Spaces:
Running on Zero
Running on Zero
| { | |
| "id": "code_security", | |
| "title": "Autonomous Code Security & PR Vulnerability Triage (28 Fields)", | |
| "description": "Automated SAST/DAST static analysis triage evaluating an enterprise pull request containing leaked secrets and injection risks.", | |
| "context": "CI/CD PIPELINE AUDIT #PR-10822\nRepository: payment-gateway-core\nBranch: feature/direct-stripe-integration -> main\nAuthor: external-contractor-92 (First PR submitted)\nDiff Summary: +482 lines, -12 lines in src/services/charge_processor.py and config/aws.env\n\nStatic Scanner Findings:\n1. Hardcoded Plaintext AWS Root Secret: AWS_SECRET_ACCESS_KEY=\"AKIAIOSFODNN7EXAMPLE...\" committed into config/aws.env\n2. Unsanitized SQL Query Concatenation: cursor.execute(f\"SELECT * FROM users WHERE id = '{req.user_id}' AND secret = '{req.token}'\")\n3. Insecure Deserialization: pickle.loads(base64.b64decode(req.headers['X-Payload'])) detected in webhook handler.\n4. Dependency Check: Added vulnerable PyPI package 'requests-oauthlib==0.4.0' with 3 critical CVEs.\n\nDeployment Target: PRODUCTION (us-west-2 Kubernetes Cluster)\nCompliance Scope: SOC2 Type II, PCI-DSS Level 1, HIPAA\nSecurity Gate Status: FAILED_BLOCKING", | |
| "schema": { | |
| "is_vulnerability": { | |
| "type": "boolean", | |
| "description": "Whether pull request introduces severe security vulnerabilities" | |
| }, | |
| "primary_cwe": { | |
| "type": "enum", | |
| "description": "Primary vulnerability classification", | |
| "choices": [ | |
| "CWE_89_SQL_INJECTION", | |
| "CWE_798_HARDCODED_CREDENTIALS", | |
| "CWE_502_DESERIALIZATION", | |
| "CWE_20_IMPROPER_INPUT" | |
| ] | |
| }, | |
| "secondary_cwe": { | |
| "type": "enum", | |
| "description": "Secondary vulnerability indicator", | |
| "choices": [ | |
| "CWE_798_HARDCODED_CREDENTIALS", | |
| "CWE_1104_OUTDATED_COMPONENTS", | |
| "CWE_200_INFO_EXPOSURE", | |
| "NONE" | |
| ] | |
| }, | |
| "severity_level": { | |
| "type": "enum", | |
| "description": "Combined security severity tier", | |
| "choices": [ | |
| "CRITICAL", | |
| "HIGH", | |
| "MEDIUM", | |
| "LOW" | |
| ] | |
| }, | |
| "block_pull_request": { | |
| "type": "boolean", | |
| "description": "Whether CI/CD merge should be immediately blocked" | |
| }, | |
| "quarantine_branch": { | |
| "type": "boolean", | |
| "description": "Whether git branch should be locked and quarantined" | |
| }, | |
| "credential_revocation_required": { | |
| "type": "boolean", | |
| "description": "Whether AWS IAM credentials must be revoked immediately" | |
| }, | |
| "requires_security_lead_signoff": { | |
| "type": "boolean", | |
| "description": "Whether AppSec lead signature is required to unblock" | |
| }, | |
| "exploitability_in_production": { | |
| "type": "enum", | |
| "description": "Production exploitability ease", | |
| "choices": [ | |
| "REMOTE_UNAUTHENTICATED", | |
| "AUTHENTICATED_USER", | |
| "INTERNAL_NETWORK_ONLY", | |
| "THEORETICAL" | |
| ] | |
| }, | |
| "blast_radius": { | |
| "type": "enum", | |
| "description": "Potential system impact scope", | |
| "choices": [ | |
| "FULL_AWS_ACCOUNT", | |
| "DATABASE_COMPROMISE", | |
| "CONTAINER_LOCAL", | |
| "NONE" | |
| ] | |
| }, | |
| "auto_generate_fix": { | |
| "type": "boolean", | |
| "description": "Whether automated remediation patch should be PRed" | |
| }, | |
| "remediation_effort": { | |
| "type": "enum", | |
| "description": "Estimated fix complexity", | |
| "choices": [ | |
| "TRIVIAL_SECRETS_ROTATION", | |
| "PARAMETRIZED_SQL_REFACTOR", | |
| "MAJOR_ARCHITECTURE_CHANGE" | |
| ] | |
| }, | |
| "pci_dss_impact": { | |
| "type": "boolean", | |
| "description": "Whether findings trigger PCI-DSS compliance breach" | |
| }, | |
| "soc2_audit_flag": { | |
| "type": "boolean", | |
| "description": "Whether finding must be logged for annual SOC2 audit" | |
| }, | |
| "hipaa_exposure_risk": { | |
| "type": "boolean", | |
| "description": "Whether patient ePHI data is exposed" | |
| }, | |
| "secret_type_detected": { | |
| "type": "enum", | |
| "description": "Specific secret credential leaked", | |
| "choices": [ | |
| "AWS_ROOT_KEY", | |
| "STRIPE_API_KEY", | |
| "DATABASE_PASSWORD", | |
| "NONE" | |
| ] | |
| }, | |
| "target_environment": { | |
| "type": "enum", | |
| "description": "Destination deployment environment", | |
| "choices": [ | |
| "PRODUCTION_CLUSTER", | |
| "STAGING_ENVIRONMENT", | |
| "LOCAL_DEV" | |
| ] | |
| }, | |
| "notify_ciso": { | |
| "type": "boolean", | |
| "description": "Whether CISO must be paged on mobile" | |
| }, | |
| "requires_immediate_patch": { | |
| "type": "boolean", | |
| "description": "Whether zero-day emergency patch window applies" | |
| }, | |
| "jira_ticket_priority": { | |
| "type": "enum", | |
| "description": "Jira security queue priority", | |
| "choices": [ | |
| "P0_BLOCKER", | |
| "P1_CRITICAL", | |
| "P2_MAJOR", | |
| "P3_MINOR" | |
| ] | |
| }, | |
| "assigned_team": { | |
| "type": "enum", | |
| "description": "Primary team responsible for remediation", | |
| "choices": [ | |
| "APP_SEC_TEAM", | |
| "INFRA_CLOUD_SEC", | |
| "CORE_BACKEND", | |
| "DEVOPS_PLATFORM" | |
| ] | |
| }, | |
| "false_positive_risk": { | |
| "type": "enum", | |
| "description": "Likelihood of false positive scan finding", | |
| "choices": [ | |
| "ALMOST_ZERO", | |
| "LOW", | |
| "MODERATE", | |
| "HIGH" | |
| ] | |
| }, | |
| "public_cve_match": { | |
| "type": "boolean", | |
| "description": "Whether findings match known public CVE databases" | |
| }, | |
| "auto_merge_allowed": { | |
| "type": "boolean", | |
| "description": "Whether branch can merge under any circumstance" | |
| }, | |
| "container_escape_risk": { | |
| "type": "boolean", | |
| "description": "Whether vulnerability allows Docker/Kubernetes container breakout" | |
| }, | |
| "data_exfiltration_risk": { | |
| "type": "enum", | |
| "description": "Risk of bulk sensitive data theft", | |
| "choices": [ | |
| "CATASTROPHIC", | |
| "HIGH", | |
| "MODERATE", | |
| "NEGLIGIBLE" | |
| ] | |
| }, | |
| "author_trust_score": { | |
| "type": "enum", | |
| "description": "Author risk profile evaluation", | |
| "choices": [ | |
| "UNTRUSTED_EXTERNAL", | |
| "NEW_EMPLOYEE", | |
| "VERIFIED_STAFF", | |
| "CORE_MAINTAINER" | |
| ] | |
| }, | |
| "security_gate_status": { | |
| "type": "enum", | |
| "description": "Final policy engine disposition", | |
| "choices": [ | |
| "FAILED_BLOCKING", | |
| "WARNING_OVERRIDABLE", | |
| "PASSED" | |
| ] | |
| } | |
| } | |
| } |