Bind WHITEHAT-WP-0001 to State Hub

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
This commit is contained in:
tegwick 2026-08-21 22:53:21 +02:00
parent 348738ba73
commit f5b7b36df6
2 changed files with 42 additions and 0 deletions

34
.custodian-brief.md Normal file
View file

@ -0,0 +1,34 @@
<!-- custodian-brief: generated by fix-consistency — do not edit manually -->
# Custodian Brief — whitehat-security
**Domain:** infotech
**Last synced:** 2026-08-21 20:53 UTC
**State Hub:** http://127.0.0.1:8000 *(adjust if running on a remote machine)*
## Active Workstreams
### Produce the adversarial evidence the Tenancy Posture ladders require
Progress: 0/7 done | workplan_id: `ecc16edc-9f9b-4fc4-8fb1-96b947a59299`
**Open tasks:**
- ! T02 — The attacker model per axis `e0070ee6`
- ! T03 — Differential cross-tenant harness (the E2 artifact) `742561f1`
- ! T04 — Prove the probes fail `a2afc0f5`
- ! T05 — RLS conformance under attack (the E3 artifact) `6df676e7`
- ! T06 — Noisy-neighbour characterisation (the P1/P2 artifact) `99254ab5`
- ! T07 — Reporting into risk-nexus `54f33288`
- ► T01 — Rules of engagement `0d28fd14`
## Inbox Hygiene
**Stale unread:** 1 message(s) older than 3 day(s) — triage at session start.
**Missing thread_id:** 1 unread message(s) lack supersession chains.
- ! audit-core: Request: the E2 adversarial artifact for audit-core — and a question about who should write it `e65435db`
---
## MCP Orientation (when available)
If the state-hub MCP server is reachable, call:
`get_domain_summary("infotech")`
This provides richer cross-domain context.
If the MCP call fails, use this file as your orientation source.

View file

@ -9,6 +9,7 @@ owner: net-kingdom
topic_slug: whitehat-security
created: "2026-08-17"
updated: "2026-08-21"
state_hub_workstream_id: "ecc16edc-9f9b-4fc4-8fb1-96b947a59299"
---
# WHITEHAT-WP-0001 — cross-tenant evidence
@ -81,6 +82,7 @@ As above. Gates everything.
id: WHITEHAT-WP-0001-T01
status: progress
priority: high
state_hub_task_id: "0d28fd14-1b82-4ac1-907b-02f43e8baae8"
```
Drafted in `docs/rules-of-engagement.md` on 2026-08-18 with authorization
@ -95,6 +97,7 @@ schema. It authorizes no live traffic until the operator personally approves
id: WHITEHAT-WP-0001-T02
status: wait
priority: high
state_hub_task_id: "e0070ee6-6060-4a29-bd88-f664034db28e"
```
What the adversary is assumed to hold, so a probe is judged against a threat
@ -119,6 +122,7 @@ only tested accident would report a strength E3 does not have.
id: WHITEHAT-WP-0001-T03
status: wait
priority: high
state_hub_task_id: "742561f1-97b6-4fcc-8e06-d18508ddecae"
```
The core technique: run the same request as two tenants and compare.
@ -141,6 +145,7 @@ currently claim `E2`. The artifact is the run record, not a green tick.
id: WHITEHAT-WP-0001-T04
status: wait
priority: high
state_hub_task_id: "a2afc0f5-3ece-410c-864c-829a8aac30fc"
```
A probe that has only ever passed is not evidence.
@ -159,6 +164,7 @@ trusted passing.
id: WHITEHAT-WP-0001-T05
status: wait
priority: medium
state_hub_task_id: "6df676e7-bed5-4291-a128-eb6e9844edf2"
```
`rapp-postgres` ADR-0003 supplies an `rls_conformance` view and a template, and
@ -183,6 +189,7 @@ the number to this repo. Set it, and state the resulting window in the record.
id: WHITEHAT-WP-0001-T06
status: wait
priority: medium
state_hub_task_id: "99254ab5-f08e-44c7-8399-be706dc03019"
```
The framework had to reword this artifact once already: its first draft
@ -204,6 +211,7 @@ consumer connection ceiling, a saturation probe is an outage if run carelessly.
id: WHITEHAT-WP-0001-T07
status: wait
priority: medium
state_hub_task_id: "54f33288-5361-4b20-8e1f-168866d64644"
```
Findings leave this repo in one direction. A run produces: what was attempted,