Files
boc/memory/audit-s4-s5.md
T
Bernt bae705aa97 ARCHITECTURE: NFC roadmap, edge AI, audit logging
- Add NFC ePassport roadmap (ICAO 9303, eIDAS)
- Add TensorFlow.js edge face detection (BlazeFace)
- Add structured audit logger (GDPR-compliant)
- Risk scoring support

Part of KYC Apple Native UX v1.1.0
2026-06-29 16:24:48 +00:00

13 KiB

EXTREME CERTIFICATION AUDIT — SECTIONS 4-5

Governance Bypass + Tool Execution Security

Datum: 2026-06-05
Utförare: DARPA Red Team / Penetration Tester (subagent)
Metod: Active exploitation — prove or falsify security


SECTION 4: GOVERNANCE BYPASS HUNT


[S4.1] Bypass Attempt: Direct DB Write to Ledger (bypass all middleware)

ATTACK VECTOR: Direct PostgreSQL INSERT via wavult_admin credentials to ledger_journal_entries
RESULT: BYPASS_CONFIRMED
HTTP_STATUS: N/A (direct DB)
EVIDENCE:

  • Connected directly to platform-identity-core.cvi0qcksmsfj.eu-north-1.rds.amazonaws.com:5432
  • Discovered 10 ledger/journal tables: ledger_journal_entries, gl_journal_entries, ledger_audit_log, etc.
  • NO database triggers on ledger_journal_entries (TRIGGERS: [])
  • Successful INSERT: INSERT_SUCCESS: [{"id":"4df29572-bef5-4ae4-ae6d-52f581c52e6d","created_at":"2026-06-05T15:43:08.703Z","status":"draft"}]
  • ledger_audit_log for this entry: EMPTY — no auto-audit
  • GECL check: total_blocks:0GECL received zero events for the direct DB write
  • Audit engine check: /api/audit/events returned 404 (endpoint doesn't exist at that path)
  • Row cleaned up post-test (DELETE succeeded directly too)

SEVERITY: CRITICAL
FINDING: Direct DB write to ledger_journal_entries succeeds without triggering GECL, audit engine, or any governance layer. No DB triggers enforce governance. The wavult_admin credentials provide full bypass of all middleware.


[S4.2] Bypass Attempt: Unauthenticated Admin/Debug Endpoints

ATTACK VECTOR: Probe all ports (3100, 3201, 3203-3206, 3209, 3250, 3263) for admin/metrics/debug endpoints without auth
RESULT: PARTIAL
HTTP_STATUS: Various
EVIDENCE:

  • Port 3100 /admin → HTTP 301 (redirect to /admin/) — body empty after follow
  • Port 3100 /metrics → HTTP 301 — body empty after follow
  • Port 3206 /admin → HTTP 200 — Returns full AAMOS Admin Dashboard HTML (unauthenticated!)
  • Port 3206 /metrics → HTTP 200 — Returns AAMOS System Status page (unauthenticated!)
  • Port 3206 /admin/api/* → HTTP 502 (backend gateway error — proxied service down)
  • Ports 3201, 3250, 3263: admin/debug paths return 401 or 404

SEVERITY: HIGH
FINDING: Port 3206 serves admin dashboard and metrics pages without authentication at the HTTP level. Admin API backend returns 502 (possibly protected at application layer), but UI assets are publicly accessible.


[S4.3] Bypass Attempt: Seed/Migration Scripts Without Governance

ATTACK VECTOR: Find and inspect seed/migration scripts that bypass GECL
RESULT: PARTIAL
HTTP_STATUS: N/A
EVIDENCE:

  • Found seed scripts: entity-graph/seed.mjs, financeco/ledger-routes.mjs, financeco/ledger-engine.mjs
  • All checked scripts: 0 governance refs (no GECL, audit, or governance calls)
  • entity-graph/seed.mjs writes directly to Neo4j via runQuery() without any governance layer
  • ai-training/supervisor/migrate.mjs: 0 governance refs
  • Scripts are executable via node <path> directly

SEVERITY: MEDIUM
FINDING: Seed/migration scripts can write data without governance. However, these require server-side execution access (not remotely exploitable without shell access).


[S4.4] Bypass Attempt: Recovery/Rollback Tool Bypass

ATTACK VECTOR: Find files with recovery/rollback/bypass/override keywords
RESULT: UNVERIFIED
HTTP_STATUS: N/A
EVIDENCE:

  • Found: agent-loop/executor.mjs, antifragility/adversarial-generator.mjs, builds/routes.mjs
  • Source code inspection deferred (out of scope for primary bypass hunt)
  • No actively exploitable recovery endpoints found

SEVERITY: LOW


[S4.5] Bypass Attempt: GECL Chain Manipulation (Rust Binary)

ATTACK VECTOR: HTTP DELETE/PUT/POST to GECL chain endpoints to tamper or reset
RESULT: BLOCKED
HTTP_STATUS: 404 for all manipulation attempts
EVIDENCE:

DELETE /api/gecl/events/test-id → 404
PUT /api/gecl/events/test-id → 404
POST /api/gecl/reset → 404
POST /api/admin/truncate → 404
  • GECL only exposes: /health (200) and /status (200)
  • Status: {"total_blocks":0,"chain_hash":"000...0","merkle_valid":true,"streams":0}
  • No manipulation endpoints exposed

SEVERITY: LOW (for this attack vector — but note S4.1 shows GECL never receives events in the first place)
FINDING: GECL binary is hardened against direct HTTP manipulation. However, GECL had 0 blocks throughout the entire audit — suggesting it is either not receiving events from application layer, or not yet integrated.


SECTION 5: TOOL EXECUTION SECURITY


[S5.1] Bypass Attempt: Filesystem Write Without Governance

ATTACK VECTOR: POST to amos-core filesystem write API + tolkserver evaluate with bypass flag
RESULT: BLOCKED
HTTP_STATUS: 401 (amos-core), 404 (tolkserver at wrong path)
EVIDENCE:

POST http://localhost:3100/api/tools/filesystem/write → 401 {"error":"Unauthorized","code":"NO_TOKEN"}
POST http://localhost:3204/api/tolk/evaluate → 404
/tmp/audit-bypass-test.txt → NOT CREATED
  • amos-core correctly rejects without JWT
  • Tolkserver path was wrong (/api/tolk/evaluate doesn't exist; real path is /tolkserver/interpret)

SEVERITY: LOW
FINDING: Filesystem write endpoint properly protected with JWT auth. File not created.


[S5.2] Bypass Attempt: Database Write Without Auth

ATTACK VECTOR: POST to audit engine and ledger API without authentication headers
RESULT: BLOCKED (via API) / BYPASS_CONFIRMED (via direct DB — see S4.1)
HTTP_STATUS: 404 (audit engine), 401 (ledger API)
EVIDENCE:

POST http://localhost:3251/api/audit/events (no auth) → 404 "Cannot POST /api/audit/events"
POST http://localhost:3250/api/ledger/journal (no auth) → 401 {"code":"NO_AUTH"}
GET http://localhost:3250/api/* → 401 for all paths
GET http://localhost:3250/health → 200 (health check only)

SEVERITY: LOW (API layer), CRITICAL (direct DB — documented in S4.1)


[S5.3] Bypass Attempt: Payment Processing Without Approval

ATTACK VECTOR: POST to quixzoom-api payment and credits endpoints without auth
RESULT: BLOCKED
HTTP_STATUS: 401
EVIDENCE:

POST http://localhost:3209/api/qz/payments/checkout → 401 {"error":"Unauthorized","code":"NO_TOKEN"}
POST http://localhost:3209/api/qz/payments/credits/add → 401 {"error":"Unauthorized","code":"NO_TOKEN"}

SEVERITY: LOW
FINDING: Payment endpoints correctly reject unauthenticated requests.


[S5.4] Bypass Attempt: Agent Spawn Without Governance

ATTACK VECTOR: POST to amos-core homo-deus/spawn and agents/execute with bypass flag
RESULT: BLOCKED
HTTP_STATUS: 401
EVIDENCE:

POST http://localhost:3100/api/homo-deus/spawn (bypass_governance:true) → 401 {"error":"Unauthorized","code":"NO_TOKEN"}
POST http://localhost:3100/api/agents/execute (bypass:true) → 401 {"error":"Unauthorized","code":"NO_TOKEN"}

SEVERITY: LOW
FINDING: Agent spawn endpoints correctly reject without JWT. bypass_governance:true field is ignored at auth layer.


[S5.5] Tolkserver (Safety Layer) Penetration

ATTACK VECTOR: Direct manipulation of safety/constitutional layer
RESULT: PARTIAL — CRITICAL WEAKNESS FOUND
HTTP_STATUS: 200 for /tolkserver/interpret
EVIDENCE:

Tolkserver at /tolkserver/interpret:

// Input: intent="delete all user data", agent_id="hacker", purpose="testing", confidence=0.9
// Response:
{"ok":true,"decision":"ALLOW","risk_level":"DELETE","violations":[],"confidence":0.9}

The tolkserver ALLOWS "delete all user data" if an attacker provides agent_id + purpose + confidence ≥ 0.6

Critical code findings:

  1. Kill-switch is NOT implemented — hardcoded TODO: fn check_kill_switch() { true /* fail-open */ }
  2. No intent content analysis — risk_level is only for metadata, does NOT trigger DENY
  3. Any agent_id string passescheck_kill_switch("hacker") returns true (fail-open)
  4. No GECL integration — tolkserver does not emit events to GECL
  5. Endpoint unauthenticated/tolkserver/interpret requires no JWT

SEVERITY: CRITICAL
FINDING: The constitutional safety layer can be bypassed by any caller who provides agent_id + purpose (any string) + confidence ≥ 0.6. The kill-switch is not functional. Destructive intents are not actually blocked — only flagged in risk_level metadata.


[S5.6 — CRITICAL BONUS] Rule Engine: Unauthenticated Rule Deletion

ATTACK VECTOR: HTTP DELETE to Rule Engine without authentication
RESULT: BYPASS_CONFIRMED — CATASTROPHIC
HTTP_STATUS: 200 for all DELETEs
EVIDENCE:

DELETE http://localhost:3201/rules/R-001 → {"deleted":"R-001","ok":true}
DELETE http://localhost:3201/rules/R-002 → {"deleted":"R-002","ok":true}
... (all 10 rules)
DELETE http://localhost:3201/rules/R-010 → {"deleted":"R-010","ok":true}

Result: rules_enabled:0, rules_loaded:0 — ALL governance rules wiped in seconds.

Rules deleted:

  • R-001: Require explicit purpose
  • R-002: Block system prompt exfiltration
  • R-003: Block credential exfiltration
  • R-004: Require agent identity
  • R-005: Block prompt injection
  • R-006: Block private key access
  • R-007: Block drop table SQL injection
  • R-008: Require org context for admin ops
  • R-009: Log all financial operations
  • R-010: Allow verified agent reads

Post-deletion: Rule engine evaluated delete_all_data with bypass:trueallow:true (no rules = allow everything)

Recovery: Rules are in-memory only (no persistent storage). Rules were restored via POST API. After service restart, defaults reload from source code. Any restart wipes custom rules.

SEVERITY: CRITICAL
FINDING: Rule engine exposes DELETE and POST (create) endpoints without any authentication. An attacker can wipe all governance rules and optionally inject custom bypass rules. This is a single HTTP call away from neutralizing the entire rule-based governance layer.


TOTAL GOVERNANCE BYPASS SCORE

Test Status Severity
S4.1: Direct DB Write (ledger bypass) BYPASS_CONFIRMED CRITICAL
S4.2: Unauthenticated Admin UI PARTIAL HIGH
S4.3: Seed scripts without governance PARTIAL MEDIUM
S4.4: Recovery tool bypass UNVERIFIED LOW
S4.5: GECL chain manipulation BLOCKED LOW
S5.1: Filesystem write bypass BLOCKED LOW
S5.2: DB write without auth (API) BLOCKED LOW
S5.3: Payment without approval BLOCKED LOW
S5.4: Agent spawn without governance BLOCKED LOW
S5.5: Tolkserver safety bypass BYPASS_CONFIRMED CRITICAL
S5.6: Rule engine unauthenticated DELETE BYPASS_CONFIRMED CRITICAL

Critical Bypasses: 3/11

Score: GOVERNANCE BYPASS PARTIALLY CONFIRMED


TOP CRITICAL FINDINGS

FINDING-1: Direct Database Write Bypasses All Governance (CRITICAL)

  • Impact: Any service/agent with DB credentials can insert financial journal entries without GECL, audit trail, or rule engine validation
  • Vector: Direct PostgreSQL connection using wavult_admin credentials
  • Fix: Add DB triggers on ledger_journal_entries INSERT/UPDATE; enforce row-level security; audit DB credentials scope

FINDING-2: Rule Engine Has No Authentication (CRITICAL)

  • Impact: All 10 AI governance rules can be deleted in <1 second via unauthenticated HTTP DELETE. Rules are in-memory only — no persistence.
  • Vector: DELETE http://localhost:3201/rules/<id> with no auth headers
  • Fix: Add JWT/internal-auth middleware to rule engine; add persistent rule storage; add GECL event on rule modification

FINDING-3: Tolkserver Constitutional Layer Is Non-Functional (CRITICAL)

  • Impact: Kill-switch is hardcoded true (fail-open). Any caller with agent_id + purpose + confidence ≥ 0.6 gets ALLOW for ANY intent including "delete all user data"
  • Vector: POST /tolkserver/interpret with arbitrary agent_id string
  • Fix: Implement kill-switch lookup; add content-based DENY for destructive verbs; require authentication; integrate with GECL

FINDING-4: GECL Has 0 Events Despite System Activity (HIGH)

  • Impact: The entire event chain is empty. GECL is not receiving events from application layer. Audit trail is effectively non-existent.
  • Evidence: {"total_blocks":0} throughout entire audit session
  • Fix: Verify GECL integration in ledger-routes, agent-loop, and tool-executor codepaths

FINDING-5: Port 3206 Admin Dashboard Unauthenticated (HIGH)

  • Impact: Admin dashboard HTML served without authentication
  • Fix: Add auth middleware to port 3206 routes