| Quarantine pipeline |
tests/test_quarantine_pipeline.py |
Python |
51 |
7-stage scanning, provenance, pass/fail logic, malformed input handling, and YARA behavior |
| PII stripping |
tests/test_search.py |
Python |
37 file total |
Email, phone, SSN, address redaction from search queries |
| Injection detection |
tests/test_search.py |
Python |
37 file total |
Prompt injection, command injection, query sanitization |
| Memory protection |
tests/test_memory_protection.py |
Python |
33 |
Swap encryption, zswap disabling, core dump prevention, mlock enforcement, TEE detection |
| Traffic analysis resistance |
tests/test_traffic_analysis.py |
Python |
41 |
Packet padding, timing jitter, dummy traffic, traffic shaping |
| Differential privacy |
tests/test_differential_privacy.py |
Python |
37 |
Noise injection, epsilon/delta budgets, query indistinguishability |
| Clipboard isolation |
tests/test_clipboard_isolation.py |
Python |
19 |
Clipboard access controls, paste sanitization, cross-context isolation |
| Canary/tripwire system |
tests/test_canary_tripwire.py |
Python |
49 |
Token placement, filesystem tripwires, tamper detection, alerting |
| Emergency containment |
tests/test_emergency_wipe.py |
Python |
20 |
Three-level panic escalation, fail-closed vault handling, and recovery boundaries |
| Update verification |
tests/test_update_rollback.py |
Python |
80 |
Signature verification, rollback triggers, version pinning, recovery |
| Vault auto-lock |
tests/test_vault_watchdog.py |
Python |
32 |
Idle detection, exact mount identity, local-console lock/unlock, and web-secret rejection |
| Web UI security |
tests/test_ui.py, tests/test_ui_cookies.py, tests/test_ui_file_handling.py |
Python |
139 total |
Route protection, input validation, exact control credentials, session-bound generation readiness, CSP/cookie headers, setup completion, upload/path handling |
| Tool firewall |
services/tool-firewall/*_test.go |
Go |
32 |
Default-deny typed-argument policy, nested blocklists and path constraints, strict request decoding, audit redaction and file-identity checks, and fail-closed allowed decisions |
| Airlock |
services/airlock/*_test.go |
Go |
27 |
Request sanitization, policy enforcement, disabled-by-default |
| Trusted registry |
services/registry/*_test.go |
Go |
36 |
Hash pinning, cosign verification, model fetch authorization |
| GPU integrity watch |
services/gpu-integrity-watch/*_test.go |
Go |
63 |
GPU probe scoring, baseline verification, degradation actions, daemon mode, driver fingerprint, device allowlist, attestor/incident integration |
| MCP firewall |
services/mcp-firewall/*_test.go |
Go |
71 |
MCP tool call policy, default-deny, input redaction, taint tracking, adversarial coverage |
| Policy engine |
services/policy-engine/*_test.go |
Go |
45 |
Unified decisions across 6 domains, evidence provenance, auth |
| Runtime attestor |
services/runtime-attestor/*_test.go |
Go |
64 |
TPM2 quote verification, HMAC bundles, state machine, startup gating, service digest verification |
| Integrity monitor |
services/integrity-monitor/*_test.go |
Go |
54 |
Baseline computation, continuous scanning, violation detection, state machine, model/binary/policy watching |
| Incident recorder |
services/incident-recorder/*_test.go |
Go |
108 |
Incident creation, auto-containment, lifecycle, severity ranking, policy loading, recovery and forensic export |
| Sandbox UI ingress |
services/ui-ingress/*_test.go |
Go |
6 |
Uncredentialed fixed routes, bounded relaying, dual UI/controller health, current protocol identity, and fail-closed upstream errors |
| Sandbox host controller |
tests/test_sandbox_control_server.py |
Python |
70 |
Exact high-entropy signing keys, request HMACs, restart-persistent nonce replay protection, token-nondisclosing protocol probes, session/profile-bound state proofs, bounded HTTP concurrency, manifest-backed generation/profile reads, pinned runtime/safe host binds, cross-platform process-tree cancellation, and verified shutdown |
| Podman control-network anchor |
tests/test_podman_anchor.py |
Python |
5 |
Exact image/identity hardening, project-only gateway lifecycle, stopped and orphan recovery, and owner-only state |
| Agent verified supervisor + HSM keys |
tests/test_agent.py |
Python |
191 |
HMAC-SHA256 token signing, nonce replay protection, expiry, tamper detection, two-phase approval, policy evidence, fail-closed tool-firewall responses, keystore abstraction (software/TPM2/PKCS11), key rotation, key derivation |
| Hardware qualification evidence |
tests/test_hardware_qualification.py |
Python |
6 |
Recursive identifier redaction, allowlisted host evidence, scoped SELinux and Podman security state, owner-only atomic reports, and explicit non-certification |
| CI app-security lint |
.github/scripts/check-hadolint.sh, .github/scripts/run-semgrep.sh |
Shell / Semgrep |
CI gate |
Containerfile/Dockerfile linting and repo-owned Semgrep security rules |