From 2d0e96527316a1cd655d9b5fa605dfb28188784b Mon Sep 17 00:00:00 2001 From: monoxgas Date: Thu, 1 Oct 2026 09:30:22 -0600 Subject: [PATCH] feat(binary-analysis): add structured findings/assets output Declare `outputs: true` in the capability manifest so binary-analysis agents get the platform's report_item / update_item / link_items tools and the built-in finding and asset item types. Confirmed results (a recovered key or C2 config, a vulnerability root cause, a malicious capability, an extracted payload) can now be emitted as structured records that flow through the platform's review-then-submit path instead of living only in the agent's prose. Add a short reporting section to the agent prompt directing it to report confirmed findings with concrete evidence and identified assets with a stable identifier, and to leave out unverified hypotheses. Bump version 0.5.0 -> 0.6.0 (new feature). Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01Pk7vhPigDSKEgkvBW5mkBF --- .../agents/binary-analysis-agent.md | 18 ++++++++++++++++++ capabilities/binary-analysis/capability.yaml | 7 ++++++- 2 files changed, 24 insertions(+), 1 deletion(-) diff --git a/capabilities/binary-analysis/agents/binary-analysis-agent.md b/capabilities/binary-analysis/agents/binary-analysis-agent.md index ac8c760..b180954 100644 --- a/capabilities/binary-analysis/agents/binary-analysis-agent.md +++ b/capabilities/binary-analysis/agents/binary-analysis-agent.md @@ -73,3 +73,21 @@ For each step, report: the tool call, the single most-useful finding, and what you plan to do next. End with the recovered artifact (or the definitive answer to the analysis question) and enough detail that someone could reproduce the analysis. + +## Reporting results + +Use `report_item` to emit structured results as you confirm them, so they +flow through the platform's review-then-submit path instead of living only +in your prose: + +- `report_item(item_type="finding", ...)` for a confirmed conclusion that + matters — a recovered key or C2 config, a vulnerability root cause, a + malicious capability, an unpacking result. Set `severity`, and put the + concrete proof (decompiled snippet, string, address, tool output) in + `evidence`. Report what you verified, not what you suspect; if a result is + still a hypothesis, keep analyzing until it holds or leave it out. +- `report_item(item_type="asset", ...)` for something you identified in + scope — the analyzed binary, an extracted payload or dropped file, an + embedded endpoint — with a stable `identifier` (hash, path, or URL). + +Reporting supplements the write-up; it does not replace showing your work. diff --git a/capabilities/binary-analysis/capability.yaml b/capabilities/binary-analysis/capability.yaml index 50a938a..bb95bd9 100644 --- a/capabilities/binary-analysis/capability.yaml +++ b/capabilities/binary-analysis/capability.yaml @@ -1,6 +1,6 @@ schema: 1 name: binary-analysis -version: "0.5.0" +version: "0.6.0" description: > Binary reverse engineering for PE, ELF, Mach-O, and raw shellcode on macOS and Linux. Static triage (pefile / pyelftools / lief, entropy, @@ -57,6 +57,11 @@ checks: skills: - skills/ +# Enables the built-in finding and asset item types plus the report_item / +# update_item / link_items mutation tools, so the agent can emit structured +# findings and assets that flow through the platform's review-then-submit path. +outputs: true + author: name: Dreadnode url: https://dreadnode.io