Repoint every remaining literal `.specify/...` / `docs/input` reference to the real package/domain location and delete all compat symlinks. The harness now runs purely via packages/casan-harness/... with no .specify facade; .specify holds ONLY runtime state (logs/, agentops/alerts.log, level5/central-governance). Refs fixed (Phase 0.5 only caught `$VAR/.specify/` — these were bare/`__file__`/literal): - secrets-scan.sh: scan-target excludes -> packages/casan-harness/... (+ apps/okr/domain/corpus) - loop_common.py: loop-policy.yaml -> harness config (package-relative) - evidence-pack-build.py: judge-gate test + traceability-matrix.py -> harness/sibling - phase10-traceability: REQ -> $CASAN_DOMAIN_ROOT/input - run-casan-pipeline.mjs: model-fallback/drift-detect/rollback-manager -> HARNESS_BASH, golden -> GOLDEN_PLAN (apps/okr/domain), with .specify/logs state kept - casan-step.mjs: requirement fallback restored to docs/input for hermetic sandboxes - descriptive config (tool-registry/harness-package/drift-policy/hallucination/risk-registry/ loop-policy.schema + docstrings) repointed for accuracy - policy-bundle.yaml: 8 policy paths -> packages/casan-harness/...; manifest regenerated + re-signed (POLICY_HASHES_VALID files=8, POLICY_SIGNATURE_VALID) Removed 22 .specify code/config symlinks + docs/input symlink. Full gate via packages path, NO facade: PASS=64 FAIL=0 SKIP=3. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
98 lines
2.0 KiB
YAML
98 lines
2.0 KiB
YAML
version: 1.0
|
|
description: AI Risk Registry (Governance + Security Mapping)
|
|
|
|
risks:
|
|
|
|
- id: RISK-001
|
|
name: Prompt Injection
|
|
category: security
|
|
severity: high
|
|
likelihood: high
|
|
impact: high
|
|
detection:
|
|
source: prompt-filter
|
|
mitigation:
|
|
- block malicious pattern
|
|
- validate input
|
|
owner: security_team
|
|
|
|
- id: RISK-002
|
|
name: Data Leakage
|
|
category: data
|
|
severity: high
|
|
likelihood: medium
|
|
impact: high
|
|
detection:
|
|
source: output-policy
|
|
mitigation:
|
|
- output filtering
|
|
- redact sensitive data
|
|
owner: ai_team
|
|
|
|
- id: RISK-003
|
|
name: PII Exposure
|
|
category: privacy
|
|
severity: high
|
|
likelihood: medium
|
|
impact: high
|
|
detection:
|
|
source: pii-rules
|
|
mitigation:
|
|
- mask PII
|
|
- block if critical
|
|
owner: compliance_team
|
|
|
|
- id: RISK-004
|
|
name: Hallucination Output
|
|
category: quality
|
|
severity: medium
|
|
likelihood: high
|
|
impact: medium
|
|
detection:
|
|
source: evaluation-harness
|
|
mitigation:
|
|
- flag uncertain output
|
|
- human review
|
|
owner: ai_team
|
|
|
|
- id: RISK-005
|
|
name: Unauthorized Tool Usage
|
|
category: security
|
|
severity: high
|
|
likelihood: low
|
|
impact: high
|
|
detection:
|
|
source: tool-harness
|
|
mitigation:
|
|
- whitelist tools
|
|
- enforce permission
|
|
owner: platform_team
|
|
|
|
risk_levels:
|
|
|
|
high:
|
|
action: require_approval
|
|
|
|
medium:
|
|
action: log_and_monitor
|
|
|
|
low:
|
|
action: allow
|
|
|
|
reporting:
|
|
|
|
enabled: true
|
|
frequency: daily
|
|
output: "packages/casan-harness/governance/risk-report.md"
|
|
|
|
review:
|
|
|
|
cycle: weekly
|
|
owner: architect
|
|
|
|
auto_update:
|
|
enabled: true
|
|
trigger: new_action_type_detected
|
|
script: packages/casan-harness/scripts/powershell/update-risk-registry.ps1
|
|
default_risk_for_unknown_action: high
|
|
note: "Unknown actions default to high-risk (fail-secure). Run update-risk-registry.ps1 to register." |