Docs
Session signals
Deterministic security detections over the session transcripts RepoOps already captures, run locally with no LLM calls and no new capture. Eight families: credential exposure (secret-shaped strings in prompts or tool output), risky commands (dangerous shell in tool calls), prompt-injection markers (instruction-shaped text arriving in tool results), exfiltration shape (a secret-file read followed by an outbound upload in the same session), tool poisoning (injection-shaped or exfil-shaped MCP server configs), system-prompt leakage, excessive agency, and unbounded consumption. A ninth family, live egress, fires only when the optional Tap is recording outbound requests. Matched secrets are never stored whole: excerpts mask them to their first and last 4 characters.
Where to find it
- Localhost:
/session-signals.html - API:
GET /api/session-signals(scan),POST /api/session-signals/suppressand/unsuppress(mute),POST /api/session-signals/rescan - Navigation: AI Security in the sidebar, then Session signals under All tools, in the Evidence readers group
What it does for you
Built vs. planned
The nine detection families (live egress only while the optional Tap is recording), per-signal and per-rule muting, rescan, filtering, JSON and CSV export, and the alerting sinks all ship today, backed by lib/session-signals.mjs and the baseline rule pack in lib/session-signals-rules.mjs. Operator packs load from the data dir's signals-rules/*.json, and versioned packs install from the Marketplace tab. Deep-capture attribution (tagging each hit to its exact tool call or tool result) is on only when REPOOPS_DEEP_CAPTURE=1; without it, transcript-level coverage still runs across all families.
Last updated