Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

1.7 KiB

Trivy Image Scan Report Template

Scan Information

Field Value
Image
Tag/Digest
Scan Date
Trivy Version
DB Version
Scanners Used vuln / misconfig / secret / license

Vulnerability Summary

Severity Count Threshold Status
CRITICAL 0 PASS/FAIL
HIGH 5 PASS/FAIL
MEDIUM 20 PASS/FAIL
LOW N/A INFO
UNKNOWN N/A INFO

Critical Findings

CVE ID Package Installed Fixed CVSS Description

High Findings

CVE ID Package Installed Fixed CVSS Description

Secrets Detected

Rule ID Category Severity File Match (redacted)

Misconfigurations

ID Type Severity Title Resolution

SBOM Summary

Package Type Count
OS packages
Python packages
Node.js packages
Go modules
Java libraries

Policy Decision

  • APPROVED for deployment
  • BLOCKED - requires remediation
  • EXCEPTION GRANTED (see risk acceptance below)

Risk Acceptance (if applicable)

CVE ID Justification Expiry Date Approved By

Remediation Actions

Priority CVE/Finding Action Owner ETA
P1
P2