Skip to content

Security: cibi-dev/langgraph-forensic-investigator

Security

SECURITY.md

Security Policy — langgraph-forensic-investigator

Standards Applied (SECURITY.md Canonical #1–17)

Base Controls (#1–5)

  • #1 Secrets: No hardcoded credentials. HMAC keys loaded from environment variables only.
  • #2 Input Validation: All external inputs validated via Pydantic v2 models with extra='forbid'.
  • #3 Output Sanitization: Report outputs sanitized before persistence.
  • #4 Dependency Pinning: pyproject.toml pins all production dependencies.
  • #5 Logging: No PII logged; structured logging with severity levels.

Phase 2 Controls (#6–13)

  • #9 Crypto Hygiene: HMAC-SHA256 signing of expert reports using hmac.compare_digest().
  • #10 Timeout: All graph nodes run under asyncio.timeout(30.0).
  • #12 Immutable State: ForensicState is TypedDict with Pydantic v2 extra='forbid'.
  • #13 Chain of Custody: Evidence hashes (SHA-256) stored with immutable timestamps.

AI Agentic Controls (#14–17)

  • #14 Anti-SSRF: All external URLs validated against a denylist before any request.
  • #15 AST Guardrails Anti-SQLi: SQL queries generated via AST parameterized builders, never string concatenation.
  • #16 Human-in-the-Loop: Final verdict requires explicit human approval before persisting the expert report.
  • #17 Anti-DoS: recursion_limit=5 enforced at StateGraph level; per-node timeout 30s.

Reporting Vulnerabilities

Open a private security advisory via GitHub Security Advisories.

There aren't any published security advisories