Whitehack — six separate practices

AgentTool can produce a redacted, crypto-aware runner-local advisory from one exact, pinned honesty linter, offer its minimized observations as unaccepted local Castle gate candidates, and separately explain caller-presented signed Agent Wallet records. A sixth, explicit local bridge can encrypt one exact public-minimal Whitehack 0.9 capsule for one recipient and place its ciphertext in a caller-selected S3-compatible bucket. It does not host an API, authorize execution or target testing, certify software, or turn a finding into permission. The separate Tax Whitehack editorial game is not a security tool.

The six boundaries

SHIPPED · ADVISORY

1. Honesty linter

AgentTool installs the public @agenttool/whitehack-scan@0.8.1 package from an exact npm 11.17.0 lock. Its source is pinned to the reviewed fdd2260efd7a… revision and the versioned exact whitehack-v0.8.1 release. Its 47 text/regex checks look for common state, failure, transparency, API, Solidity, crypto, network, WiFi, and Bluetooth lies.

The shared release artifact is agenttool-whitehack-scan-0.8.1.tgz, 79,779 bytes, with SHA-256 f02079aa5ee38cca3522141da012f1fbe2c3f3399c29710c0692a8f78fc24df8.

The AgentTool bridge observes bounded changed production files and emits only file, line, check, confidence, doctrine, and principle. Whitehack 0.8.1 cross-redacts recognized sensitive hits and same-line overlaps, but ordinary findings can still include source; AgentTool independently drops every raw snippet, title, and message from its report.

IMPLEMENTED · LOCAL OFFER

2. Castle gate intake

bin/agenttool-castle-whitehack-intake.ts reads one explicit closed advisory and emits minimized, unaccepted, local-private agenttool-castle-whitehack-intake/v1 candidates to stdout. File labels and lines are omitted by default.

It does not run Whitehack, open or write a Castle, infer Castle confidence, create a stone or friction, run a trial, choose a room, remediate, authorize, commit, publish, spawn, or use the network.

SHIPPED · LOCAL UNDERSTANDING

3. Wallet understanding

bin/whitehack-wallet-understanding.ts verifies caller-presented signed Agent Wallet descriptor, capability, intent, simulation, and optional continuity records. It projects only closed enum assertions and redacted finding metadata into the exact whitehack-understanding/v1 document.

It does not retrieve or custody keys, sign, contact RPC, simulate, broadcast, store records, authorize, prove consent or execution readiness, or add a hosted route. The adapter remains a private local tool, not a new npm package.

IMPLEMENTED · ENCRYPTED EVIDENCE

4. Evidence continuity

bin/agenttool-whitehack-evidence-storage.ts accepts only the exact Whitehack 0.9 public-minimal capsule profile, pads it to one constant 64 KiB authenticated frame, and stores encrypted ADDS objects in one explicit S3-compatible bucket.

It reads the object back and checks exact decrypted bytes before issuing one finite recipient-bound grant. The private receipt is not safe to publish. This is byte continuity at one observed time, not proof of retention, independent replication, truth, authorization, or future availability.

LOCAL · EXPLICIT SCOPE

5. Security research

A separate local workflow may review targets and vulnerability classes explicitly in scope for a named program. Dynamic PoCs run only against a separately controlled loopback Anvil target at a pinned fork block.

Public source, a bounty page, an AgentTool bearer, a marketplace purchase, or payment is not target-owner authorization. There is no live-network test, transaction broadcast, automatic submission, or automatic disclosure path here.

LEGACY · PRIVACY-SENSITIVE

6. Device Inventory

bin/whitehack.py and bin/whitehack2.py are older local macOS inventory scripts. They are not the source linter, not a smart-contract audit, and not a hosted service.

Their output can reveal network, device, user, process, tunnel, model, Keychain-path, LaunchAgent, and service metadata. Keep it local and manually review it before sharing. The explicit store command sends a labels-only aggregate to hosted AgentTool memory. No real-device snapshot is published here.

Crypto awareness, no custody

The 0.8.1 rule pack can point reviewers toward possible embedded key or recovery literals, general-purpose randomness used directly for security material, explicitly static AEAD nonces, signature expressions coerced to accept failure, re-encoded signed-webhook bodies, and signed webhook files with no visible local timestamp comparison or event-id/nonce deduplication guard. Five wallet-focused heuristics add direct signing-secret egress, direct request-to-signing paths, explicit unbounded capability values, automatic transaction-broadcast retries, and maximum fungible-token approvals.

Version 0.8.1 narrows one noisy silent-failure case: numeric identity defaults used in arithmetic or comparison through a non-reassigned binding to a locally constructed in-memory Map. Awaited reads, unknown .get() providers, reassignable or scope-ambiguous bindings, and standalone defaults remain visible. Catch guards now ignore comments and quoted examples without hiding swallowed falsy returns, and multi-line WiFi credential matches report the actual matched line.

This remains bounded text analysis, not proof of runtime object identity. It rejects visible reassignment and direct .get replacement but cannot resolve every alias, computed property, prototype mutation, or defineProperty path.

These are source-text signals. The scanner reads selected checkout bytes from runner storage into process memory, but this path does not decode or validate possible material as a key or recovery phrase, extract or import it into a key store or wallet, or serialize raw matched material into the advisory. It does not connect a wallet, signer, browser provider, RPC endpoint, or chain; query state; construct or sign bytes; submit or simulate a transaction; receive a webhook; install another package; or execute a proof of concept. CI separately installs the one locked scanner package with lifecycle scripts disabled.

It does not prove BIP-39 validity, nonce uniqueness, missing signature verification, domain separation, chain/address binding, displayed intent, key lifecycle, dependency safety, cross-module replay coverage, middleware behavior, retry idempotence, complete capability bounds, approval justification, or cryptographic correctness. A match is a review prompt, not a verdict.

Castle gate intake

This separate source-only local tool turns one closed agenttool-whitehack-advisory/v0.1 report into one agenttool-castle-whitehack-intake/v1 stdout document. It groups serialized findings by exact location while retaining only check, scanner confidence, doctrine, Clear Standard principle, and occurrence count.

bun bin/agenttool-castle-whitehack-intake.ts \
  --input advisory.json > castle-intake.json

Locations remain omitted unless the caller adds --include-locations. Opaque references avoid leaking filename order but are not confidentiality proof. The projector preserves incomplete and truncated source state, and treats producer authenticity, freshness, coverage, causation, exploitability, semantic fit, consent, verification, remediation, and publication as unknown.

A finding can only become an unaccepted gate offer. Gate → stone, finding → friction, friction → expedition, stone → tested, tested → keep, and stone → room each require a separate explicit judgment or recorded trial. Scanner confidence never becomes Castle confidence: every offer remains unset, not-run, and not-evaluated.

The pure core has no filesystem, process, network, clock, Git, or Castle dependency. The CLI adds one bounded nonblocking no-follow input read and stdout; it does not inspect or clear HALT. Publishing this documentation does not create a hosted intake route or release a new npm package.

Local wallet understanding

The separate CLI re-verifies caller-presented signed agent-wallet/0.1 records, derives bounded relationship and policy states, and passes only enum assertions plus six finding fields into Whitehack 0.8.1's createUnderstanding(). Its stdout is the exact deterministic whitehack-understanding/v1 document, not an AgentTool envelope.

Policy fields stay unknown until the descriptor, capability, delegate, chain, source, intent, and simulation bindings for one operation all match. Separately valid but unrelated records cannot create a supported policy slice.

(cd tools/whitehack-advisory \
  && npm ci --ignore-scripts --no-audit --no-fund \
    --registry=https://registry.npmjs.org --userconfig=/dev/null \
  && npm audit signatures \
    --registry=https://registry.npmjs.org --userconfig=/dev/null)
(cd packages/wallet && bun install --frozen-lockfile)

bun bin/whitehack-wallet-understanding.ts \
  --input request.json > understanding.json

--input - reads stdin. A request contains exactly document_type, findings, records, and host_assertions:

{
  "document_type": "agenttool-whitehack-wallet-input/v1",
  "findings": [],
  "records": {
    "descriptor": null,
    "capability": null,
    "intent": null,
    "simulation": null,
    "continuity_events": []
  },
  "host_assertions": {
    "evaluated_at": null,
    "usage": null,
    "signer_description": null
  }
}

The all-absent request is valid and intentionally indeterminate. Nullable record fields accept complete signed Agent Wallet records. Optional host assertions can carry an RFC3339-millisecond evaluation time; revocation nonce, intent count, per-asset spent amounts, and authenticated distinct approval count; and a closed non-exportable signer description. They remain caller assertions, not independently observed facts.

The result contains no wallet or operation IDs, accounts, assets, keys, signatures, payloads, purpose/reason text, timestamps, or provider metadata. It retains only finding file · line · check · confidence · doctrine · principle; file remains an untrusted caller label with unknown sensitivity. Finding provenance and coverage, adapter trust, payload semantics, freshness, subject binding, current continuity, durable usage/reservation, approval authenticity, consent, custody truth, live-chain state, and signing/broadcast outcome remain explicit unknowns. Execution readiness is always indeterminate.

complete: true means only that the bounded transformation completed. It does not mean an operation is complete, current, approved, authorized, consented to, safe, or ready to sign or execute. The private local adapter is not a new npm package or hosted route.

Encrypted evidence continuity

Whitehack 0.9 adds the exact whitehack-evidence-capsule/v1 public-minimal format. It carries aggregate counts across the scanner's 47 checks without target, path, line, source, message, snippet, scope, or caller text. AgentTool's separate bridge validates that closed profile, canonicalizes it, frames it to a constant size, encrypts it through ADDS, and writes only ciphertext plus signed control documents to one explicit S3-compatible provider.

bun bin/agenttool-whitehack-evidence-storage.ts store \
  --input envelope.json \
  --s3-endpoint https://objects.example.test/evidence-bucket \
  --s3-region auto \
  --s3-prefix whitehack/capsules \
  --output private-receipt.json

bun bin/agenttool-whitehack-evidence-storage.ts retrieve \
  --input private-receipt.json \
  --s3-endpoint https://objects.example.test/evidence-bucket \
  --s3-region auto \
  --s3-prefix whitehack/capsules \
  --output recovered-capsule.json

Before provider access, store reserves its receipt as a new exclusive, final-component-no-follow 0600 regular file. It never overwrites. Credentials and the retrieval private key use fixed environment names rather than command-line flags. The bridge reads the remote object back, verifies its CIDs, decrypts it, and compares the exact frame before issuing one finite recipient-bound grant. Each provider call has a five-second deadline and no automatic retry.

The adapter supports the bounded GET/PUT subset used here and signs requests with AWS Signature Version 4. Cloudflare R2, Backblaze B2, Filebase, and a caller-operated MinIO endpoint can expose compatible S3 APIs, but their account, region, endpoint, and lifecycle rules remain provider configuration. AgentTool does not enable an account, accept terms, create a bucket, buy storage, or discover credentials. Free-tier allowances are mutable policy, not part of this protocol.

The endpoint is trusted configuration, not an SSRF sandbox. The provider observes credential identity, CIDs, constant object sizes, timing, and access patterns. Expiry is a conforming-client policy check, not cryptographic revocation: a recipient can retain disclosed key material or plaintext. A successful readback proves only the exact bytes observed then—not future retention, independent replication, deletion, availability, truth, or authorization.

The CI advisory

Pull requests, merge-queue groups, and pushes to main run on GitHub-hosted Actions. They use npm ci --ignore-scripts in a private tool directory with an isolated user config and explicit public registry, verify the registry signature and SLSA attestation, and require the exact package URL and SHA-512 integrity. The bridge then checks the lock topology, package identity, zero runtime dependencies, no install/publish/version lifecycle hooks, contained real paths, pure scanText() export, and 47-check manifest. It refuses a mismatched scanner or tracked-dirty AgentTool checkout. It considers only supported changed regular files and excludes hidden paths, tests, fixtures, examples, reports, generated output, dependencies, and symlinks.

limits
  changed paths     2,000 / 256 KiB diff data
  path bytes        1,024; controls and bidi refused
  files             200
  bytes per file    512 KiB
  lines per file    10,000
  total bytes       8 MiB
  total findings    5,000
  reported details  200 (exact aggregate count retained)

errors              mark the advisory incomplete and fail its job
findings            advisory only in this first slice

Report shape: agenttool-whitehack-advisory/v0.1. The report retains source revision fdd2260efd7a11e5d52c12c53d8016d1f5e7d23a and version; the npm lock integrity stays an execution-input gate rather than a new report field. The runner has ordinary caller file permissions; these input bounds are not a process, filesystem, or network sandbox.

The GitHub job summary adds a separate bounded Attention view without changing that JSON. It groups serialized redacted findings by exact file + line; each distinct check + confidence signal keeps an occurrence count. A card renders only those redacted location and signal fields, an observational relevance label, and a stable question derived solely from validated public check tokens. It renders no scanner snippet, message, title, captured error, or raw patch text.

For a modified text path with a parseable UTF-8 zero-context diff, changed line means the finding's HEAD line is inside an exact base-to-head new-side hunk; unchanged line in changed file means it is outside every such hunk. Additions, renames, binary or type-changed paths, unparseable diffs, and classifications after a diff-byte or hunk bound is exhausted are unknown. These labels are observational and non-causal: none says the change introduced or caused a finding. The card presentation may truncate at its own bound; JSON v0.1 and its exact aggregate count stay unchanged.

The report is redacted coordination metadata, not automatically private metadata. File and line can still point to a possible weakness, and CI logs may be public. A finding can be anywhere in a changed file; the advisory does not claim the change introduced it.

Use the public package

Agents and humans can install the same exact local scanner directly. Its CLI and JavaScript API inspect caller-supplied local input; installing it does not create an AgentTool account, hosted scan route, wallet, or authority to test another system.

npm install --save-exact @agenttool/whitehack-scan@0.9.0

import { scanText } from '@agenttool/whitehack-scan/core'

const findings = scanText(source, { file: 'src/example.ts' })

npm is a convenient public mirror. Whitehack 0.9 retains the scanner and adds the evidence-capsule parser and CLI; AgentTool's CI advisory remains independently locked to reviewed 0.8.1 bytes. The exact 0.9 LOVE manifest records the 87,196-byte artifact, SHA-256 b7d004947bc3c7619daa38f002d9ddde731e2865644af0d0e609c8dd86528d3c, source revision, and replaceable mirrors. The npm publication additionally carries registry integrity and SLSA provenance.

Evidence stays local first

Raw source, PoCs, traces, private scope material, and undisclosed findings must not be sent to public CI, wakes, traces, listings, or docs. The current bridge omits snippets and scanner messages from its report; that is not a universal guarantee for future tools or operators. Already-created evidence can be collected explicitly into @agenttool/data as local immutable content-addressed records, shared as a recipient-encrypted ADDS bundle, or—only for the exact public-minimal Whitehack 0.9 capsule—sent through the explicit S3-compatible bridge above.

Those mechanisms have narrower meanings: the local data node does not encrypt its blob/FTS storage or establish authorization, and ADDS does not prove that a finding is true. A marketplace invocation can coordinate work and settlement; it cannot grant assessment scope or certify quality.

The detailed implementation and future whitehack-scope/run/finding/disclosure evidence profiles live in the Whitehack doctrine.

Whitehack 0.9 npm → Exact 0.9 release → Local packages → Agent data → ❤️ Love →