Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.1 KiB

Standards - Semgrep Custom SAST Rules

OWASP Top 10 (2021) Coverage

Category Semgrep Detection
A01 Broken Access Control Authorization bypass patterns
A02 Cryptographic Failures Weak crypto, hardcoded secrets
A03 Injection SQL, XSS, command injection (taint mode)
A04 Insecure Design Missing input validation
A05 Security Misconfiguration Debug mode, insecure defaults
A06 Vulnerable Components Deprecated API usage
A07 Auth Failures JWT misconfig, session issues
A08 Software/Data Integrity Deserialization, unsigned data
A09 Logging Failures Missing audit logging
A10 SSRF Server-side request forgery (taint mode)

CWE Coverage

Common CWEs detectable via Semgrep custom rules: CWE-79 (XSS), CWE-89 (SQLi), CWE-798 (Hardcoded Credentials), CWE-330 (Insecure Random), CWE-502 (Deserialization), CWE-918 (SSRF)

NIST SP 800-53 Rev 5

  • SA-11: Developer Security Testing
  • SA-15: Development Process, Standards, and Tools

Compliance

  • PCI DSS v4.0 Req 6.3.2: Secure development with automated tools
  • SOC 2 CC8.1: Change management with code scanning