Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.9 KiB

RESTler API Fuzzing — API Reference

Installation

git clone https://github.com/microsoft/restler-fuzzer.git
python3 ./build-restler.py --dest_dir /opt/restler

RESTler CLI Commands

Command Description
Restler compile --api_spec <spec> Compile OpenAPI spec to fuzzing grammar
Restler test --grammar_file <g> Smoke test — validate endpoint reachability
Restler fuzz-lean --grammar_file <g> Quick fuzz — one pass with all checkers
Restler fuzz --grammar_file <g> Full fuzz — extended fuzzing campaign

Key CLI Flags

Flag Description
--grammar_file Path to compiled grammar.py
--dictionary_file Custom fuzzing dictionary (dict.json)
--settings Engine settings JSON file
--target_ip Target API hostname or IP
--target_port Target API port
--time_budget Max hours to run (fuzz/fuzz-lean)
--enable_checkers Space-separated checker names
--no_ssl Disable TLS verification

Security Checkers

Checker Detects
UseAfterFree Accessing deleted resources
NamespaceRule Cross-tenant data access
ResourceHierarchy Wrong parent resource ID access
LeakageRule Sensitive data in error responses
InvalidDynamicObject Malformed object ID handling
PayloadBody Request body injection flaws

Output Directory Structure

Path Contents
ResponseBuckets/runSummary.json Aggregated run statistics
bug_buckets/ Individual bug report files
Compile/grammar.py Generated fuzzing grammar
Compile/dict.json Fuzzing dictionary

External References