Repository navigation
feat(security): add deepfake_guard — air-gapped media & document authenticity guard (#48) - #418
Merged
Merged
Conversation
…artext PII from logs
Contributor
Author
|
Pushed some follow ups addressing the gh's advanced security / CodeQL bot feedback ( While the values printed were purely synthetic mock data for offline demonstrations (no real PII involved), CodeQL’s taint analysis flagged printing dictionary keys named after document/identity fields directly to Patched both |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Implements
security/deepfake_guard(v0.1.0), an air-gapped, zero-cloud forensic engine protecting autonomous agents and KYC pipelines against synthetic media, digital tampering, and forged identity documents without external API calls or biometric data leakage.Key Capabilities
(7, 3, 1)check digits across TD1 (ID cards/residence permits), TD2, and TD3 (passports) with composite verification and expiration auditing.trainedAlgorithmicMedia, Midjourney, ComfyUI, DALL-E), and diffusion radial power spectrum slope decay.image_path), in-memory base64 (image_base64), SSRF-guarded URLs (url), or raw MRZ text (mrz_string).Acceptance Criteria Mapping
document.py,test_skill.pyforensics.py,test_deepfake_guard_simulations.pyprovenance.pyexamples/deepfake_guard_demo.py,examples/kyc_authenticity_chain_demo.py,docs/usage/skill_chaining.mddocs/skills/security/deepfake_guard.md,pyproject.tomlType of Change
skills/skills/skillware/core/loader, env, adaptersskillware/cli.py,docs/usage/cli.mdexamples/*.py, agent loops,examples/README.mdpyproject.toml,MANIFEST.inChecklist (all PRs)
Fixes #48)python -m black --check .,flake8, andruff check .pass locally (or CI-equivalent subset)pytest skills/andpytest tests/pass locally when relevantCHANGELOG.mdupdated under[Unreleased]when user-visible behavior changesexamples/README.mdupdated if this PR adds, renames, or removes a runnable scriptpytest tests/test_registry_docs.pywhen skills, examples index, or agent-loops matrix changedpytest tests/test_skill_docs.pywhen catalog Usage Examples or provider snippets changedNew or updated skill
Bundle and metadata
skills/security/deepfake_guard/manifest.yaml:name(security/deepfake_guard),version,description,parameters,constitution, realissuershort_description,issuer.github,issuer.org,requirementsEffect, Directive, Assurance
skill.py(Effect; no ad-hoc LLM-generated execution paths)instructions.md(Directive) explains when and how to use the skillcard.json(Presentation) issuer matches manifest when presenttest_skill.py(Assurance) covers execution and schema expectationsSkillLoader.load_skill("security/deepfake_guard")succeedsDocumentation and catalog
docs/skills/security/deepfake_guard.md, category hub row, row indocs/skills/README.md, anddocs/sitemap.mdConstitution and safety (skills only)
Related Issues
Fixes #48