{"_id":"@agent-ix/spec-objects-security","_rev":"3-a4c3ecf7750669abc8718592074019ef","name":"@agent-ix/spec-objects-security","dist-tags":{"latest":"0.5.0"},"versions":{"0.4.0":{"name":"@agent-ix/spec-objects-security","version":"0.4.0","keywords":["agent-ix","filament","filament-module","quoin","quire","spec"],"author":{"name":"Agent IX","email":"agents@agent-ix.dev"},"license":"MIT","_id":"@agent-ix/spec-objects-security@0.4.0","maintainers":[{"name":"agent-ix","email":"peter@agent-ix.ai"}],"homepage":"https://github.com/agent-ix/spec-objects-security#readme","bugs":{"url":"https://github.com/agent-ix/spec-objects-security/issues"},"dist":{"shasum":"638047bc273a7dd96cf0a7647dcd3abda4c91e00","tarball":"https://registry.npmjs.org/@agent-ix/spec-objects-security/-/spec-objects-security-0.4.0.tgz","fileCount":27,"integrity":"sha512-Q0/OhhNmOvufQNJzyWi4ylUxd3v4DNJzyccHAPiIzITaIevAopJdKpNdiIBibicLNc+t9BVU08BOKjw3X4yZXg==","signatures":[{"sig":"MEUCIBODlEOxGmQSXAqAZy+53KIFSPyapwrnzYzdsCfRPazCAiEAyCI6JnXo9t4EZyPNlJF64yG9M9HCN/FskxGUVNni6sE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":76021},"gitHead":"574df00f09db4d05c5cf174c9142e4a76225925e","scripts":{"prepack":"node scripts/stage-npm.mjs"},"_npmUser":{"name":"agent-ix","email":"peter@agent-ix.ai"},"repository":{"url":"git+https://github.com/agent-ix/spec-objects-security.git","type":"git"},"_npmVersion":"10.9.8","description":"Filament Module: tier-2 security and identity ObjectTypes (threat, control, risk, asset, policy, auth_flow, role, scope, jwt_claim, secret)","directories":{},"_nodeVersion":"22.23.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/spec-objects-security_0.4.0_1782528788021_0.8878787867791578","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@agent-ix/spec-objects-security","version":"0.4.1","keywords":["agent-ix","filament","filament-module","quoin","quire","spec"],"author":{"name":"Agent IX","email":"agents@agent-ix.dev"},"license":"AGPL-3.0-or-later","_id":"@agent-ix/spec-objects-security@0.4.1","maintainers":[{"name":"agent-ix","email":"peter@agent-ix.ai"}],"homepage":"https://github.com/agent-ix/spec-objects-security#readme","bugs":{"url":"https://github.com/agent-ix/spec-objects-security/issues"},"dist":{"shasum":"0b4daa7b0cc935f92ee4f61e43132ebd816c4b32","tarball":"https://registry.npmjs.org/@agent-ix/spec-objects-security/-/spec-objects-security-0.4.1.tgz","fileCount":27,"integrity":"sha512-Rd58pZwH+J1iyqVjtTS70YBRlydzcEg0yoL6sJf79IPljr6K+OelApPqgHtYSu8AI/dgIZmWLjhs4WDNui/+oA==","signatures":[{"sig":"MEYCIQDyKDiUZXJ2/83GFM+mmuGzhw7KwyaXqZ5tvUtTFfYbQgIhANym1jyjVbyHHHc34UiJBKcYAgCC1mvx6YD0dcjZYJ1d","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":76035},"gitHead":"0fea2df30e037ebe33af30214e2ffd63975ebe30","scripts":{"prepack":"node scripts/stage-npm.mjs"},"_npmUser":{"name":"agent-ix","email":"peter@agent-ix.ai"},"repository":{"url":"git+https://github.com/agent-ix/spec-objects-security.git","type":"git"},"_npmVersion":"10.9.8","description":"Filament Module: tier-2 security and identity ObjectTypes (threat, control, risk, asset, policy, auth_flow, role, scope, jwt_claim, secret)","directories":{},"_nodeVersion":"22.23.0","publishConfig":{"access":"public","registry":"https://registry.npmjs.org/"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/spec-objects-security_0.4.1_1782538126756_0.9659884188852716","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@agent-ix/spec-objects-security","version":"0.5.0","description":"Filament Module: tier-2 security and identity ObjectTypes (threat, control, risk, asset, policy, auth_flow, role, scope, jwt_claim, secret)","license":"AGPL-3.0-or-later","author":{"name":"Agent IX","email":"agents@agent-ix.dev"},"keywords":["agent-ix","filament","filament-module","quoin","quire","spec"],"scripts":{"prepack":"node scripts/stage-npm.mjs"},"publishConfig":{"registry":"https://registry.npmjs.org/","access":"public"},"repository":{"type":"git","url":"git+https://github.com/agent-ix/spec-objects-security.git"},"gitHead":"a3f6c288aabc29c56d9cbece8664f1ca1608eb10","_id":"@agent-ix/spec-objects-security@0.5.0","bugs":{"url":"https://github.com/agent-ix/spec-objects-security/issues"},"homepage":"https://github.com/agent-ix/spec-objects-security#readme","_nodeVersion":"22.23.1","_npmVersion":"12.0.2","dist":{"integrity":"sha512-9A9HIH8LhWx324HsRYrB++PikClCMBpBTh/LuSmJ94eWY9sQcjF5XyYK9flTo8MATnDs/ZaEP7jDUzfqr5zp6A==","shasum":"54bc6775a8d3fda19779a488ca62a46ee10c8877","tarball":"https://registry.npmjs.org/@agent-ix/spec-objects-security/-/spec-objects-security-0.5.0.tgz","fileCount":27,"unpackedSize":76035,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBcWJFVwUxVmjQkEfMme6eP2hP/pjbP8Kt/GeAsAMi+tAiEAuG+xvP7wGTymGmrFST22WD+7p3xptXfN1JamoviuZP0="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:8ce3fcd0-4197-4e90-ae15-911b93b1bfaf"}},"directories":{},"maintainers":[{"name":"agent-ix","email":"peter@agent-ix.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/spec-objects-security_0.5.0_1786207973853_0.12141617613768774"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-27T02:53:07.823Z","modified":"2026-08-08T16:52:54.121Z","0.4.0":"2026-06-27T02:53:08.210Z","0.4.1":"2026-06-27T05:28:46.901Z","0.5.0":"2026-08-08T16:52:53.982Z"},"bugs":{"url":"https://github.com/agent-ix/spec-objects-security/issues"},"author":{"name":"Agent IX","email":"agents@agent-ix.dev"},"license":"AGPL-3.0-or-later","homepage":"https://github.com/agent-ix/spec-objects-security#readme","keywords":["agent-ix","filament","filament-module","quoin","quire","spec"],"repository":{"type":"git","url":"git+https://github.com/agent-ix/spec-objects-security.git"},"description":"Filament Module: tier-2 security and identity ObjectTypes (threat, control, risk, asset, policy, auth_flow, role, scope, jwt_claim, secret)","maintainers":[{"name":"agent-ix","email":"peter@agent-ix.ai"}],"readme":"# spec-objects-security\n\n> Filament Module: tier-2 security and identity ObjectTypes (threats, controls, auth flows, secrets, policies)\n\n`spec-objects-security` is an **Agent-IX Filament module**: a `manifest.yaml` plus per-kind authoring **skeletons** (and frontmatter schemas) that teach the spec tooling a vocabulary of object kinds. It is not a standalone app — it is loaded by [`quire-cli`](https://github.com/agent-ix/quire-cli) and [`quoin`](https://github.com/agent-ix/quoin) to author and validate Markdown spec artifacts.\n\n## Installing quire-cli\n\n`@agent-ix` packages are published to public npm. Install the CLI globally:\n\n```bash\nnpm install -g @agent-ix/quire-cli\n```\n\nSee https://github.com/agent-ix/quire-cli#install for details.\n\n## Install this module via npm\n\nThis module is also published as a config-only npm package: `@agent-ix/spec-objects-security`.\nThe package root **is** the Filament module (`manifest.yaml` + schemas/skeletons),\nso it works directly as a `--module` target or via quoin's `package:` source.\n\n```bash\nnpm install @agent-ix/spec-objects-security\n```\n\n```bash\n# quoin — resolve the module from npm by name\nquoin plugin install package:@agent-ix/spec-objects-security\n\n# or point any tool at the installed package root\nquire validate spec/**/*.md --module node_modules/@agent-ix/spec-objects-security\n```\n\n## Object types provided\n\nThis module adds the following object kinds (frontmatter `type:` value in parentheses). All kinds are tier-2 embedded ObjectTypes — they require `id`, `title` and `type` in frontmatter plus the kind-specific contract below.\n\n| Object | `type:` | Description |\n|--------|---------|-------------|\n| Auth flow | `auth_flow` | An authentication/login flow, with a `Flow` section carrying a mermaid diagram of the sequence (e.g. OIDC authorization code flow). |\n| Permission | `permission` | A single grantable permission, naming the protected `resource` kind and the `verb` (action) it grants on it. |\n| Scope | `scope` | An OAuth/authorization scope, with a `Grants` section listing the permissions the scope confers. |\n| Role | `role` | A named role, with a `Permissions` section listing the permissions bound to it. |\n| Secret | `secret` | A managed secret (e.g. client secret), with a `Rotation` section describing how and how often it rotates. |\n| Encryption key | `encryption_key` | An encryption key, with frontmatter `algorithm` (cipher) and optional `rotation` cadence. |\n| Session config | `session_config` | A session configuration, with a `Settings` section enumerating the effective session parameters (cookies, timeouts, limits). |\n| Data classification | `data_classification` | A data sensitivity class, with a `Handling` section stating the handling requirements for that class. |\n| Trust boundary | `trust_boundary` | A trust boundary between security zones, with a `Boundary` section carrying a mermaid diagram of the zones. |\n| Audit event | `audit_event` | An emitted audit/log event, with an `Event Schema` section carrying a JSON code block of its payload schema. |\n| CSRF token | `csrf_token` | A CSRF-protection token, with frontmatter `rotation_window` (how often a fresh token is issued). |\n| CORS policy | `cors_policy` | A browser cross-origin policy, with an `Origins` section enumerating the allowed origins and their rules. |\n| Password policy | `password_policy` | A password policy, with a `Rules` section enumerating the enforced password rules. |\n| MFA method | `mfa_method` | A multi-factor authentication method, with frontmatter `kind` (method kind) and optional `factor` (auth factor class). |\n| JWT claim | `jwt_claim` | A JWT/token claim, with a `Schema` section carrying a JSON code block of the claim's JSON Schema. |\n| Threat | `threat` | A threat, with frontmatter `stride_category` (STRIDE class) and `vector` (the attack vector). |\n| Control | `control` | A security control, with a `Mappings` section mapping it to the threats, risks and standards it addresses. |\n| Risk | `risk` | A risk-register entry, with frontmatter `likelihood` and `impact` qualitative ratings driving its score. |\n| Vulnerability | `vulnerability` | A vulnerability, with frontmatter `severity` and optional `cve_id` linking the public advisory. |\n| Asset | `asset` | A protected asset, with a `Description` section describing the asset and why it matters. |\n| Attack surface | `attack_surface` | An attack surface, with an `Entry Points` section enumerating the externally reachable entry points. |\n| Policy | `policy` | A normative security policy, with a `Policy` section stating the policy text. |\n| Audit finding | `audit_finding` | A security-audit finding, with a `Recommendation` section stating the remediation recommendation. |\n\n## How this module is used\n\n### With quoin (recommended)\n\n[`quoin`](https://github.com/agent-ix/quoin) is the spec-domain authoring CLI. Install the module as a plugin, then author and validate:\n\n```bash\nquoin plugin install path:../spec-objects-security\nquoin catalog list                      # list the kinds this module adds\nquoin write . --types threat,control    # scaffold artifacts of these kinds\nquoin review                            # validate authored files\n```\n\n### With quire-cli directly\n\nPoint `quire` at this module (the package directory holds `manifest.yaml` and `skeletons/`):\n\n```bash\nquire schema threat --module ./spec_objects_security                 # a kind's extraction contract\nquire validate spec/**/*.md --module ./spec_objects_security         # structural validation\nquire extract <DOC> --module ./spec_objects_security                 # extract structured data\n```\n\nSee the [quire-cli usage docs](https://github.com/agent-ix/quire-cli#usage-instructions) for all commands.\n\n## Development\n\nThis module is a flat-layout Python package (`spec_objects_security`, Python 3.13+) managed with [Poetry](https://python-poetry.org/) and built/published via GitHub Actions to Google Artifact Registry (PyPI-compatible).\n\n```bash\nmake install          # install dependencies in the Poetry venv\nmake test             # run pytest\nmake lint             # ruff + black --check\nmake format           # auto-format (ruff --fix + black)\nmake build            # build wheel + sdist under dist/\nmake local-publish    # publish to the local pypi.ix registry\nmake update-lock      # update poetry.lock\nmake use-local p=<name> / make use-upstream p=<name>   # swap a dep source\n```\n\n**CI:** GitHub Actions runs on `push`, `pull_request`, and `v*.*.*` tags — it tests, lints, builds with `poetry build`, and on tags publishes via `twine upload -r internal-pypi`. Versioning is dynamic from the Git tag. Required CI config: `GCP_SERVICE_ACCOUNT_KEY` (secret) plus `GCP_REGION`, `GCP_PROJECT_NAME`, `GCP_PYPI` (variables).\n\n## License\n\nAGPL-3.0-or-later — see [LICENSE](./LICENSE).\n","readmeFilename":"README.md"}