diff --git a/REGISTER.md b/REGISTER.md index 1a4ab84..149ac01 100644 --- a/REGISTER.md +++ b/REGISTER.md @@ -1,16 +1,17 @@ # Register -Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-01. +Generated by `tools/register_index.py` from `findings/`. Do not edit by hand. Last built 2026-09-02. -2 live of 10 findings; 3 notes below the floor. +3 live of 11 findings; 3 notes below the floor. ## Findings | ID | Finding | System | Severity | Disclosure | Escalation | Fix owner | Status | Cadence | Next check | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | -| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | embargoed | none | railiance-platform | open | instant (0) | **due** | +| [RISK-F-0011](findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md) | qonto-assistant audit.deny stream completeness is not established | qonto-assistant | medium | public | none | qonto-assistant | open | instant (0) | **due** | +| [RISK-F-0010](findings/RISK-F-0010-embedded-backup-webdav-credential.md) | Forgejo backup source embeds a WebDAV credential default | railiance-platform | low | embargoed | none | railiance-platform | open | 1h (1) | 2026-09-02 09:11Z | | [RISK-F-0009](findings/RISK-F-0009-openbao-deny-set-covers-a-third-of-high-risk-lanes.md) | agent-high-risk-boundary denies 6 of 17 high-risk lanes; the direct bao path is unprotected for the rest | railiance-platform | **high** | public | none | railiance-platform | fixed | instant (0) | **due** | -| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | instant (0) | **due** | +| [RISK-F-0008](findings/RISK-F-0008-audit-retention-legal-basis-assumed.md) | The legal basis for retaining audit facts against an erasure request has been assumed, never established | audit-core | medium | public | **answered** (t2, answered) | risk-nexus | accepted | 1h (1) | 2026-09-02 09:11Z | | [RISK-F-0007](findings/RISK-F-0007-unverified-tenant-boundary.md) | No consumer's tenant boundary is verified anywhere | estate | **high** | public | **answered** (t4, assigned) | per-consumer, on request | fixed | instant (0) | **due** | | [RISK-F-0006](findings/RISK-F-0006-apps-pg-no-backup-configured.md) | apps-pg has no backup configured at all: R0 means no recovery | railiance-platform | **high** | public | **answered** (t3, answered) | railiance-platform | fixed | instant (0) | **due** | | [RISK-F-0005](findings/RISK-F-0005-audit-core-unfiltered-read-path.md) | audit-core read path applies no tenant filter; the bound is deployment, not code | audit-core | medium | public | none | audit-core | fixed | instant (0) | **due** | @@ -34,6 +35,7 @@ Silence never buys a softer grade — see `docs/method/dependencies.md`. | Finding | Who | What would change | Default if silent | On | | --- | --- | --- | --- | --- | +| RISK-F-0011 | qonto-assistant | a published cadence plus a reconciliation view would let a later observation support completeness; a rejection keeps the grade and records that estate observation must not treat the stream as complete | the medium grade stands; missing cadence is recorded as a stalled remediation, and observation remains staffed with completeness pending | 2026-09-16 | | RISK-F-0010 | railiance-platform | the finding becomes fixed and the embargo lifts | the low grade and embargo stand; missing fix tracking is recorded as a stalled remediation | 2026-09-15 | | RISK-F-0008 | audit-core | a working keyed commitment narrows RISK-REG-0001 to retained-by-obligation categories only | encrypt-then-hash recorded as the only known route, and the retention period recorded as unstateable | 2026-11-17 | diff --git a/STATE.md b/STATE.md index 9f5a2f3..3fcc2d9 100644 --- a/STATE.md +++ b/STATE.md @@ -1,20 +1,21 @@ # STATE — risk-nexus -**Updated:** 2026-09-01 +**Updated:** 2026-09-02 **Domain:** infotech · **Repo:** risk-nexus · **Owner:** the-custodian ## One-line posture -**The register decides.** Nine findings graded, three notes below the floor, +**The register decides.** Eleven findings graded, three notes below the floor, one regulatory determination and a thirteen-entry legal policy set; every open -question carries a default and a date, and the check cadence is scheduled on -`activity-core` rather than on anyone remembering. +question carries a default and a date. Today's live set is three: an open +medium on qonto-assistant deny-stream completeness, an open low embargoed +backup credential, and an accepted medium on audit retention. ## Workplans | ID | Status | Notes | | --- | --- | --- | -| `RISK-WP-0001` | **finished** | The four instruments, the index, the first grading | +| `RISK-WP-0001` | **finished** | The four instruments, the index, the first grading. Still waiting on canon kinds until 2026-09-17. | | `RISK-WP-0002` | **finished** | Two findings and five public method instruments handed to `policy-nexus` | | `RISK-WP-0003` | **finished** | Regulatory intake; the legal policy set | | `RISK-WP-0004` | **finished** | Running the register: cadence, verification, inbox-before-grading | @@ -24,18 +25,21 @@ question carries a default and a date, and the check cadence is scheduled on | ID | Sev | Status | Disclosure | Cadence | System | | --- | --- | --- | --- | --- | --- | +| `RISK-F-0011` | medium | open | public | instant | qonto-assistant | +| `RISK-F-0010` | low | open | embargoed | 1h | railiance-platform | +| `RISK-F-0009` | high | fixed | public | instant | railiance-platform | +| `RISK-F-0008` | medium | accepted | public | 1h | audit-core | +| `RISK-F-0007` | high | fixed | public | instant | estate | +| `RISK-F-0006` | high | fixed | public | instant | railiance-platform | +| `RISK-F-0005` | medium | fixed | public | instant | audit-core | +| `RISK-F-0004` | medium | fixed | public | instant | tenant-engine | +| `RISK-F-0003` | medium | fixed | public | instant | ops-warden | +| `RISK-F-0002` | medium | fixed | public | instant | ops-warden | | `RISK-F-0001` | high | fixed | public | instant | flex-auth | -| `RISK-F-0002` | medium | open | embargoed | instant | ops-warden | -| `RISK-F-0003` | medium | mitigated | embargoed | 1h | ops-warden | -| `RISK-F-0004` | medium | open | embargoed | instant | tenant-engine | -| `RISK-F-0005` | medium | mitigated | public | instant | audit-core | -| `RISK-F-0006` | high | **fixed** | public | instant | railiance-platform | -| `RISK-F-0007` | high | accepted | embargoed | instant | estate | -| `RISK-F-0008` | medium | accepted | public | instant | audit-core | -| `RISK-F-0009` | high | open | embargoed | instant | railiance-platform | Notes below the floor: `RISK-N-0001` noisy neighbours · `RISK-N-0003` found by -reading not watching · `RISK-N-0004` zone lookup. +reading not watching (first observation-sourced finding arrived 2026-09-02, +still a note) · `RISK-N-0004` zone lookup. Not one field reads `unset`. @@ -68,17 +72,13 @@ an unread message) and `daily-register-check-sweep` (07:15, unconditional). Both instruct a session that exercises judgement; neither may record an outcome. -## Waiting on other people — 9 open, all defaulted +## Waiting on other people | Who | On | Defaults | | --- | --- | --- | -| ops-warden | does the flex-auth pin admit ingress, before enabling `policy.enabled` | 2026-08-27 | -| railiance-platform | deny-set coverage report (`F-0009`) | 2026-09-03 | -| tenant-engine | confirm/correct `events()`; fix tracking | 2026-09-03 | -| user-engine | tenant-boundary verification (`RISK-V-0002`) | 2026-09-03 | +| qonto-assistant | heartbeat / emission-cadence and a reconciliation view for `audit.deny` (`F-0011`) | 2026-09-16 | +| railiance-platform | revoke or invalidate the provider credential, remove the source default, name fix tracking (`F-0010`) | 2026-09-15 | | the-custodian | canon kinds packet | 2026-09-17 | -| railiance-platform | backup target, cost, demonstrated restore | 2026-09-18 | -| audit-core | is `may_read` false on every production credential | 2026-09-19 | | audit-core | keyed commitment; `platform-pg` co-residency horizon | 2026-11-17 | ## Verify @@ -112,5 +112,8 @@ statehub fix-consistency --repo risk-nexus production instance. The estate's read model cannot see any `risk-nexus` workplan. - **C-31** fires on `RISK-F-` ids until canon registers the kinds. Packet sent. + Defaults 2026-09-17. - **OpenBao is unverifiable from here** (403). Every grade touching an OpenBao policy is a grade on a document, and says so. +- **`RISK-F-0011` is due at `instant`.** Graded this sitting; not clean-checked + in the same sitting. The next pass climbs it if nothing moved. diff --git a/docs/regulatory/audit-retention-basis.md b/docs/regulatory/audit-retention-basis.md index 105e722..8bb4480 100644 --- a/docs/regulatory/audit-retention-basis.md +++ b/docs/regulatory/audit-retention-basis.md @@ -8,11 +8,11 @@ determined: "2026-08-20" finding: RISK-F-0008 sources_read: "GDPR Arts 5, 6, 17, 21, 32; Recitals 49, 65; HGB §257; AO §147" external_review: none -last_checked: "2026-09-01T00:38:53Z" -next_check: "2026-09-01T00:38:53Z" -cadence: instant -clean_streak: 0 -checked_by: "codex/risk-nexus" +last_checked: "2026-09-02T08:11:18Z" +next_check: "2026-09-02T09:11:18Z" +cadence: 1h +clean_streak: 1 +checked_by: "grok/risk-nexus" --- # RISK-REG-0001 — the retention basis, written down @@ -179,3 +179,4 @@ estate's stated position, with the achieved-versus-target gap recorded as unresolved. - **2026-09-01** — not clean: the dated review found that the 2026-08-20 target-period amendment had never advanced this record's check state. The targets now stand explicitly; achievement under the shared backup horizon and keyed-commitment feasibility remain open. Cadence 1h → instant; checked again immediately. +- **2026-09-02** — clean check: grounds and target periods unchanged; still waiting on the platform-pg co-residency horizon. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z. diff --git a/docs/rulings/2026-09-02-qonto-deny-stream.md b/docs/rulings/2026-09-02-qonto-deny-stream.md new file mode 100644 index 0000000..63d996d --- /dev/null +++ b/docs/rulings/2026-09-02-qonto-deny-stream.md @@ -0,0 +1,68 @@ +--- +id: RISK-RULING-2026-09-02-A +type: ruling +title: "Inbox intake: qonto-assistant audit.deny stream completeness" +status: adopted +owner: risk-nexus +adopted: "2026-09-02" +review_interval: 6m +disclosure: public +revision: "adopted-1" +last_reviewed: "2026-09-02" +--- + +# Inbox intake — 2026-09-02 + +One unread finding-intake from Gate House. The two findings already due were +read against it first; it does not speak about them. + +## Decision + +| Finding | Prior state | Ruling | Evidence that changes it | +| --- | --- | --- | --- | +| `RISK-F-0011` | unfiled | medium, public, open | live deny observed; no heartbeat, cadence, or reconciliation view; local lockout does not consume the stream | + +The reporter asked for a finding, a note, or an explicit rejection. It is a +finding. Both floor tests hold: qonto-assistant can publish or reject a +cadence, and recording this changes whether anyone may treat the deny stream +as complete. + +It is not a note. `RISK-N-0004` is the missing-capability shape with no owner +and nothing to route. Here the owner is named, the residual is already routed, +and observation is already staffed on a claim it cannot finish. + +## Why medium, and why not the reporter's "load-bearing" reading unmodified + +Gate House said the `audit.deny` class is load-bearing because qonto-assistant's +escalation loop branches on it. Current source narrows that. `DenyEscalationTracker` +is in-process on the decision path; `AuditLogger.emit` is a parallel record. A +missing audit line would not, today, turn the Fast Local Loop off. + +The stream is still load-bearing for **estate observation**. King's Guard +already consumes it. Without a cadence or a reconciliation view, that +observation can preserve a received deny and cannot vouch for the stream. +That is the defect. + +`I2` not `I3`: one lane's observation, not a crossed authorization or tenant +boundary. Access remains denied in the observed case; the local lockout is +independent of the stream. + +`L3` not `L4`: completeness unknown is not "denies are being dropped". The +reporter said so, and this register follows it. `L3` not `L2` because the +working set already reads the stream. + +No fidelity modifier: the observer did not claim completeness. + +## What is not decided here + +Taxonomy ownership of an emission-cadence declaration (net-kingdom / +info-tech-canon) stays their residual. Depth-one: this finding waits on +qonto-assistant, defaults on 2026-09-16, and does not wait on a canon debate +that has not yet failed one routing exchange. + +## Same sitting, already-due findings + +`RISK-F-0010` and `RISK-F-0008` / `RISK-REG-0001` were due from 2026-09-01. +The intake does not mention them. Owner records have not moved since that +check. Their outcomes are recorded with `make checked`, not re-graded here. +`RISK-F-0011` is not clean-checked in this sitting. diff --git a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md index 5899e2a..c23a70b 100644 --- a/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md +++ b/findings/RISK-F-0008-audit-retention-legal-basis-assumed.md @@ -44,10 +44,10 @@ escalation_act: rule decision: "identity in audit records: opaque subject ids preferred, agent identifiers where possible, operator credentials only where necessary, policy decisions tracked to the responsible party; zone-level privacy guarantees may raise the floor" outstanding: "whether the stated target periods are achievable under platform-pg co-residency, and whether a keyed commitment restores erasability" determination: RISK-REG-0001 -last_checked: "2026-09-01T00:38:53Z" -next_check: "2026-09-01T00:38:53Z" -cadence: instant -clean_streak: 0 +last_checked: "2026-09-02T08:11:17Z" +next_check: "2026-09-02T09:11:17Z" +cadence: 1h +clean_streak: 1 waiting_on: - who: audit-core what: "does a keyed commitment restore erasability without breaking chain verification; what is the platform-pg co-residency horizon" @@ -57,7 +57,7 @@ waiting_on: default_at: "2026-11-17" graded_by: risk-nexus ruling: RISK-RULING-2026-08-19-C -checked_by: "codex/risk-nexus" +checked_by: "grok/risk-nexus" --- # RISK-F-0008 — the exemption nobody has established @@ -364,3 +364,4 @@ co-residency horizon that decides whether the stated retention periods are achievable. An accepted risk still gets checked. - **2026-08-20** — not clean: Trigger list ruled: no external determination in build mode; accepted with the legal policy set as the compensating control. Cadence instant → instant; checked again immediately. - **2026-09-01** — not clean: the regulatory record now states target periods per category; the remaining gap is whether platform-pg co-residency can achieve them, while the keyed-commitment question is unchanged. Grade and acceptance hold. Cadence instant → instant; checked again immediately. +- **2026-09-02** — clean check: acceptance, RISK-REG-0001, and the audit-core keyed-commitment wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z. diff --git a/findings/RISK-F-0010-embedded-backup-webdav-credential.md b/findings/RISK-F-0010-embedded-backup-webdav-credential.md index 631d691..f1ae890 100644 --- a/findings/RISK-F-0010-embedded-backup-webdav-credential.md +++ b/findings/RISK-F-0010-embedded-backup-webdav-credential.md @@ -25,10 +25,10 @@ embargo_condition: "the provider credential is revoked or invalidated and the li embargo_since: "2026-09-01" embargo_review: "2026-09-15" escalation: none -last_checked: "2026-09-01T00:32:44Z" -next_check: "2026-09-01T00:32:44Z" -cadence: instant -clean_streak: 0 +last_checked: "2026-09-02T08:11:17Z" +next_check: "2026-09-02T09:11:17Z" +cadence: 1h +clean_streak: 1 waiting_on: - who: railiance-platform what: "revoke or invalidate the provider credential, remove the source default, name fix tracking, and demonstrate governed ciphertext upload plus restore" @@ -38,7 +38,7 @@ waiting_on: default_at: "2026-09-15" graded_by: risk-nexus ruling: RISK-RULING-2026-09-01-A -checked_by: "codex/risk-nexus" +checked_by: "grok/risk-nexus" --- # RISK-F-0010 — Forgejo backup source embeds a WebDAV credential default @@ -121,3 +121,4 @@ Reasoning: `docs/rulings/2026-09-01-inbox-sweep.md`. ## Reviews - **2026-09-01** — graded from the filed report and a redacted current-source check. The literal default remains; no fix record was found. Cadence starts at instant. +- **2026-09-02** — clean check: literal source default remains; no fix tracking; embargo and 2026-09-15 wait unchanged. Cadence instant → 1h (1 clean in a row); next check 2026-09-02 09:11Z. diff --git a/findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md b/findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md new file mode 100644 index 0000000..0e457a4 --- /dev/null +++ b/findings/RISK-F-0011-qonto-audit-deny-stream-completeness.md @@ -0,0 +1,146 @@ +--- +id: RISK-F-0011 +type: finding +title: "qonto-assistant audit.deny stream completeness is not established" +status: open +owner: risk-nexus +reported_by: kings-guard +reported_via: gate-house +routed_by: gate-house +date_reported: "2026-09-01" +date_filed: "2026-09-02" +system: qonto-assistant +environment: production +fix_owner: qonto-assistant +fix_tracking: unset +# Graded by risk-nexus 2026-09-02 — docs/rulings/2026-09-02-qonto-deny-stream.md +severity: medium +severity_at_production: medium +impact: I2 +likelihood: L3 +fidelity_modifier: false +production_rescore: false +disclosure: public +publication: pending-handover +publication_id: risk-f-0011-qonto-audit-deny-stream-completeness +publication_path: "findings/qonto-audit-deny-stream-completeness/v1/index.html" +publication_subtitle: "A live deny was observed on qonto-assistant, but nothing yet lets anyone claim the load-bearing deny stream is complete." +revision: "graded-1" +last_reviewed: "2026-09-02" +review_interval: 6m +escalation: none +last_checked: "2026-09-02T07:20:00Z" +next_check: "2026-09-02T07:20:00Z" +cadence: instant +clean_streak: 0 +waiting_on: + - who: qonto-assistant + what: "publish a heartbeat or emission-cadence declaration and a reconciliation view for the audit.deny stream, or reject that obligation" + since: "2026-09-02" + would_change: "a published cadence plus a reconciliation view would let a later observation support completeness; a rejection keeps the grade and records that estate observation must not treat the stream as complete" + default: "the medium grade stands; missing cadence is recorded as a stalled remediation, and observation remains staffed with completeness pending" + default_at: "2026-09-16" +graded_by: risk-nexus +ruling: RISK-RULING-2026-09-02-A +checked_by: "grok/risk-nexus" +--- + +# RISK-F-0011 — qonto-assistant audit.deny stream completeness is not established + +## What is true, as reported + +King's Guard observed real `qonto-assistant` allow and deny events emitted by +`audit.AuditLogger` through `CapabilityService`. One deny (`list_transactions` +over MCP, `arg_constraint`) arrived with record richness 90 and preserved +origin linkage. Gate House accepted that mapping and recorded the qonto lane +as staffed for observation. + +The same return says the `audit.deny` class is load-bearing, and that its +**stream completeness is unknown**: + +- no heartbeat or emission-cadence declaration is published; +- no reconciliation view was supplied; +- richness 90 describes the received record, not the stream; +- no claim is made that every deny was emitted or observed. + +This is not evidence that an event was suppressed. The reporter assigned no +severity and asked this register to intake, grade, and route. + +Safe evidence named by Gate House: kings-guard revision `9daea96`; source +return `23480b81-bc34-4df4-92cc-840fbc8514fd`; Gate House disposition +`no_change` at commit `feff576` and +`gate-house/docs/conformance/2026-09-02-kings-guard-qonto-live-observation.md`. +The owner route `3b9c26a1-ba1a-4189-b439-edd61683aed5` was unread at intake. + +## How it was found + +Live observation, not a self-assessment. King's Guard completed +`KG-WP-0003-T06/T07` against the real qonto-assistant lane. Gate House reviewed +the return under `GH-WP-0001-T06` and routed the implementation residual here +on 2026-09-01 (message `53645a75-0215-4261-a700-f7aedf09e7e8`). + +## What a current-source check adds + +The local lockout does **not** consume the audit stream. `DenyEscalationTracker` +is in-process state on the decision path (`CapabilityService` calls +`record_deny` / `check` directly; `AuditLogger.emit` is a parallel record). +A dropped audit line would not, on today's source, disable qonto-assistant's +own Fast Local Loop. + +What the stream is load-bearing *for* is estate observation. King's Guard +already consumes it. Without a cadence declaration or a reconciliation view, +that observation can report a received deny and cannot vouch that every deny +was emitted. + +No heartbeat, emission-cadence, or reconciliation artefact was found in +qonto-assistant at filing. `fix_tracking` is unset. + +Taxonomy ownership of an emission-cadence declaration (net-kingdom / +info-tech-canon) is a separate residual. This record does not wait on it: +depth-one, and one routing exchange has not yet failed. Silence there does not +change qonto-assistant's obligation to declare what it emits, or this grade. + +## Suggested direction + +Suggestion, owned by `qonto-assistant`: + +1. Publish a heartbeat or emission-cadence declaration for `audit.deny`. +2. Supply a reconciliation view an observer can use to test completeness. +3. Open fix tracking, or reject the obligation in writing so observation stays + explicitly incomplete. + +Risk Nexus owns severity, disclosure, escalation, and review cadence. + +## Register ruling — 2026-09-02 + +`medium` (`I2` × `L3`), public, no escalation. + +**`I2`: one system's observation of one deny class.** A missed audit.deny +does not, on the facts established, authorize a Qonto action or disable the +in-process lockout. It leaves estate observation unable to treat the stream as +complete. That is confined to the qonto-assistant lane. + +**`L3`: the gap is the current state of a stream the working set already +consumes.** King's Guard reached the stream with no additional step and still +could not complete the claim. This is not `L4`: suppression is not established, +and the band is scored on the missing completeness evidence, not on an +unobserved drop. It is not `L2`: waiting for a special foothold would describe +the wrong defect. + +**No fidelity modifier.** The observer reported completeness as unknown. A +later claim that the stream is complete without a cadence or reconciliation +view would be the lying-control state; that is not today's headline. + +**Disclosure `public`.** Reading this does not shorten a path to a defect. It +is a missing completeness claim, published as one. Handover to `policy-nexus` +is `pending-handover`. + +**No escalation.** No real-person data exposure, no new outside obligation, no +new spend, no failed ownership exchange, and no fourteen-day stall. The dated +wait makes that last statement expire. + +Reasoning: `docs/rulings/2026-09-02-qonto-deny-stream.md`. + +## Reviews + +- **2026-09-02** — graded from the Gate House intake, the named conformance review, and a current-source check of qonto-assistant. Local lockout is in-process; the emitted deny stream still has no cadence or reconciliation view. Cadence starts at instant. diff --git a/notes/RISK-N-0003-defects-found-by-reading-not-monitoring.md b/notes/RISK-N-0003-defects-found-by-reading-not-monitoring.md index df90dcd..d96f1e0 100644 --- a/notes/RISK-N-0003-defects-found-by-reading-not-monitoring.md +++ b/notes/RISK-N-0003-defects-found-by-reading-not-monitoring.md @@ -52,3 +52,14 @@ difference between an argument and a measurement. It comes back as a finding the first time something is found in one of the 110 that a reasonable sweep would have caught earlier. + +## Update — 2026-09-02: the first observation-sourced finding + +`RISK-F-0011` arrived from King's Guard live observation, routed by Gate House. +That breaks the original "none by monitoring" half of the sentence. It does not +trip the revisit: the finding is the observer reporting that a load-bearing +deny stream has no completeness evidence, not a defect monitoring should have +caught and did not. + +The note stays a note. There is still no owner for estate-wide detection, and +one observation-sourced finding does not convert an argument into a defect. diff --git a/tools/inbox_check.py b/tools/inbox_check.py index d7669aa..a56bab0 100644 --- a/tools/inbox_check.py +++ b/tools/inbox_check.py @@ -22,7 +22,7 @@ HUB = "http://127.0.0.1:8000/messages/?to_agent=risk-nexus&limit=100" def fetch() -> list[dict] | None: try: - with urllib.request.urlopen(HUB, timeout=6) as r: + with urllib.request.urlopen(HUB, timeout=20) as r: return json.load(r) except (urllib.error.URLError, TimeoutError, json.JSONDecodeError, OSError): return None