access to
41+
your released binaries.
3642
* **Custom Test Environments**: Replacing the default container reproduction
3743
stage with isolated VMs, physical hardware testbeds (via USB/serial), or
3844
custom simulators.

‎SCHEMA.md‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,8 @@ evolves sequentially as different skills process it.
1616
- **`description`** (String): Detailed explanation of the flaw and its
1717
mechanism.
1818
- **`code_paths`** (Array of Strings): Exact locations of the flaw (e.g.,
19-
`["src/auth.c:145"]`).
19+
`["src/auth.c:145"]`, binary memory addresses, function offsets, or specific
20+
files within an extracted firmware blob).
2021
- **`impact`** (String): The potential consequence of the vulnerability.
2122
- **`severity`** (Enum): Initial severity estimate (`"CRITICAL"`, `"HIGH"`,
2223
`"MEDIUM"`, `"LOW"`, `"INFO"`).
@@ -55,7 +56,9 @@ evolves sequentially as different skills process it.
5556
- **`patch_status`** (Enum): The outcome of the patching and re-attack
5657
attempts.
5758
- Values: `"VERIFIED_SECURE"`, `"VERIFICATION_FAILED"`, `"ERROR"`
58-
- **`patch_diff`** (String): The unified diff of the verified fix.
59+
- **`patch_diff`** (String): The unified diff of the verified fix, OR for
60+
binary-only targets, a general recommendation on how this could be mitigated
61+
in a production environment.
5962
- **`reattack_status`** (Enum): The outcome of the variant-hunting re-attack
6063
attempt against the patch.
6164
- Values: `"bypassed_patch"`, `"failed_to_bypass"`

‎mantis_meta_agent/SKILL.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,17 @@ resilience, and monitors long-running security pipelines.
2525
Act as a persistent, long-lived supervisor that drives the Mantis defensive
2626
security reviewing pipeline continuously.
2727

28+
> **Target Agnosticism Directive:** The target you are evaluating may be raw
29+
> source code, a compiled binary, a firmware blob, or a live staging/dev
30+
> endpoint. Ground your analysis in whatever format the target is currently in.
31+
> You are authorized and encouraged to use whatever suitable tools are at your
32+
> disposal (e.g., standard Unix tools, `unblob`, `radare2`, `angr`, `objdump`,
33+
> `Ghidra`, `qemu`, `unicorn`, emulator harnesses) to extract, analyze,
34+
> reproduce, and test the findings. If source code is not available, do not
35+
> attempt to force a source-code workflow; adapt and 'do what works' for the
36+
> artifact at hand. Ensure your subagents are aware of the tools available to
37+
> them.
38+
2839
Do not perform the auditing or patching tasks yourself. Instead, delegate them
2940
to specialized subagents to maintain context efficiency and isolate tasks.
3041

‎mantis_patch/SKILL.md‎

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -33,23 +33,38 @@ Execute the patching and verification stage as follows:
3333

3434
2. **Generate and Apply Minimal Patches:** For each reproduced security flaw:
3535

36+
- **Target Agnosticism (Binaries vs Source):** If the target is source
37+
code, proceed with generating and applying a code patch as described
38+
below. If the target is a compiled binary or firmware blob without
39+
source code available, **do not attempt to modify the binary or write
40+
binary patching scripts**. Instead, skip the file
41+
backup/modification/diff steps and generate a general, high-level
42+
recommendation for how this issue could be mitigated in a production
43+
environment without requiring deep technical depth. Output this
44+
mitigation string in place of the `patch_diff` field.
45+
3646
- *Optional Parallel Trajectory Search:* If your framework supports
3747
subagents, you may spawn multiple concurrent subagents to design diverse
3848
patch implementations. Test all generated patches that successfully
3949
secure the code without breaking standard functionality, and select the
4050
*best* patch (e.g., the most minimal, readable, and idiomatic fix)
4151
rather than just the first one that works.
52+
4253
- Read the original flawed file to grasp function dependencies and
4354
structures.
55+
4456
- Design a minimal, correct patch to mitigate the security flaw (e.g.
4557
adding bound checks, validating sizes, inserting NUL-terminators)
4658
without breaking other features.
59+
4760
- **Backup First:** Create a copy of the target file appending `.bak` to
4861
its filename to allow robust recovery in case the patch breaks
4962
compilation or functionality.
63+
5064
- Replace the file content with your generated patched code.
5165

52-
3. **Post-Patch Verification Run:** To confirm the patch works, re-run the
66+
3. **Post-Patch Verification Run:** *(Skip this step for binary-only targets
67+
where no code patch was applied)*. To confirm the patch works, re-run the
5368
reproducer script inside your isolated execution environment. Use the exact
5469
`"repro_file_path"` and `"run_command"` from the reproduction entry to
5570
verify the patch.
@@ -69,9 +84,10 @@ Execute the patching and verification stage as follows:
6984
bug, or if your re-attack successfully bypasses your patch, the patch is
7085
insufficient. Re-evaluate and adapt your fix.
7186

72-
4. **Extract Patch and Restore Codebase:** Do not leave the codebase in an
73-
altered state. Once you have a final outcome (either `VERIFIED_SECURE` or
74-
you have exhausted your retries), you must:
87+
4. **Extract Patch and Restore Codebase:** *(Skip this step for binary-only
88+
targets)*. Do not leave the codebase in an altered state. Once you have a
89+
final outcome (either `VERIFIED_SECURE` or you have exhausted your retries),
90+
you must:
7591

7692
- If successful, generate a unified diff (e.g., `diff -u file.bak file`)
7793
representing your exact changes.

‎mantis_plan/SKILL.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,16 @@ Analyze the repository structure and create a detailed defensive security review
2525
plan that avoids duplication of prior efforts while digging deep into complex
2626
inter-procedural paths and un-scanned code boundaries.
2727

28+
> **Target Agnosticism Directive:** The target you are evaluating may be raw
29+
> source code, a compiled binary, a firmware blob, or a live staging/dev
30+
> endpoint. Ground your planning in whatever format the target is currently in.
31+
> You are authorized and encouraged to use whatever suitable tools are at your
32+
> disposal (e.g., standard Unix tools, `unblob`, `radare2`, `angr`, `objdump`,
33+
> `Ghidra`, `qemu`, `unicorn`) to explore the artifact structure. If source code
34+
> is not available, do not attempt to force a source-code workflow (e.g.
35+
> searching for `.c` or `.py` files); adapt and 'do what works' for the artifact
36+
> at hand.
37+
2838
Execute the planning stage as follows:
2939

3040
1. **Check for Threat Model Context:** Check the knowledge base directory for a

‎mantis_reproduce/SKILL.md‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,11 @@ Execute the reproduction stage under these constraints:
4848
payload (e.g., `crash.payload`) that triggers the target bug. To run your
4949
script or payload, use the execution or containerization tools available in
5050
your environment to execute the code safely. Select the most appropriate
51-
runtime image and flags for the target language.
51+
runtime image and flags for the target. **Execute your reproduction using
52+
the appropriate environment:** If the target is firmware, you may write a
53+
script to boot it via `qemu`, `unicorn`, or Firmadyne. If it's a binary, you
54+
may use dynamic instrumentation or standard execution. Use your best
55+
judgment to construct a working harness for the artifact.
5256

5357
- *Optional Parallel Trajectory Search:* If your environment or agent
5458
framework supports spawning subagents, you can deploy multiple

0 commit comments

Comments
 (0)