AgentTool can produce a redacted, crypto-aware runner-local advisory from
one exact, pinned honesty linter, offer its minimized observations as
unaccepted local Castle gate candidates, and separately explain
caller-presented signed Agent Wallet records. A sixth, explicit local
bridge can encrypt one exact public-minimal Whitehack 0.9 capsule for one
recipient and place its ciphertext in a caller-selected S3-compatible
bucket. It does not host an API, authorize execution or target testing,
certify software, or turn a finding into permission. The separate Tax
Whitehack editorial game is not a security tool.
The six boundaries
SHIPPED · ADVISORY
1. Honesty linter
AgentTool installs the public
@agenttool/whitehack-scan@0.8.1
package from an exact npm 11.17.0 lock. Its source is pinned to the reviewed
fdd2260efd7a…
revision and the versioned exact
whitehack-v0.8.1
release.
Its 47 text/regex checks look for common state, failure,
transparency, API, Solidity, crypto, network, WiFi, and Bluetooth
lies.
The shared release artifact is
agenttool-whitehack-scan-0.8.1.tgz, 79,779 bytes, with
SHA-256
f02079aa5ee38cca3522141da012f1fbe2c3f3399c29710c0692a8f78fc24df8.
The AgentTool bridge observes bounded changed production files and
emits only file, line, check, confidence, doctrine, and principle.
Whitehack 0.8.1 cross-redacts recognized sensitive hits and
same-line overlaps, but ordinary findings can still include source;
AgentTool independently drops every raw snippet, title, and message
from its report.
IMPLEMENTED · LOCAL OFFER
2. Castle gate intake
bin/agenttool-castle-whitehack-intake.ts reads one
explicit closed advisory and emits minimized, unaccepted,
local-private agenttool-castle-whitehack-intake/v1
candidates to stdout. File labels and lines are omitted by default.
It does not run Whitehack, open or write a Castle, infer Castle
confidence, create a stone or friction, run a trial, choose a room,
remediate, authorize, commit, publish, spawn, or use the network.
SHIPPED · LOCAL UNDERSTANDING
3. Wallet understanding
bin/whitehack-wallet-understanding.ts verifies
caller-presented signed Agent Wallet descriptor, capability, intent,
simulation, and optional continuity records. It projects only
closed enum assertions and redacted finding metadata into the exact
whitehack-understanding/v1 document.
It does not retrieve or custody keys, sign, contact RPC, simulate,
broadcast, store records, authorize, prove consent or execution
readiness, or add a hosted route. The adapter remains a private
local tool, not a new npm package.
IMPLEMENTED · ENCRYPTED EVIDENCE
4. Evidence continuity
bin/agenttool-whitehack-evidence-storage.ts accepts
only the exact Whitehack 0.9 public-minimal capsule profile, pads it
to one constant 64 KiB authenticated frame, and stores encrypted
ADDS objects in one explicit S3-compatible bucket.
It reads the object back and checks exact decrypted bytes before
issuing one finite recipient-bound grant. The private receipt is
not safe to publish. This is byte continuity at one observed time,
not proof of retention, independent replication, truth,
authorization, or future availability.
LOCAL · EXPLICIT SCOPE
5. Security research
A separate local workflow may review targets and vulnerability
classes explicitly in scope for a named program. Dynamic PoCs run
only against a separately controlled loopback Anvil target at a
pinned fork block.
Public source, a bounty page, an AgentTool bearer, a marketplace
purchase, or payment is not target-owner authorization. There is no
live-network test, transaction broadcast, automatic submission, or
automatic disclosure path here.
LEGACY · PRIVACY-SENSITIVE
6. Device Inventory
bin/whitehack.py and bin/whitehack2.py are
older local macOS inventory scripts. They are not the source linter,
not a smart-contract audit, and not a hosted service.
Their output can reveal network, device, user, process, tunnel,
model, Keychain-path, LaunchAgent, and service metadata. Keep it
local and manually review it before sharing. The explicit
store command sends a labels-only aggregate to hosted
AgentTool memory. No real-device snapshot is published here.
Crypto awareness, no custody
The 0.8.1 rule pack can point reviewers toward possible embedded key or
recovery literals, general-purpose randomness used directly for
security material, explicitly static AEAD nonces, signature expressions
coerced to accept failure, re-encoded signed-webhook bodies, and signed
webhook files with no visible local timestamp comparison or
event-id/nonce deduplication guard. Five wallet-focused heuristics add
direct signing-secret egress, direct request-to-signing paths, explicit
unbounded capability values, automatic transaction-broadcast retries,
and maximum fungible-token approvals.
Version 0.8.1 narrows one noisy silent-failure case:
numeric identity defaults used in arithmetic or comparison through a
non-reassigned binding to a locally constructed in-memory
Map. Awaited reads, unknown .get() providers,
reassignable or scope-ambiguous bindings, and standalone defaults remain
visible. Catch guards now ignore comments and quoted examples without
hiding swallowed falsy returns, and multi-line WiFi credential matches
report the actual matched line.
This remains bounded text analysis, not proof of runtime object
identity. It rejects visible reassignment and direct
.get replacement but cannot resolve every alias, computed
property, prototype mutation, or defineProperty path.
These are source-text signals. The scanner reads selected checkout
bytes from runner storage into process memory, but this path does not
decode or validate possible material as a key or recovery phrase,
extract or import it into a key store or wallet, or serialize raw
matched material into the advisory. It does not connect a wallet, signer, browser
provider, RPC endpoint, or chain; query state; construct or sign bytes;
submit or simulate a transaction; receive a webhook; install another
package; or execute a proof of concept. CI separately installs the one
locked scanner package with lifecycle scripts disabled.
It does not prove BIP-39 validity, nonce uniqueness, missing signature
verification, domain separation, chain/address binding, displayed
intent, key lifecycle, dependency safety, cross-module replay coverage,
middleware behavior, retry idempotence, complete capability bounds,
approval justification, or cryptographic correctness. A match is a
review prompt, not a verdict.
Castle gate intake
This separate source-only local tool turns one closed
agenttool-whitehack-advisory/v0.1 report into one
agenttool-castle-whitehack-intake/v1 stdout document. It
groups serialized findings by exact location while retaining only
check, scanner confidence, doctrine, Clear Standard principle, and
occurrence count.
bun bin/agenttool-castle-whitehack-intake.ts \
--input advisory.json > castle-intake.json
Locations remain omitted unless the caller adds
--include-locations. Opaque references avoid leaking
filename order but are not confidentiality proof. The projector
preserves incomplete and truncated source state, and treats producer
authenticity, freshness, coverage, causation, exploitability,
semantic fit, consent, verification, remediation, and publication as
unknown.
A finding can only become an unaccepted gate offer. Gate → stone,
finding → friction, friction → expedition, stone → tested, tested →
keep, and stone → room each require a separate explicit judgment or
recorded trial. Scanner confidence never becomes Castle confidence:
every offer remains unset, not-run, and
not-evaluated.
The pure core has no filesystem, process, network, clock, Git, or
Castle dependency. The CLI adds one bounded nonblocking no-follow input
read and stdout; it does not inspect or clear HALT. Publishing this
documentation does not create a hosted intake route or release a new
npm package.
Local wallet understanding
The separate CLI re-verifies caller-presented signed
agent-wallet/0.1 records, derives bounded relationship and
policy states, and passes only enum assertions plus six finding fields
into Whitehack 0.8.1's createUnderstanding(). Its stdout is
the exact deterministic whitehack-understanding/v1
document, not an AgentTool envelope.
Policy fields stay unknown until the descriptor, capability, delegate,
chain, source, intent, and simulation bindings for one operation all
match. Separately valid but unrelated records cannot create a supported
policy slice.
The all-absent request is valid and intentionally indeterminate.
Nullable record fields accept complete signed Agent Wallet records.
Optional host assertions can carry an RFC3339-millisecond evaluation
time; revocation nonce, intent count, per-asset spent amounts, and
authenticated distinct approval count; and a closed non-exportable
signer description. They remain caller assertions, not independently
observed facts.
The result contains no wallet or operation IDs, accounts, assets, keys,
signatures, payloads, purpose/reason text, timestamps, or provider
metadata. It retains only finding
file · line · check · confidence · doctrine · principle;
file remains an untrusted caller label with unknown
sensitivity. Finding provenance and coverage, adapter trust, payload
semantics, freshness, subject binding, current continuity, durable
usage/reservation, approval authenticity, consent, custody truth,
live-chain state, and signing/broadcast outcome remain explicit
unknowns. Execution readiness is always indeterminate.
complete: true means only that the bounded transformation
completed. It does not mean an operation is complete, current,
approved, authorized, consented to, safe, or ready to sign or execute.
The private local adapter is not a new npm package or hosted route.
Encrypted evidence continuity
Whitehack 0.9 adds the exact
whitehack-evidence-capsule/v1 public-minimal format. It
carries aggregate counts across the scanner's 47 checks without target,
path, line, source, message, snippet, scope, or caller text. AgentTool's
separate bridge validates that closed profile, canonicalizes it, frames
it to a constant size, encrypts it through ADDS, and writes only
ciphertext plus signed control documents to one explicit
S3-compatible provider.
bun bin/agenttool-whitehack-evidence-storage.ts store \
--input envelope.json \
--s3-endpoint https://objects.example.test/evidence-bucket \
--s3-region auto \
--s3-prefix whitehack/capsules \
--output private-receipt.json
bun bin/agenttool-whitehack-evidence-storage.ts retrieve \
--input private-receipt.json \
--s3-endpoint https://objects.example.test/evidence-bucket \
--s3-region auto \
--s3-prefix whitehack/capsules \
--output recovered-capsule.json
Before provider access, store reserves its receipt as a
new exclusive, final-component-no-follow 0600 regular
file. It never overwrites. Credentials and the retrieval private key
use fixed environment names rather than command-line flags. The bridge
reads the remote object back, verifies its CIDs, decrypts it, and
compares the exact frame before issuing one finite recipient-bound
grant. Each provider call has a five-second deadline and no automatic
retry.
The adapter supports the bounded GET/PUT subset used here and signs
requests with AWS Signature Version 4.
Cloudflare R2,
Backblaze B2,
Filebase, and a
caller-operated MinIO endpoint can expose compatible S3 APIs, but their
account, region, endpoint, and lifecycle rules remain provider
configuration. AgentTool does not enable an account, accept terms,
create a bucket, buy storage, or discover credentials. Free-tier
allowances are mutable policy, not part of this protocol.
The endpoint is trusted configuration, not an SSRF sandbox. The
provider observes credential identity, CIDs, constant object sizes,
timing, and access patterns. Expiry is a conforming-client policy check,
not cryptographic revocation: a recipient can retain disclosed key
material or plaintext. A successful readback proves only the exact
bytes observed then—not future retention, independent replication,
deletion, availability, truth, or authorization.
The CI advisory
Pull requests, merge-queue groups, and pushes to main run on
GitHub-hosted Actions. They use npm ci --ignore-scripts in a
private tool directory with an isolated user config and explicit public
registry, verify the registry signature and SLSA attestation, and
require the exact package URL and SHA-512 integrity.
The bridge then checks the lock topology, package identity, zero runtime
dependencies, no install/publish/version lifecycle hooks, contained real paths, pure
scanText() export, and 47-check manifest. It refuses a
mismatched scanner or tracked-dirty AgentTool checkout. It considers
only supported changed regular files and excludes hidden paths, tests,
fixtures, examples, reports, generated output, dependencies, and symlinks.
limits
changed paths 2,000 / 256 KiB diff data
path bytes 1,024; controls and bidi refused
files 200
bytes per file 512 KiB
lines per file 10,000
total bytes 8 MiB
total findings 5,000
reported details 200 (exact aggregate count retained)
errors mark the advisory incomplete and fail its job
findings advisory only in this first slice
Report shape: agenttool-whitehack-advisory/v0.1. The report
retains source revision fdd2260efd7a11e5d52c12c53d8016d1f5e7d23a
and version; the npm lock integrity stays an execution-input gate rather
than a new report field. The runner has ordinary caller file permissions;
these input bounds are not a process, filesystem, or network sandbox.
The GitHub job summary adds a separate bounded Attention view without
changing that JSON. It groups serialized redacted findings by exact
file + line; each distinct
check + confidence signal keeps an occurrence count. A card
renders only those redacted location and signal fields, an observational
relevance label, and a stable question derived solely from validated
public check tokens. It renders no scanner snippet, message, title,
captured error, or raw patch text.
For a modified text path with a parseable UTF-8 zero-context diff,
changed line means the finding's HEAD line is inside an
exact base-to-head new-side hunk;
unchanged line in changed file means it is outside every
such hunk. Additions, renames, binary or type-changed paths,
unparseable diffs, and classifications after a diff-byte or hunk bound
is exhausted are unknown. These labels are observational
and non-causal: none says the change introduced or caused a finding.
The card presentation may truncate at its own bound; JSON v0.1 and its
exact aggregate count stay unchanged.
The report is redacted coordination metadata, not automatically private
metadata. File and line can still point to a possible weakness, and CI
logs may be public. A finding can be anywhere in a changed file; the
advisory does not claim the change introduced it.
Use the public package
Agents and humans can install the same exact local scanner directly.
Its CLI and JavaScript API inspect caller-supplied local input; installing
it does not create an AgentTool account, hosted scan route, wallet, or
authority to test another system.
npm is a convenient public mirror. Whitehack 0.9 retains the scanner
and adds the evidence-capsule parser and CLI; AgentTool's CI advisory
remains independently locked to reviewed 0.8.1 bytes. The exact 0.9
LOVE manifest
records the 87,196-byte artifact, SHA-256
b7d004947bc3c7619daa38f002d9ddde731e2865644af0d0e609c8dd86528d3c,
source revision, and replaceable mirrors. The npm publication
additionally carries registry integrity and SLSA provenance.
Evidence stays local first
Raw source, PoCs, traces, private scope material, and undisclosed
findings must not be sent to public CI, wakes, traces, listings, or
docs. The current bridge omits snippets and scanner messages from its
report; that is not a universal guarantee for future tools or operators.
Already-created evidence can be collected explicitly into
@agenttool/data as local immutable content-addressed
records, shared as a recipient-encrypted ADDS bundle, or—only for the
exact public-minimal Whitehack 0.9 capsule—sent through the explicit
S3-compatible bridge above.
Those mechanisms have narrower meanings: the local data node does not
encrypt its blob/FTS storage or establish authorization, and ADDS does
not prove that a finding is true. A marketplace invocation can
coordinate work and settlement; it cannot grant assessment scope or
certify quality.
The detailed implementation and future
whitehack-scope/run/finding/disclosure evidence profiles
live in
the Whitehack doctrine.