- #1 Secrets: No hardcoded credentials. HMAC keys loaded from environment variables only.
- #2 Input Validation: All external inputs validated via Pydantic v2 models with
extra='forbid'. - #3 Output Sanitization: Report outputs sanitized before persistence.
- #4 Dependency Pinning:
pyproject.tomlpins all production dependencies. - #5 Logging: No PII logged; structured logging with severity levels.
- #9 Crypto Hygiene: HMAC-SHA256 signing of expert reports using
hmac.compare_digest(). - #10 Timeout: All graph nodes run under
asyncio.timeout(30.0). - #12 Immutable State:
ForensicStateis TypedDict with Pydantic v2extra='forbid'. - #13 Chain of Custody: Evidence hashes (SHA-256) stored with immutable timestamps.
- #14 Anti-SSRF: All external URLs validated against a denylist before any request.
- #15 AST Guardrails Anti-SQLi: SQL queries generated via AST parameterized builders, never string concatenation.
- #16 Human-in-the-Loop: Final verdict requires explicit human approval before persisting the expert report.
- #17 Anti-DoS:
recursion_limit=5enforced at StateGraph level; per-node timeout 30s.
Open a private security advisory via GitHub Security Advisories.