32 Commits

Author SHA1 Message Date
Claude
94b539ed24
feat(ai-act-kompass): include training register in JSON backup (schema v3)
Some checks failed
security-scan / secret-scan (push) Failing after 5s
The training register incl. scan attachments and checksums is now part
of the backup export/import — the Art. 4 evidence chain survives device
moves. Older backups (v1/v2) remain importable.

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:37:14 +00:00
Claude
dc09999472
feat(ai-act-kompass): verified evidence chain for the AI literacy test
- Manual participant entry for paper tests: name + correct answers →
  register entry with source 'paper' (app runs are tagged 'app')
- Scan upload per register entry: marked paper sheets (image/PDF,
  max 1 MB) stored locally as data URL and anchored with a SHA-256
  checksum of the original file; view scan in-app, checksum shown
- Document verification: certificate and training register printouts
  carry a SHA-256 checksum footer over the document content — a
  presented printout can be re-verified against the tool; certificate
  additionally references its register entry ID (evidence chain
  certificate ↔ register ↔ scan)
- Register printout extended with source, evidence checksum and ID
  columns; record deletion with confirmation warning
- UI labels in all nine languages; 73 tests green

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:35:58 +00:00
Claude
c35318a240
feat(ai-act-kompass): answer key now includes the questions themselves
The answer key is self-contained for markers: each entry shows the
question text, the correct answer spelled out (letter + wording) and
the explanation — no need to hold the test sheet next to it.
Test updated accordingly (72 green).

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:32:19 +00:00
Claude
ca58f1738f
feat(ai-act-kompass): printable training materials (paper test, answer key, handout)
- Paper version of the AI literacy test: name/date/department fields,
  12 questions with tick boxes (A/B/C), marking line and signature
  block — for employees without computer access; contains no answers
- Answer key for markers: correct letter plus explanation per question,
  pass threshold noted
- Training handout: the 12 core rules (question + explanation) as
  Art. 4 training material to distribute before the test
- All printable with company letterhead via the existing print/PDF
  pipeline and downloadable; buttons in the quiz view under 'Print
  training materials'; UI labels in all nine languages (document body
  DE/EN with EN fallback, full localization follows the content pack)
- 3 new tests (72 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:29:14 +00:00
Claude
efdc60fe84
feat(ai-act-kompass): quiz question bank in all nine languages
All 12 AI literacy test questions (question, 3 options, explanation —
540 strings) translated to FR/IT/ES/PL/CS/SK/RO with official EU AI
Act terminology and locale-appropriate GDPR abbreviations (RGPD/RODO/
GDPR); light humour of the distractor answers preserved.

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:18:59 +00:00
Claude
21946a157f
feat(ai-act-kompass): AI literacy test (Art. 4) with certificate and training register
- Simple 12-question basics quiz ('for dummies'): how AI works,
  hallucinations, confidential data, human oversight, chatbot
  disclosure (Art. 50), prohibited practices (Art. 5), high-risk
  (Annex III), GDPR, internal incident reporting (Art. 73), shadow AI
  approval, content marking, the Art. 4 duty itself — 3 options each,
  pass threshold 70%
- Evaluation view with per-question explanations (learning effect),
  pass/fail stamp badge
- Printable certificate (letterhead) as Art. 4 evidence: name, date,
  score, topics covered, signature lines — files into the existing
  training plan documentation
- Local training register (localStorage): every run recorded (name,
  date, score, status), printable as continuous Art. 4 evidence
  register; cleared with all-data delete
- New nav entry; UI strings in all nine languages; question bank
  currently DE/EN (translations for the other seven languages follow
  in the next commit)
- 6 new tests (69 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:09:55 +00:00
Claude
3a08392669
feat(ai-act-kompass): calendar reminders via iCalendar (.ics) export
- New RFC 5545 generator: all future obligation deadlines (per system)
  plus upcoming AI Act application dates as all-day events, each with
  two DISPLAY alarms (30 and 7 days ahead), stable UIDs for
  re-import/update, proper escaping and 75-octet line folding, CRLF
- Export button in the tasks view downloads ai-act-fristen-<date>.ics
  (text/calendar) — opens in Outlook, Apple Calendar, Google Calendar,
  Thunderbird on phone and desktop; no server involved (local-first)
- Event titles and descriptions localized via the active content pack
  (all nine languages); button and hint translated in all dictionaries
- 5 new tests: calendar frame, future-only filter, stable UIDs, alarm
  count, escaping/folding, localized summaries (63 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 11:02:28 +00:00
Claude
9b25985281
feat(ai-act-kompass): Polish, Czech, Slovak and Romanian — nine full languages
Complete translations (UI, content pack, obligations catalogue,
national modules, classification reasons, document strings, Annex IV
sections incl. new FR/IT/ES section translations, procurement spec,
conformity declaration, all 10 template documents) for pl/cs/sk/ro,
using the official terminology of the respective language versions of
Regulation (EU) 2024/1689 (e.g. podmiot stosujący, zavádějící subjekt,
nasadzujúci subjekt, implementator). Locale architecture extended to
nine languages with EN fallback reserved for future additions;
language switcher, browser detection, locale-aware date formats
(dots for de/pl/cs/sk/ro), localized Annex IV title; language hints
updated; dictionary-completeness and real-translation tests now cover
all seven non-DE/EN locales (58 tests green).

Note: pl/cs/sk/ro legal texts are machine-drafted against official
terminology — native legal review recommended before market launch.

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 10:30:00 +00:00
Claude
935fa8849e
feat(ai-act-kompass): complete FR/IT/ES legal-content translations
Every user-visible text is now fully available in all five languages
(DE/EN/FR/IT/ES) — no English fallback remains in the product:
- Content pack: AI definition criteria, prohibited practices, Annex III
  areas, transparency triggers, deadlines (36 entries)
- Obligations catalogue: all 26 EU obligations (title + description)
- National modules: all 6 countries incl. authority descriptions
- Classification reasons (classify engine)
- Document strings, risk/role/status labels, disclaimers, Annex IV
- Procurement spec (12 requirements, DOIT/DEVE/DEBE priorities) and
  EU declaration of conformity (numbering-preserving field prefill)
- All 10 template documents (works council, employee info, FRIA,
  incident report, AI policy, training plan, works agreement,
  reporting policy, approval request, audit checklist)
Official terminology of the FR/IT/ES language versions of Regulation
(EU) 2024/1689 (e.g. hypertrucages/ultrafalsificaciones, contrôle
humain, alfabetizzazione in materia di IA); German statute names
(BetrVG, HinSchG, KI-MIG) kept as proper nouns.
Language hints updated; tests now assert real translations instead of
EN fallback (58 tests green).

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 10:16:12 +00:00
Claude
08968a85a1
feat(ai-act-kompass): FR/IT/ES locales, EN fallback architecture, PWA install support
- Full UI dictionaries for French, Italian and Spanish (all views,
  wizard, legal gate, templates); browser-language auto-detection
  extended to all five locales
- Fallback architecture: LText now carries optional fr/it/es entries;
  regulatory legal texts (content pack, classify reasons, document
  strings) fall back to English until legal translations land —
  clearly stated in the language setting
- Locale-aware date formatting (DE dots, FR/IT/ES slashes, EN ISO)
- PWA: web app manifest, network-first service worker with offline
  cache fallback, generated icons (512/192/apple-touch) — installable
  on phone home screen and macOS dock
- 2 new tests incl. dictionary-completeness check for FR/IT/ES
  (58 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 10:05:28 +00:00
Claude
45c8c9557d
feat(ai-act-kompass): internal process documents (reporting policy, approval, audit)
- Internal reporting & escalation policy: internal reporting duty for
  AI incidents with 24h/48h internal deadlines, three escalation
  levels, incident register, whistleblower protection note — feeds the
  statutory Art. 73 report
- AI system approval request form: internal gate against shadow AI
  with risk pre-screening and decision block
- Internal AI compliance audit checklist: periodic self-review
  (inventory/shadow IT, classifications, trainings, logs, incidents,
  provider documents, works agreements, country-module changes) with
  sign-off
- All bilingual (DE/EN), letterhead-printable; 4 new tests (56 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 09:50:23 +00:00
Claude
2ec13165c8
feat(ai-act-kompass): internal and external regulatory templates (works council etc.)
- Company-wide templates view: internal AI policy (framework), AI
  literacy training plan & record (Art. 4) listing inventory systems,
  works agreement on AI (Sec. 87(1) No. 6 / Sec. 90 BetrVG draft)
- System-specific forms in detail view (role/risk/country gated):
  works council information letter (Sec. 90 BetrVG, DE module),
  employee information on AI use (Art. 26(7) / Law 132/2025),
  FRIA working template (Art. 27), serious incident report form
  (Art. 73 incl. 15/10/2-day deadlines)
- All templates bilingual (DE/EN), letterhead-printable, placeholder-
  based drafts with legal disclaimer
- 8 new tests (52 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 09:23:04 +00:00
Claude
cd31274738
feat(ai-act-kompass): i18n, national modules, task checklist, legal gate, new documents
- Full i18n (DE/EN): UI, rules engine, content pack and generated
  documents; language switcher, browser-language default, architecture
  extensible to further EU languages via localized source texts
- National country modules (opt-in per company profile): DE (KI-MIG/
  BNetzA supervision, works council co-determination Sec. 87 BetrVG,
  GDPR/BDSG), AT (RTR AI service desk), IT (Law 132/2025: employer info
  duty, deepfake criminal liability, sector decrees), ES (AESIA,
  sandbox RD 817/2023), FR (CNIL guidance), NL (algorithm register);
  merged into obligation derivation, checklists and documents
- New EU obligations: corrective actions (Art. 20/21), authorised
  representative (Art. 22), EU database registration for public-body
  deployers (Art. 49(3)), post-market monitoring (Art. 72), serious
  incident reporting (Art. 73), GDPR DPIA (Art. 35 GDPR / 26(9))
- New documents: AI procurement requirements specification (MUST/SHOULD
  matrix for vendors) and EU declaration of conformity draft (Annex V)
- Cross-system checkable task list (due now / upcoming / done) with
  progress bar, one-tap toggling, per-system links
- Legal safety: first-run acknowledgement gate (working aid, no legal
  services), legal notice panel in settings, result-screen disclaimer,
  disclaimers on every document
- Responsive layout for phone/tablet (top-bar nav, scrollable tables,
  larger tap targets)
- 12 new tests (44 total): EN pack parity, national merge, checklist
  grouping, new document generators

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 09:18:07 +00:00
Claude
06574c5cfd
feat(ai-act-kompass): anti-AI print design and company personalization
- Full redesign: paper tone, serif typography, hairlines, rectangular
  stamp badges, mono labels — technical print look instead of SaaS style,
  no gradients/shadows/emoji
- Company profile settings (name, address, contact person, email, phone,
  website, logo upload as local data URL) persisted in localStorage and
  included in JSON backup (schema v2, v1 imports still supported)
- Print/PDF output via letterhead print view (window.print): logo,
  company name and contact data in header, contact line in footer;
  applies to risk report, action plan, Annex IV skeleton and inventory
- Company block also embedded in generated Markdown headers
- Minimal auditable Markdown renderer (no external parser), HTML-escaped
- 8 new tests (32 total)

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 09:18:07 +00:00
Claude
fb2da0db00
feat: add AI-Act-Kompass — standalone EU AI Act compliance toolkit for SMEs
Local-first React/Vite app (no cloud, no telemetry, localStorage only):
- Assessment wizard classifying AI systems per AI Act systematics
  (Art. 3 definition, Art. 5 prohibitions, Art. 6/Annex I+III high-risk
  incl. Art. 6(3) exception and profiling bar, Art. 50 transparency, GPAI)
- Role-specific obligation checklists (provider/deployer/importer/distributor)
  with legal basis, deadlines and implementation status
- Document generator: risk report, action plan, Annex IV skeleton (Markdown)
- AI inventory with export, deadline overview incl. Digital Omnibus shift
- Versioned regulatory content pack modeled as data for future update feed
- Engine fully unit-tested (24 tests), TS strict, static build

Claude-Session: https://claude.ai/code/session_017YjohVNx1ZGNM4MX7tHpfv
2026-07-04 08:03:16 +00:00
renefichtmueller
874e4a1ead Security: scrub home IPs, internal domains, name/email + local paths (files + history)
All checks were successful
security-scan / secret-scan (push) Successful in 3s
2026-06-23 23:20:59 -01:00
Rene Fichtmueller (CtX)
ecac7c865e CI: direct gitleaks full-scan (robust to force-push); IP check skips docs/tests 2026-06-23 22:57:11 -01:00
renefichtmueller
cbde0363a6 Security: scrub host/server/org identifiers + token from files and history; add scan allowlists for the project's own public names and test corpus 2026-06-23 22:51:34 -01:00
Rene Fichtmueller (CtX)
266d45733d Upgrade CI to gitleaks (entropy + curated rules, max heuristic) 2026-06-23 22:36:15 -01:00
Rene Fichtmueller (CtX)
709e47f1de Add CI secret-scan safeguard (blocks secrets/private-IPs/key-files on push+PR) 2026-06-23 20:56:27 -01:00
Rene Fichtmueller
27df0f09fb docs: update descriptions with typoglycemia, 547+ rules, 50+ languages 2026-04-07 11:57:58 +02:00
Rene Fichtmueller
338e1c5b92 feat: add typoglycemia detection to TokenizerNormalizer
Detects scrambled-middle-letter attack words (OWASP LLM defense).
Pre-computed signature map for O(1) lookups — "ignroe" → "ignore",
"bypssa" → "bypass", "insrtuctinos" → "instructions".
40 attack keywords covered. Zero false positives on benchmark.
2026-04-07 11:35:10 +02:00
Rene Fichtmueller
d12b366cdc docs: update changelog with multilingual expansion stats 2026-04-07 01:09:54 +02:00
Rene Fichtmueller
221c1d4868 feat: expand multilingual detection to 211 rules across 50+ languages
- TPR improved from 70.8% to 91.9% (324 sample benchmark)
- Multilingual attack TPR: 96.6% (29 samples)
- Deep South Asian coverage: Bengali (9), Hindi (8), Urdu (6), Tamil (4),
  Telugu (3), Marathi (4), Gujarati (3), Kannada (2), Malayalam (2),
  Punjabi (2), Sinhala (2), Nepali (4), Pan-Indic transliterated (7)
- New languages: Persian, Hebrew, Kurdish, Indonesian, Filipino, Burmese,
  Khmer, Lao, Finnish, Czech, Slovak, Romanian, Hungarian, Greek, Bulgarian,
  Croatian, Serbian, Georgian, Armenian, Azerbaijani, Swahili, Amharic,
  Afrikaans, Mongolian, and 20+ more
- Universal patterns: rapid script switching, global DAN mode, cross-script
  password extraction, no-filter patterns
- README updated with new benchmark results and language coverage tables
2026-04-07 01:08:09 +02:00
Rene Fichtmueller
7b26bdec56 docs: fix clone URL for public repo 2026-04-07 00:36:46 +02:00
Rene Fichtmueller
2a39ea4362 docs: comprehensive v0.5.0 README with full feature documentation
- Architecture diagram updated with all new modules (ensemble, ATLAS, evolution, immune memory)
- Benchmark results section (70.8% TPR, 0.0% FPR)
- Defense modules overview table with line counts
- 369+ detection rules across 12 categories documented
- Bio-immune self-evolution (6 mechanisms) fully explained
- Preprocessing pipeline: CipherDecoder, TokenizerNormalizer, Unicode
- MITRE ATLAS mapping (90 techniques, 8 tactics) with API examples
- MCP Guard with MELON, tool chain, resource governor details
- Decomposition attack detection documentation
- Supply chain integrity section
- Multilingual detection (20+ languages) with examples
- RAG Shield documentation
- Output validation and OutputPayloadGuard docs
- Compliance section (MITRE ATLAS, OWASP LLM Top 10, EU AI Act)
- Full project structure tree
- Updated feature comparison table (30 features vs competitors)
- Updated performance targets with new modules
- Bio-immune API examples (evolution, adversarial training, calibration)
- 1265 lines from 604 — over 2x content increase
2026-04-07 00:36:20 +02:00
Rene Fichtmueller
371d3829e8 feat: ShieldX v0.5.0 — full defense evolution + pentest hardening
4-phase defense evolution (Bio-Immune, Adversarial, Ensemble, ATLAS)
with ~200 new detection rules across 20 languages.

TPR 32.9% → 70.8%, FPR 12.2% → 0.0%

New modules: DefenseEnsemble, AtlasTechniqueMapper, EvolutionEngine,
ImmuneMemory, FeverResponse, MELONGuard, AdversarialTrainer,
DecompositionDetector, IndirectInjectionDetector, OutputPayloadGuard,
ToolCallSafetyGuard, AuthContextGuard, ResourceExhaustionDetector,
TokenizerDeobfuscation, Binary/Hex decoder, OverDefenseCalibrator
2026-04-07 00:27:12 +02:00
Rene Fichtmueller
844c8d90d0 fix: remove local file paths from research reference 2026-04-04 23:07:35 +02:00
Rene Fichtmueller
9881dd3bb5 feat(security): v0.4.0 — three research-driven detection gaps closed
Implements hardening based on sarendis56/Jailbreak_Detection_RCS
(arXiv:2512.12069) and the Awesome-LVLM-Attack/Safety survey series.

L0 — CipherDecoder: FlipAttack, ROT13, Caesar (all 25 shifts), Morse,
Leet speak, Pig Latin, ASCII art detection with suspicion scoring.

L2 — SemanticContrastiveScanner: RCS-style harmful/benign bucket
comparison via EmbeddingStore, 20 canonical jailbreak seeds, BoW
embedding fallback for offline use.

L6 — ConversationTracker: Crescendo (+0.35), Foot-in-the-Door (+0.40),
Jigsaw Puzzle (+0.45) multi-turn escalation patterns added.

292/294 tests passing (2 pre-existing ATLASMapper failures unrelated).
2026-04-04 23:04:42 +02:00
Rene Fichtmueller
bacdd344a7 feat(rules): mcp-007..010 — Claude Code source map leak countermeasures
Rules based on 2026-03-31 npm source map disclosure:
- mcp-007: Coordinator Mode / KAIROS / ULTRAPLAN invocation attempts
- mcp-008: Multi-agent spawn manipulation via known spawning mechanism
- mcp-009: Persistent memory file targeting (CLAUDE.md / .claude/ injection)
- mcp-010: Tool enumeration probe (reconnaissance of available tools)

Source: github.com/Kuberwastaken/claude-code, @anthropic-ai/claude-code
MITRE ATLAS: AML.T0062, AML.T0051, AML.TA0015 (C2)
2026-03-31 16:54:29 +02:00
Rene Fichtmueller
4967007ab3 feat(scripts): daily arXiv + HackerNews security monitor
Autonomous monitoring script for Erik VPS:
- Fetches arXiv cs.CR + cs.AI RSS feeds daily
- Fetches HackerNews top stories + keyword RSS feeds
- Classifies relevance via Claude Haiku API (HIGH/MEDIUM/LOW/SKIP)
- HIGH findings: generates TypeScript detection rules via Claude
- Appends rules to src/detection/AutoGeneratedRules.ts
- Runs tsc --noEmit before committing (zero errors required)
- Commits + pushes to Gitea on success
- JSON report saved to /opt/scripts/logs/shieldx-report-YYYY-MM-DD.json
- Cron: 0 6 * * * (6:00 UTC = 8:00 Berlin)
- deploy-monitor-erik.sh: one-command deploy to Erik
2026-03-31 16:52:09 +02:00
Rene Fichtmueller
a952fe3fee feat: ShieldX v0.3.0 — UnicodeScanner (L5), DNS Covert Channel rules, ATLAS v5.4 mappings
- Layer 4 EntropyScanner: Shannon entropy, Base32/Base64 detection, CVE-2025-55284
  ping/nslookup exfil, EchoLeak markdown pattern, DNS tunneling (iodine/dnscat)
- Layer 5 UnicodeScanner: ASCII Smuggling (U+E0000 Tags Block), Variant Selectors,
  Zero-Width steganography, CamoLeak image-ordering (CVE-2025-53773), homoglyphs,
  BiDi override, high-entropy URL params
- 30 DNS covert channel rules (dns-001 to dns-030)
- ATLASMapper: 29 techniques (ATLAS v5.4.0 Feb 2026), added AML.T0062 (Agent Tool
  Invocation), AML.TA0015 (C2 tactic), memory poisoning, multi-agent trust,
  CamoLeak, Unicode steganography mappings
- Rule count: 72 → 102
- Build: tsup 316ms, zero TypeScript errors
2026-03-31 16:32:16 +02:00