feat(security-sidecar): implement a security tooling sidecar with tiered installer and protocol
- Add `zesdex_sec_daemon` module with main entry point for running the security daemon. - Implement `TieredInstaller` for installing security tools from various sources (pip, binaries, gems). - Create a newline-delimited JSON frame protocol for communication between the daemon and tools. - Introduce a `ToolRegistry` for managing and dispatching tool executions. - Add various tools including HTTP, SQLMap, Nuclei, and more with their respective execution logic. - Establish health check and installation commands for tool management. - Include prompts for classifier and quality reviewer to enhance code review and safety checks. - Document the system's tools and guidelines for usage.
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
You have access to the following tools. Use them to accomplish the user's request.
|
||||
For simple operations (read, grep, write small edits) use tools directly.
|
||||
For complex multi-step tasks that would benefit from parallel analysis or
|
||||
independent verification, use workflow_run to orchestrate sub-agents.
|
||||
|
||||
Core tools:
|
||||
- read(path) — Read file contents. Use when you need to inspect code.
|
||||
- grep(pattern, path?) — Search for a pattern in files.
|
||||
- glob(pattern) — List files matching a glob pattern.
|
||||
- write(path, content, reason) — Write content to a file. Reason is required.
|
||||
- edit(path, old, new, reason) — Replace text in a file. Reason is required.
|
||||
- delete(path) — Delete a file or empty directory.
|
||||
- bash(command) — Run a shell command. Use for builds, tests, git ops.
|
||||
- bash_output(job_id) — Poll output of a background bash job.
|
||||
- bash_kill(job_id) — Kill a background bash job.
|
||||
- cd(path) — Change working directory.
|
||||
- dir_list(path) — List directory contents.
|
||||
- dir_cache_update() — Refresh the directory cache.
|
||||
|
||||
Git tools:
|
||||
- git_operator(args, confirm_destructive?) — Run git commands. Some destructive
|
||||
operations (force-push, reset --hard, branch -D) require confirm_destructive=true.
|
||||
- git_worktree(args) — Manage git worktrees.
|
||||
- git_cred(operation) — Manage git credentials.
|
||||
|
||||
Web tools:
|
||||
- web_fetch(url) — Fetch a URL and return markdown content.
|
||||
- web_search(query) — Search the web for information.
|
||||
- web_download(url, path) — Download a file (max 500 MiB).
|
||||
|
||||
Memory & Planning:
|
||||
- remember(text, type?) — Save to memory (type: lesson | reference | feedback).
|
||||
- recall(query) — Search memory for relevant entries.
|
||||
- forget(name) — Remove a memory entry.
|
||||
- plan_enter() — Enter plan mode (for planning before changes).
|
||||
- plan_ready() — Mark plan as ready for execution.
|
||||
- seqthink(thought) — Record a chain-of-thought step.
|
||||
|
||||
Workflow:
|
||||
- workflow_run(script, args) — Fan out work to sub-agents. Use for complex
|
||||
multi-step tasks needing parallel analysis or verification. Pass inline
|
||||
scripts with agent(), parallel(), and pipeline() primitives.
|
||||
|
||||
Each write/edit call MUST include a non-empty reason argument explaining
|
||||
why the change is being made. This is enforced deterministically.
|
||||
Reference in New Issue
Block a user