Skip to content

autoresearch: global threshold search#23

Open
Techris93 wants to merge 10 commits into
mainfrom
autoresearch/global-20260406-220009
Open

autoresearch: global threshold search#23
Techris93 wants to merge 10 commits into
mainfrom
autoresearch/global-20260406-220009

Conversation

@Techris93
Copy link
Copy Markdown
Owner

Automated local autoresearch run.

Baseline F1: 0.864995 (FP=447, FPR=0.3921)
Best score: 0.874385 | F1: 0.875039 (FP=373, FPR=0.3272)

Report: /Users/chrixchange/.openclaw/workspace/secopsai/results/autoresearch-20260406-220009.json

Reproduce:

  1. source .venv/bin/activate
  2. python scripts/autoresearch_search.py --iters 200 --seed 1337 --fp-max 999999 --penalty 0.002

@cloudflare-workers-and-pages
Copy link
Copy Markdown

cloudflare-workers-and-pages Bot commented Apr 6, 2026

Deploying website with  Cloudflare Pages  Cloudflare Pages

Latest commit: 946caf4
Status: ✅  Deploy successful!
Preview URL: https://d2f15826.website-bks.pages.dev
Branch Preview URL: https://autoresearch-global-20260406.website-bks.pages.dev

View logs

@cloudflare-workers-and-pages
Copy link
Copy Markdown

Deploying secopsai with  Cloudflare Pages  Cloudflare Pages

Latest commit: 946caf4
Status: ✅  Deploy successful!
Preview URL: https://a5c6fd55.secopsai.pages.dev
Branch Preview URL: https://autoresearch-global-20260406.secopsai.pages.dev

View logs

Copy link
Copy Markdown

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 946caf4866

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread detect.py
Comment on lines +735 to +736
r"(?i)(nohup\s+.+\s+&\b|/bin/\w+\s+-c\s+.*\s+&\b|start\s+/min\s+powershell|powershell.*-enc\b|"
r"cscript(?:\.exe)?\s+.*\.vbs\b|osascript\s+.*\.scpt\b|chmod\s+\d+\s+.+&&.+https?://|"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove impossible word boundary after '&' in detached regex

The detached-shell alternatives in detect_detached_payload_execution use &\b, but \b after & will not match normal shell backgrounding syntax, so patterns like nohup ... & and /bin/sh -c ... & are effectively never detected through these branches. This causes RULE-112 to miss common detached payload-launch commands unless another fallback regex happens to match.

Useful? React with 👍 / 👎.

Comment on lines +297 to +298
if not risk_tags:
risk_tags = list(metadata.keys()) if metadata else []
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve empty risk tags instead of metadata key names

When risk_tags is absent, normalize_row now fills it with metadata field names (for example source_name, detector, fingerprint) rather than risk labels, which silently corrupts tag semantics for downstream filtering and analytics. Any finding without explicit risk_tags will be mislabeled with these synthetic values instead of staying empty.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant