Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
135 commits
Select commit Hold shift + click to select a range
ad4bd3e
changed gitignore
chenjie-booker Jun 2, 2026
060e981
fix(webui): avoid misrouting absolute paths as slash commands
chenjie-booker Jun 3, 2026
544fe6a
feat:edr增加自动登录功能
luguili-booker Jul 1, 2026
aaafc48
Merge branch 'dev' of https://github.com/AgentFlocks/flocks into dev
luguili-booker Jul 1, 2026
1a244b7
feat: add project management to session sidebar
Jul 2, 2026
d4f84db
Merge branch 'dev' of https://github.com/AgentFlocks/flocks into dev
luguili-booker Jul 9, 2026
901fb16
feat: add slack channel support
Jul 10, 2026
e2d84b0
Merge remote-tracking branch 'origin/dev' into codex/slack-channel
Jul 15, 2026
6caddd5
merge: sync dev into session project branch
Jul 15, 2026
9f3b591
feat: complete project management actions
Jul 15, 2026
c575fcd
fix(hub): isolate plugin installation failures
duguwanglong Jul 15, 2026
061acc8
chore: sync main into dev after main-1f96945a07cc
github-actions[bot] Jul 15, 2026
2b81e90
Merge pull request #565 from AgentFlocks/chore/sync-main-into-dev-mai…
duguwanglong Jul 15, 2026
a9eda82
fix(hub): roll back failed plugin changes
duguwanglong Jul 16, 2026
0364cf9
fix(model): reveal provider API keys on demand
duguwanglong Jul 16, 2026
06f3839
Merge pull request #564 from AgentFlocks/fix/plugin-refresh-error-iso…
stephamie7 Jul 16, 2026
1efc3f1
Merge pull request #566 from AgentFlocks/fix/model-list-api-key-display
stephamie7 Jul 16, 2026
5530814
feat(tdp): align threat tool and action names
Jul 17, 2026
4a9da10
Add project rename and deletion safeguards
Jul 17, 2026
5d0821f
docs(tdp): clarify threat query routing
Jul 17, 2026
58c0270
Merge pull request #567 from AgentFlocks/feat/align-tdp-threat-tool-n…
duguwanglong Jul 17, 2026
a510545
fix(tui): select first provider with models
Jul 17, 2026
08d664c
Merge pull request #568 from AgentFlocks/fix/tui-default-provider-sel…
stephamie7 Jul 17, 2026
02e603e
fix(docker): use supervised service startup
Jul 17, 2026
85b7625
feat: complete project-based session management
Jul 17, 2026
2caff90
refactor(updater): simplify source upgrade handoff
Jul 17, 2026
5520722
fix(tdp): remove default incident duration cap
Jul 17, 2026
6925280
Merge pull request #572 from AgentFlocks/fix/tdp-incident-duration-fi…
duguwanglong Jul 17, 2026
d158a40
Merge latest dev into slack channel
Jul 18, 2026
c5b6221
fix(channel): gate slack member allowlist field
Jul 18, 2026
bae84e3
fix(updater): back up before detached handoff
xiami762 Jul 19, 2026
83a25a3
fix(updater): support legacy upgrade handoffs
xiami762 Jul 19, 2026
3f3f976
test(updater): exercise real handoff restarts
xiami762 Jul 19, 2026
9ecb413
test(updater): cover localized upgrade handoffs
xiami762 Jul 19, 2026
803dcc3
fix(updater): harden restart handoff compatibility
xiami762 Jul 19, 2026
568472b
fix(updater): align progress and preflight handoff
xiami762 Jul 19, 2026
8159d40
fix(updater): finish CLI handoff without terminal leaks
xiami762 Jul 19, 2026
64518fa
fix(cli): merge update apply and restart progress
xiami762 Jul 19, 2026
5b80178
fix: address project session review findings
Jul 20, 2026
783c612
fix(updater): harden legacy upgrade handoff
Jul 20, 2026
46b1fd9
fix(docker): preserve legacy port overrides
Jul 20, 2026
14b2efc
fix: distinguish source and working directories
Jul 20, 2026
5929b73
fix(workflow): cap HTTP triage LLM concurrency
duguwanglong Jul 20, 2026
865f78c
Merge pull request #570 from AgentFlocks/fix/docker-daemon-deployment
stephamie7 Jul 20, 2026
9b7d764
fix: persist collapsed project state
Jul 20, 2026
c7f85cf
fix(webui): prevent markdown from overflowing chat messages
duguwanglong Jul 20, 2026
4d175a1
Merge pull request #574 from AgentFlocks/fix/session-markdown-overflow
stephamie7 Jul 20, 2026
0ec7fce
feat: add collapsible tasks group
Jul 20, 2026
da75f61
feat: add collapsible sidebar sections
Jul 20, 2026
ee5735a
fix(updater): tolerate Windows handoff output encoding
Jul 20, 2026
517059f
fix(updater): preserve legacy handoff endpoints
Jul 20, 2026
96c7d1a
fix(channel): persist slack allowlist removal
Jul 20, 2026
5979ffe
Merge pull request #573 from AgentFlocks/fix/http-triage-concurrency-…
stephamie7 Jul 20, 2026
ccec29f
fix: address session project review issues
Jul 20, 2026
604f8b9
Merge pull request #553 from AgentFlocks/feat/session-project-management
duguwanglong Jul 20, 2026
d22a236
fix(runtime): reduce noisy warnings and harden startup
duguwanglong Jul 20, 2026
3efb482
fix(session): retry empty transport errors
Jul 20, 2026
ed19736
feat: make tool failure auto-disable configurable
duguwanglong Jul 20, 2026
6c28abf
Merge pull request #576 from AgentFlocks/fix/retry-empty-transport-er…
duguwanglong Jul 20, 2026
471fa29
fix(device-plugins): repair bundled WAF and EDR integrations
duguwanglong Jul 20, 2026
ebc101f
feat(provider): add Kimi K2.7 Code to ThreatBook CN
duguwanglong Jul 20, 2026
9965950
feat(provider): add Kimi K2.7 Code to ThreatBook IO
duguwanglong Jul 20, 2026
74b0555
Remove deprecated DeepSeek model names
Jul 20, 2026
514f85b
fix(webui): clarify stats access failures
Jul 20, 2026
7b6faf0
fix: improve slack channel setup
Jul 20, 2026
5862929
Merge pull request #571 from AgentFlocks/refactor/simple-upgrade-handoff
stephamie7 Jul 21, 2026
8cd6e9b
Merge pull request #579 from AgentFlocks/feat/add-kimi-k2-7-code
stephamie7 Jul 21, 2026
011df9f
fix: address slack review findings
Jul 21, 2026
b128aad
fix(skyeye): encode alarm list IP filters
Jul 21, 2026
d2c0617
fix(webui): clarify project session hierarchy
Jul 21, 2026
f2a36a0
fix: harden slack access controls
Jul 21, 2026
5636c11
fix(project): start folder picker from home
Jul 21, 2026
f75b05d
fix(webui): save the current browsed project folder
Jul 21, 2026
25c9cff
Merge pull request #584 from AgentFlocks/fix/skyeye-alarm-list-ip-enc…
duguwanglong Jul 21, 2026
adcb55a
Merge pull request #583 from AgentFlocks/codex/remove-deepseek-deprec…
duguwanglong Jul 21, 2026
83e8cc9
fix(webui): guard project creation on Enter
Jul 21, 2026
840f622
feat(project): add local project sharing
Jul 21, 2026
f680e01
fix(webui): align session action menu sizing
Jul 21, 2026
095c6e4
fix(webui): sync project folder input while browsing
Jul 21, 2026
097cd06
fix(webui): sync folder browser from path input
Jul 21, 2026
1253efa
fix(webui): preserve path text during folder sync
Jul 21, 2026
f9b1fc5
fix(webui): restore Pro product name fallback
Jul 21, 2026
9820ad7
Merge pull request #586 from AgentFlocks/fix/pro-product-name-fallback
stephamie7 Jul 21, 2026
b3c325e
Merge pull request #585 from AgentFlocks/fix/session-sidebar-hierarchy
stephamie7 Jul 21, 2026
0178245
feat(workflow): add integration status to cards
duguwanglong Jul 21, 2026
937279f
fix(webui): address stats failure review feedback
Jul 21, 2026
1ae903b
Merge pull request #577 from AgentFlocks/feat/configurable-tool-failu…
xiami762 Jul 21, 2026
1063806
refactor(workflow): tighten integration status contracts
duguwanglong Jul 21, 2026
e431efa
merge: resolve dev conflicts in slash command fix
Jul 21, 2026
dadacc3
Merge pull request #364 from AgentFlocks/fix/workflow_chat_no_response
duguwanglong Jul 21, 2026
0b61d3e
Fix Windows Chrome debug setup guidance
Jul 21, 2026
b683ad7
Merge pull request #582 from AgentFlocks/codex/verify-same-origin-dep…
stephamie7 Jul 21, 2026
6a49300
chore(merge): resolve dev integration conflicts
duguwanglong Jul 21, 2026
7095209
Merge pull request #575 from AgentFlocks/fix/fix-console-sync-heartbe…
stephamie7 Jul 21, 2026
2a8ae72
fix(workflow): provide tool context for trigger executions
duguwanglong Jul 21, 2026
ebbc006
fix(edr): recover browser daemon for auth flows
luguili-booker Jul 21, 2026
2df1051
Merge branch 'dev' of https://github.com/AgentFlocks/flocks into code…
luguili-booker Jul 21, 2026
1672743
fix(workflow): clean up trigger tool contexts
duguwanglong Jul 21, 2026
0610b96
Merge pull request #578 from AgentFlocks/fix/audit-device-plugins
stephamie7 Jul 21, 2026
c817275
Address Chrome debug setup review feedback
Jul 21, 2026
f0ac4d9
feat(workflow): persist configurable service ports
duguwanglong Jul 21, 2026
78fcc2d
Merge pull request #588 from AgentFlocks/codex/fix-windows-chrome-deb…
stephamie7 Jul 21, 2026
4309569
fix(webui): sync workflow chat model selection
Jul 21, 2026
b011120
fix: show visible error when model is unavailable
Jul 21, 2026
64285f6
test(workflow): isolate spawn failure from socket state
duguwanglong Jul 21, 2026
c3c9971
Merge pull request #591 from AgentFlocks/codex/fix-workflow-session-m…
stephamie7 Jul 21, 2026
049632d
Merge pull request #590 from AgentFlocks/feat/persist-workflow-listen…
xiami762 Jul 21, 2026
6709532
fix(edr): capture login token and streamline skill routing
luguili-booker Jul 21, 2026
84ff8a4
Merge remote-tracking branch 'origin/dev' into codex/fix-sangfor-edr-…
luguili-booker Jul 21, 2026
d538a64
fix: pass slack app token to preflight
Jul 21, 2026
90d1e64
Merge pull request #593 from AgentFlocks/codex/fix-sangfor-edr-daemon
duguwanglong Jul 22, 2026
1fbd859
chore(merge): sync dev into workflow status branch
duguwanglong Jul 22, 2026
54ecc11
fix(tool): reset and sync auto-disable state
duguwanglong Jul 22, 2026
389e071
Merge pull request #595 from AgentFlocks/fix/fix-tool-auto-disable-state
stephamie7 Jul 22, 2026
0d2fe60
Merge pull request #587 from AgentFlocks/feat/workflow-api-trigger-st…
xiami762 Jul 22, 2026
ec73d75
fix: support slack inbound media
Jul 22, 2026
53c6ba4
Merge pull request #589 from AgentFlocks/fix/fix-trigger-tool-context
stephamie7 Jul 22, 2026
58ebf00
fix(mcp): fail calls when connection owner exits
Jul 22, 2026
a819549
fix(mcp): cancel responses with interrupted callers
Jul 22, 2026
01bb6ae
fix(session): restore task context and bundled skills
Jul 22, 2026
7b22834
fix(question): prevent remote prompt loss
Jul 22, 2026
ae0d727
Merge pull request #596 from AgentFlocks/fix/mcp-owner-exit-unblocks-…
duguwanglong Jul 22, 2026
d1d090c
Merge pull request #592 from AgentFlocks/codex/fix-model-error-response
stephamie7 Jul 22, 2026
bb7afd4
Merge pull request #598 from AgentFlocks/fix/remote-question-popup
stephamie7 Jul 22, 2026
6efa6dd
Merge pull request #597 from AgentFlocks/fix/skill-builtin-discovery
stephamie7 Jul 22, 2026
0d02640
fix: forward new command prompt to fresh channel session
Jul 22, 2026
7484408
Merge remote-tracking branch 'origin/dev' into codex/slack-channel
Jul 22, 2026
a08c3a5
Merge pull request #581 from AgentFlocks/codex/slack-channel
stephamie7 Jul 22, 2026
1f11c67
fix(device): create instances from installed templates
Jul 22, 2026
4b076a2
fix(device): allow auth state configuration
Jul 22, 2026
1857968
Merge pull request #601 from AgentFlocks/fix/device-template-discovery
duguwanglong Jul 22, 2026
d8c90e9
chore/update-version-2026-7-22
stephamie7 Jul 22, 2026
671ee39
Merge pull request #603 from AgentFlocks/chore/update-version-2026-7-22
duguwanglong Jul 22, 2026
83e8057
fix(tools): synchronize auto-disabled state
duguwanglong Jul 22, 2026
542f570
Merge pull request #605 from AgentFlocks/fix/tool-auto-disable-state-…
stephamie7 Jul 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .flocks/flocks.json.example
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,9 @@
"readMaxBytes": 51200,
"readMaxLineLength": 2000
},
"toolFailure": {
"disableOnRepeatedFailure": true
},
"sandbox": {
"mode": "off",
"scope": "agent",
Expand Down
2 changes: 1 addition & 1 deletion .flocks/flockshub/index.json
Original file line number Diff line number Diff line change
Expand Up @@ -14573,7 +14573,7 @@
"type": "device",
"name": "Chaitin SafeLine WAF",
"description": "Chaitin SafeLine WAF OpenAPI integration.",
"version": "1.0.0",
"version": "1.0.1",
"category": "integration",
"tags": [
"waf",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
"name": "Chaitin SafeLine WAF",
"description": "Chaitin SafeLine WAF OpenAPI integration.",
"descriptionCn": "长亭雷池 WAF OpenAPI 接入。",
"version": "1.0.0",
"version": "1.0.1",
"author": "Flocks Team",
"license": "MIT",
"category": "integration",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -267,10 +267,10 @@ async def _request(
if resp.status >= 400:
return ToolResult(
success=False,
data=resp_json,
output=resp_json,
error=f"HTTP {resp.status}: {resp_text[:300]}",
)
return ToolResult(success=True, data=resp_json)
return ToolResult(success=True, output=resp_json)


def _pick(params: dict[str, Any], *keys: str) -> dict[str, Any]:
Expand All @@ -291,10 +291,9 @@ def _page_query(params: dict[str, Any]) -> dict[str, Any]:
# ---------------------------------------------------------------------------


async def host(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def host(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
cfg = _load_config(params.get("enterprise_project_id"))
pid = cfg.project_id
action = params.get("action", "")

if action == "host_list":
q = _page_query(params)
Expand Down Expand Up @@ -360,10 +359,9 @@ async def host(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
return ToolResult(success=False, error=f"Unknown action: {action}")


async def policy(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def policy(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
cfg = _load_config(params.get("enterprise_project_id"))
pid = cfg.project_id
action = params.get("action", "")

if action == "policy_list":
q = _page_query(params)
Expand Down Expand Up @@ -400,7 +398,9 @@ async def policy(params: dict[str, Any], ctx: ToolContext) -> ToolResult:

if action == "cc_rule_create":
pol_id = params["policy_id"]
body = _pick(params, "url", "limit_num", "limit_period", "lock_time", "tag_type", "action")
body = _pick(params, "url", "limit_num", "limit_period", "lock_time", "tag_type")
if params.get("rule_action") is not None:
body["action"] = params["rule_action"]
return await _request(cfg, "POST", f"/v1/{pid}/waf/policy/{pol_id}/cc", body=body)

if action == "cc_rule_delete":
Expand All @@ -415,7 +415,9 @@ async def policy(params: dict[str, Any], ctx: ToolContext) -> ToolResult:

if action == "custom_rule_create":
pol_id = params["policy_id"]
body = _pick(params, "name", "conditions", "action", "priority", "description")
body = _pick(params, "name", "conditions", "priority", "description")
if params.get("rule_action") is not None:
body["action"] = params["rule_action"]
return await _request(cfg, "POST", f"/v1/{pid}/waf/policy/{pol_id}/custom", body=body)

if action == "custom_rule_delete":
Expand Down Expand Up @@ -446,16 +448,17 @@ async def policy(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
return ToolResult(success=False, error=f"Unknown action: {action}")


async def event(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def event(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
cfg = _load_config(params.get("enterprise_project_id"))
pid = cfg.project_id
action = params.get("action", "")

if action == "event_list":
q = _page_query(params)
for k in ("from", "to", "hosts", "attacks", "action"):
for k in ("from", "to", "hosts", "attacks"):
if params.get(k) is not None:
q[k] = params[k]
if params.get("event_action") is not None:
q["action"] = params["event_action"]
return await _request(cfg, "GET", f"/v1/{pid}/waf/event/attack/logs", query=q)

if action == "event_show":
Expand All @@ -471,9 +474,11 @@ async def event(params: dict[str, Any], ctx: ToolContext) -> ToolResult:

if action == "event_export_job":
body = {}
for k in ("from", "to", "hosts", "attacks", "action"):
for k in ("from", "to", "hosts", "attacks"):
if params.get(k) is not None:
body[k] = params[k]
if params.get("event_action") is not None:
body["action"] = params["event_action"]
return await _request(cfg, "POST", f"/v1/{pid}/waf/event/attack/log/job", body=body)

if action == "threat_distribution":
Expand All @@ -500,10 +505,9 @@ async def event(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
return ToolResult(success=False, error=f"Unknown action: {action}")


async def overview(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def overview(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
cfg = _load_config(params.get("enterprise_project_id"))
pid = cfg.project_id
action = params.get("action", "")

def _time_query() -> dict[str, Any]:
q: dict[str, Any] = {}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ inputSchema:
- event_list
用途: 查询攻击事件列表(分页)
必填: 无
常用: `from`、`to`、`hosts`、`attacks`、`action`、`page`、`pagesize`
常用: `from`、`to`、`hosts`、`attacks`、`event_action`、`page`、`pagesize`
风险提示: 只读查询接口;建议传 from/to 缩小范围
是否任务型: 否
- event_show
Expand All @@ -38,7 +38,7 @@ inputSchema:
- event_export_job
用途: 下发自定义导出攻击事件的异步任务
必填: `from`、`to`
常用: `from`、`to`、`hosts`、`attacks`、`action`
常用: `from`、`to`、`hosts`、`attacks`、`event_action`
风险提示: 写操作(下发异步任务);任务完成后可通过 `event_log_download` 获取结果
是否任务型: 是
- threat_distribution
Expand Down Expand Up @@ -89,9 +89,12 @@ inputSchema:
items:
type: string
description: 攻击类型列表(如 `sqli`、`xss`、`cmdi`、`cc` 等)
action:
event_action:
type: string
description: 防护动作筛选,`block`(拦截)或 `log`(仅记录)
enum:
- block
- log
top:
type: integer
description: 返回 Top N 条数,默认 5
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -61,8 +61,8 @@ inputSchema:
是否任务型: 否
- cc_rule_create
用途: 创建 CC 防护规则
必填: `policy_id`、`url`、`limit_num`、`limit_period`、`lock_time`、`tag_type`、`action`
常用: `policy_id`、`url`、`limit_num`、`limit_period`、`lock_time`、`tag_type`、`action`
必填: `policy_id`、`url`、`limit_num`、`limit_period`、`lock_time`、`tag_type`、`rule_action`
常用: `policy_id`、`url`、`limit_num`、`limit_period`、`lock_time`、`tag_type`、`rule_action`
风险提示: 写操作;会新增 CC 规则
是否任务型: 否
- cc_rule_delete
Expand All @@ -79,8 +79,8 @@ inputSchema:
是否任务型: 否
- custom_rule_create
用途: 创建精准防护规则
必填: `policy_id`、`name`、`conditions`、`action`
常用: `policy_id`、`name`、`conditions`、`action`、`priority`
必填: `policy_id`、`name`、`conditions`、`rule_action`
常用: `policy_id`、`name`、`conditions`、`rule_action`、`priority`
风险提示: 写操作;会新增精准防护规则
是否任务型: 否
- custom_rule_delete
Expand Down Expand Up @@ -168,7 +168,7 @@ inputSchema:
tag_type:
type: string
description: CC 规则标签类型,如 `ip`、`cookie`、`header` 等
action:
rule_action:
type: object
description: 规则匹配后的动作,含 `category`(`block`/`pass`/`log`)等字段
conditions:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -156,10 +156,10 @@ async def _post(
if resp.status >= 400:
return ToolResult(
success=False,
data=resp_json,
output=resp_json,
error=f"HTTP {resp.status}: {resp_text[:200]}",
)
return ToolResult(success=True, data=resp_json)
return ToolResult(success=True, output=resp_json)


def _pick(params: dict[str, Any], *keys: str) -> dict[str, Any]:
Expand All @@ -171,9 +171,8 @@ def _pick(params: dict[str, Any], *keys: str) -> dict[str, Any]:
# ---------------------------------------------------------------------------


async def group(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def group(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
base_url, timeout, secret_id, secret_key, verify_ssl = _resolve_runtime_config()
action = params.get("action", "")

if action == "group_list":
return await _post(base_url, "/api/group/_list", {}, secret_id, secret_key, timeout, verify_ssl)
Expand All @@ -194,9 +193,8 @@ async def group(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
return ToolResult(success=False, error=f"Unknown action: {action}")


async def clnts(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def clnts(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
base_url, timeout, secret_id, secret_key, verify_ssl = _resolve_runtime_config()
action = params.get("action", "")

if action == "clnts_online":
body = _pick(params, "offset")
Expand Down Expand Up @@ -231,9 +229,8 @@ async def clnts(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
return ToolResult(success=False, error=f"Unknown action: {action}")


async def task(params: dict[str, Any], ctx: ToolContext) -> ToolResult:
async def task(ctx: ToolContext, action: str, **params: Any) -> ToolResult:
base_url, timeout, secret_id, secret_key, verify_ssl = _resolve_runtime_config()
action = params.get("action", "")

if action == "task_create":
body = _pick(params, "offset")
Expand Down
12 changes: 6 additions & 6 deletions .flocks/flockshub/plugins/workflows/stream_alert_triage/guide.md
Original file line number Diff line number Diff line change
Expand Up @@ -218,7 +218,7 @@ alert_records
| `input_paths` | 无 | 显式路径列表,优先级最高 |
| `input_path` | 无 | 单个显式路径 |
| `input_date` | 今天 | 自动发现该日所有上游 `dedup_result_*.jsonl` |
| `concurrency` | `1` | `workflow.md` 和 metadata 推荐 1;`concurrent_triage` 会限制到 1 到 5 |
| `concurrency` | `1` | 控制外层 work unit 和运行级 LLM 并发预算;`concurrent_triage` 会限制到 1 到 5 |
| `max_triage_cache_size` | `100000` | 小于 1 时回退 100000 |
| `triage_output_mode` | `soc_db` | 输出模式:`soc_db` / `jsonl` / `both` / `none` |
| `soc_db_path` | `~/.flocks/data/soc.db` | 默认 SOC DB 写入位置 |
Expand All @@ -228,10 +228,10 @@ alert_records
并发注意:

- 外层 `ThreadPoolExecutor(max_workers=concurrency)` 处理 unique work units。
- 内层每个 leader 会用 4 路并行 LLM 分支:`survey`、`cve_related`、`cve_info`、`payload_analysis`。
- 稳态 LLM 峰值约为 `concurrency * 4`
- 配置引导应默认显式给出 `concurrency=1`。如果用户要提高到 2 到 5,先说明 LLM 并发和上游工具压力,再确认。
- 当前 `load_dedup_file` 节点在完全不传 `concurrency` 时会输出 5;因此引导和样例中应显式传 `concurrency=1`,避免与文档推荐值不一致
- 每个 leader 仍会执行 `survey`、`cve_related`、`cve_info`、`payload_analysis` 4 个 LLM 分支
- 所有 `llm.ask()` 共享运行级信号量,稳态 LLM 峰值不超过 `concurrency`,不会再与 4 个分支相乘
- 配置引导应默认显式给出 `concurrency=1`。如果用户要提高到 2 到 5,先说明 LLM 和上游工具压力,再确认。
- `load_dedup_file` 在完全不传 `concurrency` 时同样输出 1,与文档和样例保持一致

leader/follower 规则:

Expand Down Expand Up @@ -298,7 +298,7 @@ leader/follower 规则:
3. 后续每行是否能按 JSON 对象解析。
4. 是否至少有 `dedup_key`、`sip`、`dip`、`req_http_url`、`threat_name` 中的关键字段。
5. 按 `dedup_key` 估算 unique work units 和 follower 数。
6. 预估 `concurrency * 4` 的 LLM 峰值
6. 确认运行级 LLM 峰值不超过 `concurrency`

真实执行验证注意:

Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "stream_alert_triage",
"nameCn": "HTTP研判工作流",
"description": "Self-contained downstream pipeline for stream_alert_denoise. Loads enriched_alerts from JSONL files written by stream_alert_denoise, then runs leader/follower concurrent triage with the tdp_alert_triage logic INLINED (no sub-workflow invocation). Alerts sharing the same dedup_key in a batch form groups; only the LEADER (first occurrence) is triaged, FOLLOWERS reuse the leader result with no extra LLM calls. Each alert's 4 LLM analysis branches (survey / cve_related / cve_info / payload_analysis) still run in parallel via a nested 4-way ThreadPoolExecutor. The semantic-tagged markdown verdict report is attached to each alert via the `triage_report` field — NO per-alert markdown file is written to disk. Persistent cache (triage_cache.pkl, FIFO LRU, file-locked, atomic write): historic dedup_key hits reuse the cached verdict/title/triage_report instantly; misses run the full inline triage and persist new results. Default persistence writes enriched triage alerts into ~/.flocks/data/soc.db alert_records; optional JSONL output is controlled by config.json or triage_output_mode=jsonl/both.",
"description": "Self-contained downstream pipeline for stream_alert_denoise. Loads enriched_alerts from JSONL files written by stream_alert_denoise, then runs leader/follower concurrent triage with the tdp_alert_triage logic INLINED (no sub-workflow invocation). Alerts sharing the same dedup_key in a batch form groups; only the LEADER (first occurrence) is triaged, FOLLOWERS reuse the leader result with no extra LLM calls. Each alert keeps the 4 LLM analysis branches (survey / cve_related / cve_info / payload_analysis), while every llm.ask call shares the run-wide concurrency budget so nested executors cannot multiply provider load. The semantic-tagged markdown verdict report is attached to each alert via the `triage_report` field — NO per-alert markdown file is written to disk. Persistent cache (triage_cache.pkl, FIFO LRU, file-locked, atomic write): historic dedup_key hits reuse the cached verdict/title/triage_report instantly; misses run the full inline triage and persist new results. Default persistence writes enriched triage alerts into ~/.flocks/data/soc.db alert_records; optional JSONL output is controlled by config.json or triage_output_mode=jsonl/both.",
"category": "default",
"status": "active",
"createdBy": null,
Expand Down
Loading
Loading