config

package
v0.167.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 11, 2026 License: AGPL-3.0 Imports: 5 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type AgentConfig added in v0.2.5

type AgentConfig struct {
	// ConfirmIdleTimeout overrides the 5 m idle-confirmation timeout. When
	// the operator walks away without answering a confirmation prompt the
	// agent treats silence as a deny after this duration.
	ConfirmIdleTimeout time.Duration `yaml:"confirm_idle_timeout,omitempty"`
}

AgentConfig holds agent-level tunables that can be overridden via the config file. Zero values fall back to the hard-coded defaults.

type BadUSBValidatorConfig

type BadUSBValidatorConfig struct {
	Enabled       *bool  `yaml:"enabled,omitempty"`
	AllowCritical bool   `yaml:"allow_critical,omitempty"`
	WarnAction    string `yaml:"warn_action,omitempty"`
}

BadUSBValidatorConfig is the per-validator knob set for DuckyScript static analysis.

type BruceConfig added in v0.9.0

type BruceConfig struct {
	Port      string `yaml:"port,omitempty"`       // /dev/ttyACM1, COM4, etc.
	Baud      int    `yaml:"baud,omitempty"`       // default 115200
	BoardType string `yaml:"board_type,omitempty"` // hint: cardputer | m5stick | tdisplay | cyd | c5
}

BruceConfig configures the optional Bruce ESP32 backend (BruceDevices/firmware — Cardputer/M5Stick/T-Display/CYD/ESP32-C5). Empty Port disables the backend; the agent runs Flipper-only.

type BusPirateConfig added in v0.9.0

type BusPirateConfig struct {
	Port string `yaml:"port,omitempty"`
	Baud int    `yaml:"baud,omitempty"` // default 115200
}

BusPirateConfig configures the optional Bus Pirate 5 universal-bus probe (DangerousPrototypes/BusPirate5-firmware).

type Config

type Config struct {
	APIKey      string            `yaml:"api_key"`
	OpenAIKey   string            `yaml:"openai_api_key"`
	Model       string            `yaml:"model"`
	Serial      SerialConfig      `yaml:"serial"`
	Marauder    MarauderConfig    `yaml:"marauder"`
	Bruce       BruceConfig       `yaml:"bruce,omitempty"`
	Faultier    FaultierConfig    `yaml:"faultier,omitempty"`
	BusPirate   BusPirateConfig   `yaml:"buspirate,omitempty"`
	Flipper     FlipperConfig     `yaml:"flipper,omitempty"`
	Agent       AgentConfig       `yaml:"agent,omitempty"`
	Web         WebConfig         `yaml:"web"`
	Devices     map[string]Device `yaml:"devices"`
	ConfirmRisk string            `yaml:"confirm_risk,omitempty"`
	Persona     string            `yaml:"persona,omitempty"`
	// Mode selects the operation profile (see internal/mode):
	// standard | recon | intel | stealth | assault. Empty string
	// resolves to standard (no constraints, behaviour identical to
	// pre-mode builds). The CLI flag --mode overrides this value.
	//
	// Layered with ReadOnly: dispatch consults ReadOnly first, then
	// the per-mode group allow-list. Both gates are independently
	// useful — ReadOnly is the hard no-write rail; Mode is a coarse
	// capability profile (Recon blocks transmit groups, Stealth
	// blocks Marauder + RF, etc.).
	Mode string `yaml:"mode,omitempty"`

	// ReadOnly engages the v0.19.0 safety rail: dispatch refuses any
	// tool above risk.Low (no writes, no transmits, no execution, no
	// payload generation). Replaces the persona+mode allow-list maze
	// with a single boolean. Default false preserves historic CRUD
	// behaviour. The CLI flag --read-only overrides this value.
	ReadOnly bool `yaml:"read_only,omitempty"`

	Watch         WatchConfig         `yaml:"watch,omitempty"`
	Webhooks      []WebhookConfig     `yaml:"webhooks,omitempty"`
	Observability ObservabilityConfig `yaml:"observability,omitempty"`
	Validator     ValidatorConfig     `yaml:"validator,omitempty"`
	Rules         []RuleConfig        `yaml:"rules,omitempty"`
	Cost          CostConfig          `yaml:"cost,omitempty"`

	// MCPClients is the raw YAML for outbound MCP federation entries
	// (internal/mcpfed). Stored as []yaml.Node so config.go has no
	// dependency on the mcpfed package — mcpfed.ParseClientConfigs
	// decodes each node into its own ClientConfig type.
	MCPClients []yaml.Node `yaml:"mcp_clients,omitempty"`
}

func Load

func Load(path string) (*Config, error)

func (Config) GoString added in v0.2.5

func (c Config) GoString() string

GoString implements fmt.GoStringer so that %#v formatting never prints APIKey or OpenAIKey in plaintext.

func (*Config) RequireAPIKey added in v0.4.0

func (c *Config) RequireAPIKey() error

RequireAPIKey reports an error when the Anthropic API key is missing. Modes that drive Claude (REPL, --web, --voice) call this after Load. --mcp does not — the host MCP client supplies the LLM, so requiring a key here would block the documented "plug into Claude Desktop" flow.

func (Config) String added in v0.2.5

func (c Config) String() string

String implements fmt.Stringer so that %v and %s formatting never prints APIKey or OpenAIKey in plaintext.

type CostConfig

type CostConfig struct {
	Rates map[string]CostRateConfig `yaml:"rates,omitempty"`
	// BudgetUSD caps the session's cumulative cost. The cost tracker
	// fires a warning at 80% and refuses new turns past 100%. Zero
	// (the default) disables the budget. The CLI flag --budget
	// overrides this value. See internal/cost.Tracker.SetBudget.
	BudgetUSD float64 `yaml:"budget_usd,omitempty"`
}

CostConfig lets operators override the built-in per-model USD rate table. Missing entries fall back to the package defaults in internal/cost; entries present here shadow those.

type CostRateConfig

type CostRateConfig struct {
	Input  float64 `yaml:"input"`
	Output float64 `yaml:"output"`
}

CostRateConfig is one pricing entry. InputPerMTok and OutputPerMTok are USD per million tokens.

type Device

type Device struct {
	Type     string            `yaml:"type"`
	File     string            `yaml:"file"`
	Commands map[string]string `yaml:"commands,omitempty"`
}

type FaultierConfig added in v0.9.0

type FaultierConfig struct {
	Port string `yaml:"port,omitempty"`
	Baud int    `yaml:"baud,omitempty"` // default 115200
}

FaultierConfig configures the optional hextreeio Faultier USB voltage-glitcher.

type FlipperConfig added in v0.2.5

type FlipperConfig struct {
	// ExecTimeout overrides the 10 s per-command read deadline in ExecCtx.
	ExecTimeout time.Duration `yaml:"exec_timeout,omitempty"`
	// WriteFileTimeout overrides the 10 s post-payload read deadline in
	// WriteFileCtx.
	WriteFileTimeout time.Duration `yaml:"write_file_timeout,omitempty"`
	// Pipeline picks the named retry/timeout profile applied across the
	// command-dispatch layer. One of "fast", "balanced", "resilient".
	// Empty resolves to "balanced", which preserves legacy behaviour
	// byte-for-byte. The CLI flag --pipeline overrides this when set.
	Pipeline string `yaml:"pipeline,omitempty"`
}

FlipperConfig holds per-operation timeout overrides for the Flipper serial layer. Zero values fall back to the hard-coded defaults (10s).

type MarauderConfig

type MarauderConfig struct {
	Enabled  bool   `yaml:"enabled"`
	Port     string `yaml:"port"` // ignored when Bridge=true or Transport=="ble"
	BaudRate int    `yaml:"baud_rate"`

	// Transport selects the wire-level backend.
	//   - "" or "serial" — open Port at BaudRate (default; today's behaviour)
	//   - "ble"          — connect directly to a standalone ESP32-Marauder
	//                      devboard over BLE. Port is reinterpreted as the
	//                      BLE address (MAC on Linux/Windows, CoreBluetooth
	//                      UUID on macOS, or device LocalName).
	//
	// Mutually exclusive with Bridge: when Transport=="ble" the Marauder
	// reaches us directly via Bluetooth, so the Flipper UART bridge is not
	// involved. Configurable per-launch via --marauder-ble.
	Transport string `yaml:"transport,omitempty"`

	// Bridge enables Marauder-via-Flipper-USB-UART-bridge mode. When
	// true, PromptZero issues BridgeCommand on the Flipper CLI, then
	// reopens the same serial port at BaudRate and wraps it as a
	// Marauder client. Mutually exclusive with a separate-cable
	// Marauder (Port is ignored when Bridge=true).
	Bridge bool `yaml:"bridge,omitempty"`

	// BridgeCommand is the firmware-specific CLI string to launch the
	// USB-UART bridge app. Empty means use the package default
	// (`loader open "USB-UART Bridge"`). Override for forks that ship
	// the app under a different name.
	BridgeCommand string `yaml:"bridge_command,omitempty"`

	// BridgeSettle is the post-launch sleep before reopening the port
	// as a Marauder. Empty/zero means use 750ms — long enough for the
	// firmware to swap CDC handlers and re-issue line coding, short
	// enough that operators don't notice. Tune up if your kernel
	// re-enumerates the CDC node.
	BridgeSettle time.Duration `yaml:"bridge_settle,omitempty"`

	// BridgePortReopenTimeout is the max time to wait for
	// marauder.Connect() to succeed after the bridge launches.
	// Empty/zero means 5s. Increase on USB hubs with slow re-enum.
	BridgePortReopenTimeout time.Duration `yaml:"bridge_port_reopen_timeout,omitempty"`
}

type ObservabilityConfig

type ObservabilityConfig struct {
	LogLevel       string `yaml:"log_level,omitempty"`
	LogFormat      string `yaml:"log_format,omitempty"`
	LogFile        string `yaml:"log_file,omitempty"`
	MetricsEnabled bool   `yaml:"metrics_enabled,omitempty"`
	MetricsPath    string `yaml:"metrics_path,omitempty"`
}

ObservabilityConfig tunes the slog handler and Prometheus /metrics endpoint. LogFile, when non-empty, is opened append-mode alongside the stderr handler so operators keep local tailing while landing a log on disk. MetricsEnabled + MetricsPath control the /metrics route on the web server — note the surface is not auth-gated, same as the rest of the web UI.

type RuleActionConfig

type RuleActionConfig struct {
	Type    string                 `yaml:"type"`
	Tool    string                 `yaml:"tool,omitempty"`
	Params  map[string]interface{} `yaml:"params,omitempty"`
	Webhook string                 `yaml:"webhook,omitempty"`
}

RuleActionConfig is one step in a rule's Then list. Type picks the handler; the other fields are consumed depending on the type.

type RuleConfig

type RuleConfig struct {
	Name        string             `yaml:"name"`
	Description string             `yaml:"description,omitempty"`
	When        RuleMatchConfig    `yaml:"when"`
	Then        []RuleActionConfig `yaml:"then"`
	Cooldown    string             `yaml:"cooldown,omitempty"`
	Enabled     *bool              `yaml:"enabled,omitempty"`
}

RuleConfig is the YAML round-trip shape for one reactive rule. See internal/rules for the runtime surface. Cooldown uses the standard Go duration format ("30s", "1m", "2h"); empty means no cooldown.

type RuleMatchConfig

type RuleMatchConfig struct {
	Tool           string `yaml:"tool,omitempty"`
	Risk           string `yaml:"risk,omitempty"`
	Level          string `yaml:"level,omitempty"`
	OutputContains string `yaml:"output_contains,omitempty"`
	Success        *bool  `yaml:"success,omitempty"`
}

RuleMatchConfig defines audit-entry matching. Non-empty fields are ANDed; empty fields are wildcards. Tool supports a trailing "*" glob ("workflow_*") as a common convenience.

Success is a tristate: omit the key to match either outcome, set `success: true` to fire only when the tool succeeded, set `success: false` to fire only on failures. Useful for alerts like "tell me when wifi_handshake_capture fails" without hand-rolling an output_contains check.

type SerialConfig

type SerialConfig struct {
	Port     string `yaml:"port"`
	BaudRate int    `yaml:"baud_rate"`

	// TransportURL overrides Port + BaudRate when set. Accepts any
	// scheme registered with internal/flipper/transport:
	//
	//   serial:///dev/ttyACM0?baud=230400   — explicit serial
	//   mock:///dev/pts/5                   — test harness pty slave
	//   ble://AA:BB:CC:DD:EE:FF             — reserved (Phase-B)
	//
	// Empty = default behaviour (build a serial URL from Port +
	// BaudRate). This field is also settable via the --transport CLI
	// flag, which overrides whatever the config file specifies.
	TransportURL string `yaml:"transport_url,omitempty"`
}

SerialConfig carries the legacy serial-port connection fields. When TransportURL is non-empty it wins, so the port/baud fields become dead — kept here because existing config files still populate them and removing the keys would break loading.

type ValidatorConfig

type ValidatorConfig struct {
	BadUSB BadUSBValidatorConfig `yaml:"badusb,omitempty"`
}

ValidatorConfig gates the BadUSB sandbox validator. Disable with Enabled=false to run scripts unchecked (not recommended). AllowCritical lets critical findings through after logging — mainly for operators who know what they're doing and accept the risk. WarnAction picks between "warn" (log + run) and "block" (refuse) when warn findings surface.

type WatchConfig

type WatchConfig struct {
	Enabled bool        `yaml:"enabled,omitempty"`
	Paths   []string    `yaml:"paths,omitempty"`
	Rules   []WatchRule `yaml:"rules,omitempty"`
}

WatchConfig configures the --watch filesystem-trigger mode. Paths is the list of directories (or specific files) to observe. Rules describe how individual files within those paths map to prompts fed into the agent.

type WatchRule

type WatchRule struct {
	Pattern string `yaml:"pattern"`
	Prompt  string `yaml:"prompt"`
	Persona string `yaml:"persona,omitempty"`
}

WatchRule is a single pattern -> prompt mapping. Pattern uses filepath.Match syntax ("*.sub", "*.png", etc.) matched against the file's basename. Prompt is templated with {{path}}, {{dir}}, {{name}}, {{ext}} at fire time. Persona, when set, overrides the active persona for the duration of the FS-triggered turn.

type WebConfig

type WebConfig struct {
	// Host is the interface to bind the web UI to. Empty defaults to
	// "127.0.0.1" (loopback). Set to "0.0.0.0" to accept connections
	// from any interface — pair with a non-empty Token when you do.
	Host string `yaml:"host"`
	Port int    `yaml:"port"`

	// Token, when non-empty, gates every /api and /ws request behind a
	// bearer-token check. HTTP callers send `Authorization: Bearer <token>`;
	// browsers negotiate the WebSocket with `Sec-WebSocket-Protocol: bearer,
	// <token>` (the server echoes `bearer` back on success). Leave empty
	// for local-only deployments — the server prints a loud warning when
	// it's bound non-loopback without a token set.
	// PROMPTZERO_WEB_TOKEN env var overrides this field when set.
	Token string `yaml:"token,omitempty"`

	// CORSOrigins is the list of origins allowed to connect the WebSocket
	// and call /api cross-origin. Empty (default) means same-origin only.
	// Entries match the browser's `Origin` header verbatim
	// (e.g. "https://cockpit.lan"). A literal "*" is refused at Start —
	// set AllowAnyOrigin instead.
	CORSOrigins []string `yaml:"cors_origins,omitempty"`

	// AllowAnyOrigin opts in to wildcard Origin matching for cross-origin
	// WebSocket connections. Must be paired with removing "*" from
	// CORSOrigins — the indirection is intentional so a stray "*" in a
	// copy-pasted config can't silently disable Origin enforcement.
	AllowAnyOrigin bool `yaml:"allow_any_origin,omitempty"`

	// AllowUnauthedPublic, when true, falls back to the pre-fix warn-and-continue
	// behaviour when the server is bound non-loopback without a token. By default
	// (false) the server refuses to start in that configuration. Set this only in
	// controlled environments where you accept the open-access risk.
	AllowUnauthedPublic bool `yaml:"allow_unauthed_public,omitempty"`
}

type WebhookConfig

type WebhookConfig struct {
	Name    string            `yaml:"name"`
	URL     string            `yaml:"url"`
	Events  []string          `yaml:"events,omitempty"`
	Headers map[string]string `yaml:"headers,omitempty"`
	Secret  string            `yaml:"secret,omitempty"`
}

WebhookConfig is one HTTP webhook subscription. Empty Events means "all events". Secret, when non-empty, enables HMAC-SHA256 body signing via the X-PromptZero-Signature header. See internal/webhook for the runtime surface this feeds.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL