feat(binary-analysis): structured findings/assets output - #166
Merged
Merged
Conversation
Declare `outputs: true` in the capability manifest so binary-analysis agents get the platform's report_item / update_item / link_items tools and the built-in finding and asset item types. Confirmed results (a recovered key or C2 config, a vulnerability root cause, a malicious capability, an extracted payload) can now be emitted as structured records that flow through the platform's review-then-submit path instead of living only in the agent's prose. Add a short reporting section to the agent prompt directing it to report confirmed findings with concrete evidence and identified assets with a stable identifier, and to leave out unverified hypotheses. Bump version 0.5.0 -> 0.6.0 (new feature). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Pk7vhPigDSKEgkvBW5mkBF
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Enables structured output for the
binary-analysiscapability so its agent can emit queryable findings and assets instead of only prose.capability.yaml: declareoutputs: true. This turns on the built-infindingandassetitem types plus thereport_item/update_item/link_itemsmutation tools for the capability's agent.agents/binary-analysis-agent.md: add a short reporting section directing the agent to report confirmed findings (recovered key/C2 config, vulnerability root cause, malicious capability, unpacking result) with concrete evidence and a severity, and identified assets (the analyzed binary, extracted payloads, embedded endpoints) with a stable identifier. Unverified hypotheses are left out.0.5.0->0.6.0(new feature; the release-plan script keys off the manifest version field).Why
Binary analysis produces results worth tracking as records — a recovered key, a vulnerability root cause, a dropped payload. With
outputsenabled, those become structured items tied to the session and trace span that produced them, so they flow through the platform's review-then-submit path and can be filtered, linked, and reported on, rather than being buried in the run transcript.The declaration follows the documented one-line contract (
outputs: trueenables the corefindingandassettypes) and the existing precedent of a capability opting into item output.Validation
dreadnode capability validate capabilities/binary-analysisand--strict: both pass (binary-analysis@0.6.0, 1 ok / 0 warn / 0 failed).mcp/test_server.py(22 passed) andmcp/test_ghidra_mcp.py(8 passed).No MCP server, tool, or test code changed; the capability was not run against any target or binary.
🤖 Generated with Claude Code
https://claude.ai/code/session_01Pk7vhPigDSKEgkvBW5mkBF