docs: document Nuclei/ZAP as decided deterministic detectors under the agentic DAST (not yet implemented)
CI / Check (push) Skipped
CI / Check (pull_request) Failing after 2m55s
CI / Detect Changes (pull_request) Skipped
CI / Deploy Agent (pull_request) Skipped
CI / Deploy Dashboard (pull_request) Skipped
CI / Deploy Docs (pull_request) Skipped
CI / Deploy MCP (pull_request) Skipped

Spec v0.2.1 decision (2026-08-31): keep the agentic DAST/pentest layer, integrate
Nuclei then ZAP baseline underneath as deterministic detectors feeding the
control-map LUT; offline vuln DB (Trivy/Grype) on the on-prem runner trigger.
Clearly marked as planned so the docs stay truthful until the code lands.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EgxGHn22YEfQz5fLHSHkLv
This commit is contained in:
Sharang Parnerkar
2026-08-31 15:12:41 +02:00
co-authored by Claude Fable 5
parent b7b9c812ab
commit 61c6eab54e
3 changed files with 16 additions and 1 deletions
+1 -1
View File
@@ -6,7 +6,7 @@ Control mapping connects the scanner's raw output — deterministic tool finding
The design has one rule, borrowed from the ZeroFalse / IRIS line of research: **deterministic tools are the detectors; the LLM is only ever a grounded false-positive filter, never the thing that finds the issue.**
- A tool (semgrep, gitleaks, syft/osv, the DAST agents, the PLC linter) detects deterministically.
- A tool (semgrep, gitleaks, syft/osv, the PLC linter; the DAST agents today, with **Nuclei and ZAP planned** as deterministic web/OT detectors underneath them — see [Tools & Scanners](/reference/tools#planned-integrations-decided-2026-08-31-not-yet-in-the-code)) detects.
- An **authored, human-reviewed lookup table** (`control-map`) maps that detection to the control(s) it's evidence for.
- The LLM enters last, to *confirm or refute* the mapping against the actual code — and every surviving verdict is anchored to a verbatim snippet by the grounding gate.