Skip to content

feat(binary-analysis): structured findings/assets output - #166

Merged
monoxgas merged 1 commit into
mainfrom
feat/binary-analysis-outputs
Oct 1, 2026
Merged

monoxgas merged 1 commit into
mainfrom
feat/binary-analysis-outputs

Conversation

@monoxgas

@monoxgas monoxgas commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

What

Enables structured output for the binary-analysis capability so its agent can emit queryable findings and assets instead of only prose.

  • capability.yaml: declare outputs: true. This turns on the built-in finding and asset item types plus the report_item / update_item / link_items mutation tools for the capability's agent.
  • agents/binary-analysis-agent.md: add a short reporting section directing the agent to report confirmed findings (recovered key/C2 config, vulnerability root cause, malicious capability, unpacking result) with concrete evidence and a severity, and identified assets (the analyzed binary, extracted payloads, embedded endpoints) with a stable identifier. Unverified hypotheses are left out.
  • Version bump 0.5.0 -> 0.6.0 (new feature; the release-plan script keys off the manifest version field).

Why

Binary analysis produces results worth tracking as records — a recovered key, a vulnerability root cause, a dropped payload. With outputs enabled, those become structured items tied to the session and trace span that produced them, so they flow through the platform's review-then-submit path and can be filtered, linked, and reported on, rather than being buried in the run transcript.

The declaration follows the documented one-line contract (outputs: true enables the core finding and asset types) and the existing precedent of a capability opting into item output.

Validation

  • dreadnode capability validate capabilities/binary-analysis and --strict: both pass (binary-analysis@0.6.0, 1 ok / 0 warn / 0 failed).
  • Capability unit tests: mcp/test_server.py (22 passed) and mcp/test_ghidra_mcp.py (8 passed).
  • Pre-commit hooks on the changed files: check-yaml, end-of-file-fixer, trailing-whitespace, gitleaks all pass.

No MCP server, tool, or test code changed; the capability was not run against any target or binary.

🤖 Generated with Claude Code

https://claude.ai/code/session_01Pk7vhPigDSKEgkvBW5mkBF

Declare `outputs: true` in the capability manifest so binary-analysis
agents get the platform's report_item / update_item / link_items tools
and the built-in finding and asset item types. Confirmed results (a
recovered key or C2 config, a vulnerability root cause, a malicious
capability, an extracted payload) can now be emitted as structured
records that flow through the platform's review-then-submit path instead
of living only in the agent's prose.

Add a short reporting section to the agent prompt directing it to report
confirmed findings with concrete evidence and identified assets with a
stable identifier, and to leave out unverified hypotheses.

Bump version 0.5.0 -> 0.6.0 (new feature).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Pk7vhPigDSKEgkvBW5mkBF
@monoxgas
monoxgas merged commit f8e08f0 into main Oct 1, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant