Files
strix/strix/tools/reporting/reporting_sdk_tools.py
T
0xallam dfae78e8fd feat(migration): phase 2.4 — wrap remaining local SDK tools
Five tool families ported to SDK function tools using the proven
delegation pattern from Phase 2.3:

- web_search (1 tool): asyncio.to_thread around the synchronous
  Perplexity request so the 300s API call doesn't block the SDK
  event loop.

- file_edit (3 tools — str_replace_editor, list_files, search_files):
  these run *inside* the sandbox container in the legacy harness
  (sandbox_execution=True), so the SDK wrappers route through
  post_to_sandbox rather than importing the legacy module on the
  host (which pulls in openhands_aci, a sandbox-only dependency).

- reporting (1 tool — create_vulnerability_report): asyncio.to_thread
  around the legacy function, which itself runs CVSS XML parsing,
  LLM-based dedup against existing findings, and tracer persistence.

- load_skill (1 tool): legacy adapter passes ctx.context['agent_id']
  through. The legacy implementation reaches into _agent_instances,
  a global Phase 3 will replace; until then the call degrades to a
  structured error rather than crashing.

- finish_scan (1 tool): legacy adapter pattern. Validates non-empty
  fields, checks no other agents are still active (via legacy
  _agent_graph), persists the four executive sections through the
  global tracer.

Tests: 12 new tests in test_sdk_remaining_local_tools.py — registration
checks, web_search delegation + missing-key path, file_edit dispatch
shape verification, vuln-report validation + delegation, load_skill
adapter passthrough, finish_scan validation + delegation. The two
finish_scan tests use a fixture that snapshots/clears the legacy
_agent_graph['nodes'] dict so cross-test pollution from legacy
multi-agent tests doesn't mask the validation path.

Per-file ruff TC002 ignores added for the five new wrapper modules
(same reason as Phase 2.3 — RunContextWrapper must be runtime-importable
for SDK function_schema().get_type_hints()).

Refs: PLAYBOOK.md §3.5.
2026-04-25 00:21:37 -07:00

91 lines
3.0 KiB
Python

"""SDK function-tool wrapper for the legacy ``create_vulnerability_report``.
One tool. Local execution (``sandbox_execution=False`` in the legacy
registration). The legacy implementation handles XML parsing for the
CVSS breakdown and code locations, runs LLM-based dedup against
existing reports through ``strix.llm.dedupe.check_duplicate``, and
persists via ``get_global_tracer().add_vulnerability_report``.
We wrap the synchronous legacy function in ``asyncio.to_thread`` because
the dedup check makes a network call and we don't want to block the
event loop while it waits.
"""
from __future__ import annotations
import asyncio
import json
from typing import Any
from agents import RunContextWrapper
from strix.tools._decorator import strix_tool
from strix.tools.reporting import reporting_actions as _legacy
def _dump(result: dict[str, Any]) -> str:
return json.dumps(result, ensure_ascii=False, default=str)
# Generous timeout: the dedup check makes a separate LLM call, and large
# scans can have many existing reports to compare against.
@strix_tool(timeout=180)
async def create_vulnerability_report(
ctx: RunContextWrapper,
title: str,
description: str,
impact: str,
target: str,
technical_analysis: str,
poc_description: str,
poc_script_code: str,
remediation_steps: str,
cvss_breakdown: str,
endpoint: str | None = None,
method: str | None = None,
cve: str | None = None,
cwe: str | None = None,
code_locations: str | None = None,
) -> str:
"""File a vulnerability report against the active scan.
The report is dedup-checked against existing reports (LLM-based
similarity); if it's a near-duplicate, the call returns a
``duplicate_of`` pointer instead of creating a new entry.
Args:
title: Short headline (e.g. ``"Reflected XSS in /search?q="``).
description: What the vuln is.
impact: Concrete impact statement.
target: Affected URL / host / service.
technical_analysis: How it works.
poc_description: Reproduction summary.
poc_script_code: Working PoC (curl, python, etc.).
remediation_steps: Recommended fix.
cvss_breakdown: CVSS 3.1 vector parameters as XML (legacy schema).
endpoint: Optional endpoint path.
method: Optional HTTP method.
cve: Optional CVE identifier.
cwe: Optional CWE identifier.
code_locations: Optional XML list of file/line references.
"""
return _dump(
await asyncio.to_thread(
_legacy.create_vulnerability_report,
title=title,
description=description,
impact=impact,
target=target,
technical_analysis=technical_analysis,
poc_description=poc_description,
poc_script_code=poc_script_code,
remediation_steps=remediation_steps,
cvss_breakdown=cvss_breakdown,
endpoint=endpoint,
method=method,
cve=cve,
cwe=cwe,
code_locations=code_locations,
),
)