Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
.git
.github
.venv
.intentgate-state
__pycache__
*.py[cod]
*.egg-info
.env
.env.*
!.env.integrations.example
config/integrations.json
tests
docs
observability
deploy
*.log
19 changes: 19 additions & 0 deletions .env.integrations.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
# Copy to .env.integrations and populate only integrations you enable.
DEFENDER_XDR_TOKEN=
MICROSOFT_SENTINEL_TOKEN=
CROWDSTRIKE_ACCESS_TOKEN=
SENTINELONE_API_TOKEN=
SPLUNK_TOKEN=
ELASTIC_API_KEY=

# Change these before exposing the stack beyond localhost.
UIG_INGEST_TOKEN=change-me
GRAFANA_ADMIN_USER=admin
GRAFANA_ADMIN_PASSWORD=change-me

# Manager escalation webhook (generic JSON, Slack, or Teams).
UIG_MANAGER_ID=
UIG_MANAGER_REPORT_THRESHOLD=70
UIG_MANAGER_WEBHOOK_URL=
UIG_MANAGER_WEBHOOK_TOKEN=
UIG_MANAGER_WEBHOOK_STYLE=generic
37 changes: 37 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: Bug report
description: Report a reproducible defect or incorrect policy outcome.
title: "[Bug]: "
labels: [bug]
body:
- type: markdown
attributes:
value: Do not include credentials, private command history, or sensitive security events.
- type: textarea
id: description
attributes:
label: Description
description: What happened, and what did you expect?
validations:
required: true
- type: textarea
id: reproduction
attributes:
label: Reproduction
description: Provide a minimal sanitized command and configuration.
validations:
required: true
- type: input
id: environment
attributes:
label: Environment
description: OS, Python version, shell, and project version.
validations:
required: true
- type: dropdown
id: decision
attributes:
label: Incorrect decision
options: [ALLOW, REVIEW, BLOCK, Not applicable]
validations:
required: true

26 changes: 26 additions & 0 deletions .github/ISSUE_TEMPLATE/feature_request.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
name: Feature request
description: Propose a policy, integration, workflow, or observability improvement.
title: "[Feature]: "
labels: [enhancement]
body:
- type: textarea
id: problem
attributes:
label: Problem
description: What security or usability problem should this solve?
validations:
required: true
- type: textarea
id: proposal
attributes:
label: Proposed approach
description: Describe the behavior, relevant platforms, and expected decision impact.
validations:
required: true
- type: textarea
id: tradeoffs
attributes:
label: False-positive, privacy, and latency tradeoffs
validations:
required: true

15 changes: 15 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
version: 2
updates:
- package-ecosystem: pip
directory: "/"
schedule:
interval: monthly
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: monthly
- package-ecosystem: docker
directory: "/"
schedule:
interval: monthly

18 changes: 18 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
## Summary

Describe what changed and why.

## Security impact

- Decision or scoring changes:
- False-positive / false-negative tradeoffs:
- Privacy or telemetry changes:

## Validation

- [ ] Unit tests pass
- [ ] New behavior includes tests
- [ ] Python sources compile
- [ ] Docker Compose validates when affected
- [ ] No credentials or private telemetry are included

69 changes: 69 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
name: CI

on:
push:
branches: [main]
pull_request:

permissions:
contents: read

jobs:
test:
strategy:
matrix:
os: [ubuntu-latest, windows-latest]
python-version: ["3.11", "3.13"]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
cache: pip
- name: Install
run: python -m pip install -e .
- name: Test
run: python -m unittest discover -s tests -v
- name: Compile
run: python -m compileall -q src tests

compose:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Validate Docker Compose
run: docker compose -f docker-compose.observability.yml config --quiet

terraform:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: hashicorp/setup-terraform@v3
with:
terraform_version: "1.14.0"
- name: Check formatting
run: terraform -chdir=deploy/terraform fmt -check -recursive
- name: Initialize providers
run: terraform -chdir=deploy/terraform init -backend=false
- name: Validate configuration
run: terraform -chdir=deploy/terraform validate

ansible:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: "3.13"
cache: pip
- name: Install Ansible
run: python -m pip install "ansible-core>=2.18,<2.20" ansible-lint
- name: Install collections
run: ansible-galaxy collection install -r deploy/ansible/requirements.yml
- name: Syntax check
working-directory: deploy/ansible
run: ansible-playbook -i inventories/example.ini deploy.yml --syntax-check
- name: Lint playbook and role
working-directory: deploy/ansible
run: ansible-lint deploy.yml roles
37 changes: 37 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
.venv/
__pycache__/
*.py[cod]
.pytest_cache/
.test-state/
.intentgate-state/
dist/
build/
*.egg-info/
.env
.env.*
!.env.integrations.example
config/integrations.json
*.log
*.local.*
history.jsonl
manager-reports/

# Terraform state and local inputs
**/.terraform/
*.tfstate
*.tfstate.*
*.tfvars
*.tfvars.json
!*.tfvars.example
crash.log
override.tf
override.tf.json
*_override.tf
*_override.tf.json

# Ansible operator inventory, Vault data, and retry artifacts
deploy/ansible/inventories/*.ini
!deploy/ansible/inventories/example.ini
deploy/ansible/group_vars/all.yml
deploy/ansible/host_vars/
*.retry
21 changes: 21 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
# Changelog

All notable changes to this project will be documented here.

## [0.3.0] - 2026-08-12

### Added

- Low-latency `ALLOW`, `REVIEW`, and `BLOCK` command policy engine
- Windows and Linux privilege detection
- Cross-platform destructive-action catalog
- Per-user behavioral command baseline and anomaly scoring
- Cached project provenance and code-health scanning
- Normalized AV, EDR, and SIEM signal ingestion
- Microsoft Defender local collector and enterprise integration templates
- Prometheus metrics and provisioned Grafana dashboard
- Redacted asynchronous manager/security risk reports
- Generic, Slack, and Microsoft Teams webhook delivery
- Automated tests and repository governance documentation
- Terraform Docker Compose deployment module
- Ansible Linux host bootstrap and secure deployment role
22 changes: 22 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Code of Conduct

## Our commitment

We are committed to a welcoming, respectful, and harassment-free community for everyone, regardless of background, identity, experience, or viewpoint.

## Expected behavior

- Be constructive, specific, and respectful.
- Assume good faith while challenging ideas with evidence.
- Respect privacy and never post credentials, private telemetry, or identifying command history.
- Accept responsibility, apologize when appropriate, and learn from mistakes.
- Keep security research safe, lawful, and proportionate.

## Unacceptable behavior

Harassment, threats, discrimination, doxxing, deliberate disruption, sexualized conduct, and publishing another person's private information are not acceptable.

## Enforcement

Repository maintainers may edit, remove, or reject contributions and temporarily or permanently restrict participation when behavior violates these expectations. Report conduct concerns privately to the repository owner through an appropriate GitHub channel.

45 changes: 45 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# Contributing

Thank you for helping improve User Intent AI Security.

## Development setup

```powershell
python -m venv .venv
.\.venv\Scripts\python.exe -m pip install -e .
.\.venv\Scripts\python.exe -m unittest discover -s tests -v
```

Linux and macOS users can substitute `.venv/bin/python`.

## Pull requests

1. Open an issue first for major policy, architecture, telemetry, or privacy changes.
2. Keep each pull request focused on one coherent outcome.
3. Add tests for new rules, integrations, redaction behavior, and decision changes.
4. Explain false-positive and false-negative tradeoffs for security detections.
5. Never commit real credentials, customer events, employee command history, or private manager reports.
6. Run the test suite, bytecode compilation, and Compose validation before requesting review.

```powershell
.\.venv\Scripts\python.exe -m unittest discover -s tests -v
.\.venv\Scripts\python.exe -m compileall -q src tests
docker compose -f docker-compose.observability.yml config --quiet
```

## Detection contributions

New destructive-action patterns should include:

- The platforms and command families affected
- A concise risk category and explanation
- A conservative score justified by likely impact
- Positive and negative tests
- Consideration of quoting, aliases, mixed case, and benign administrative usage

Avoid broad patterns that classify ordinary read-only commands as destructive.

## Integration contributions

Use the normalized signal model. Keep credentials in environment variables, bound network operations, use event IDs for deduplication, define TTL behavior, and document the vendor API version used.

8 changes: 8 additions & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
FROM python:3.13-slim
WORKDIR /app
COPY pyproject.toml README.md ./
COPY src ./src
RUN pip install --no-cache-dir .
EXPOSE 8787
CMD ["uig-service", "--host", "0.0.0.0", "--port", "8787"]

22 changes: 22 additions & 0 deletions LICENSE
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
MIT License

Copyright (c) 2026 BB AI Arena

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

Loading
Loading