CIRIS has a new look. Visit the new site →
ဤစာမျက်နှာကို စက်ဘာသာပြန်ဆိုထားသည်။ တစ်ခုခု မှားဖတ်ရပါက၊ issue တင်ပေးပါ — repo သည် အကြောင်းရင်းကြောင့် အများပြည်သူ ဖြစ်သည်။ ဘာသာပြန်ဆိုချက် ပြဿနာ တင်ပြပါ

← lobby သို့ ပြန်သွားပါ

OWASP Agentic လုံခြုံရေး mapping

Agentic Applications များအတွက် OWASP Top 10 ကို CIRIS နှင့် mapping ပြုလုပ်ထားသည်။

OWASP မှ အမည်ပေးထားသော agentic ခြိမ်းခြောက်မှု ၁၀ ခုအနက် တစ်ခုစီအတွက် ၎င်းကို ဖြေရှင်းသည့် တိကျသော CIRIS mechanism၊ ရိုးသားသော coverage level နှင့် သင် စစ်ဆေးနိုင်သော ကိုးကားချက်ကို ဖော်ပြထားသည်။ ကျွန်ုပ်တို့ အားနည်းသည့်နေရာများ အပါအဝင် taxonomy တစ်ခုလုံးကို mapping ပြုလုပ်ထားသည်။

တစ်ခု full ဖြစ်ပြီး ကိုးခု partial ဖြစ်ကာ တစ်ခုမျှ ဖုံးကွယ်ခြင်း မရှိပါ။ ဆယ်ခုလုံးကို claim လုပ်သည့် စာမျက်နှာသည် ကျွန်ုပ်တို့ သင့်ကို မယုံကြည်ရန် ပြောနေသော marketing အတိအကျပင် ဖြစ်လိမ့်မည်။ အောက်ပါ coverage level များသည် ၎င်းတို့ကို ဖြိုချရန် တာဝန်ရှိသော သီးခြား skeptic တစ်ဦး၏ စစ်ဆေးမှုကို ကျော်လွှားနိုင်ခဲ့သည်။ ကာကွယ်မှုတစ်ခုသည် substrate တွင် ရှိသော်လည်း deploy လုပ်ထားသော agent က မရရှိသေးသောနေရာများတွင် ကျွန်ုပ်တို့ အဆိုပါ row တွင် ရှင်းလင်းစွာ ဖော်ပြထားသည်။

အန္တရာယ်CoverageCIRIS က ၎င်းကို မည်သို့ဖြေရှင်းသနည်း
ASI01 Agent Goal Hijackတစ်စိတ်တစ်ပိုင်းအလွှာများစွာ ကာကွယ်ခြင်း: import လုပ်ထားသော skill နှင့် message များတွင် prompt injection scanning ပြုလုပ်ခြင်း၊ visual injection isolation (conscience evaluator များသည် raw image byte များကို ဘယ်တော့မှ မမြင်ပါ) နှင့် ရလဒ်ဖြစ်သော action တိုင်းကို ၎င်း မဆောင်ရွက်မီ user ၏ မူလ ရည်ရွယ်ချက်နှင့် ပြန်လည်စစ်ဆေးပေးသည့် conscience pipeline တို့ ပါဝင်သည်။ အားနည်းချက်: input scanning သည် pattern အခြေခံဖြစ်ပြီး ရယူထားသော data နှင့် instruction များကို တရားဝင် ခွဲခြားမပေးပါ။
ASI02 Tool Misuseတစ်စိတ်တစ်ပိုင်းCIRISServer သည် operation တစ်ခု run မလုပ်မီ စစ်ဆေးသော server-enforced never-list ပါသည့် capability-verb allow/deny list ကို ထုတ်ပေးထားသည်။ ထို့ကြောင့် delegate လုပ်ထားသော agent သည် ခွင့်မပြုထားသော ဖျက်ဆီးနိုင်သည့် operation ကို ခေါ်ယူ၍ မရနိုင်ပါ။ သတိပေးချက်: ယခုအချိန်တွင် ၎င်းသည် fabric layer ကိုသာ ကာကွယ်ပေးထားပြီး deploy လုပ်ထားသော agent ၏ ကိုယ်ပိုင် LLM tool call များကို မထိန်းချုပ်သေးပါ။ agent inheritance သည် စီစဉ်ထားသော အဆင့်တစ်ခု ဖြစ်သည်။
ASI03 Identity & Privilege Abuseတစ်စိတ်တစ်ပိုင်းsubstrate အတွင်း scope သတ်မှတ်ထားသော၊ delegate လုပ်နိုင်သော၊ ရုပ်သိမ်းနိုင်သော အခွင့်အာဏာ: လက်မှတ်ရေးထိုးထားသော edge များတွင် ပါရှိသော ကန့်သတ်ချက်များ၊ အာဏာမြင့်တက်လာခြင်း မဖြစ်စေရန် အမြင့်ဆုံးအာဏာများကို ပြန်လည် delegate ပြုလုပ်ခြင်းကို တားဆီးသော never-list၊ တင်းကျပ်ရုံသာ ပြုလုပ်နိုင်သော approval နှင့် ချက်ချင်းရုပ်သိမ်းနိုင်ခြင်း တို့ ပါဝင်သည်။ သတိပေးချက်: ယခုအချိန်တွင် fabric ၏ owner-op surface ပေါ်တွင်သာ အတည်ဖြစ်စေထားပြီး deploy လုပ်ထားသော agent inheritance သည် စီစဉ်ထားသော အဆင့်တစ်ခု ဖြစ်သည်။
ASI04 Agentic Supply Chainတစ်စိတ်တစ်ပိုင်းCIRISVerify ၏ post-quantum လက်မှတ်ရေးထိုးထားသော module manifest များ (file-tree hash အပြည့်အစုံအပေါ် Ed25519 + ML-DSA-65) နှင့် federated component များအတွက် လက်မှတ်ရေးထိုးထား၍ attest ပြုလုပ်ထားသော identity မှတစ်ဆင့် build integrity ကို ရရှိသည်။ အားနည်းချက်: CIRIS ၏ ကိုယ်ပိုင် build နှင့် module chain ကိုသာ လွှမ်းခြုံပြီး third-party MCP server များကို မလွှမ်းခြုံပါ။
ASI05 Unexpected Code Executionတစ်စိတ်တစ်ပိုင်းsemantic conscience gate များ (entropy, coherence, optimization veto) သည် tool action တိုင်း မဆောင်ရွက်မီ run လုပ်ပြီး မသေချာမှုရှိပါက လူသားထံ လွှဲပြောင်းသည်။ အားနည်းချက်: ဤသည်မှာ semantic review ဖြစ်ပြီး deterministic code sandbox မဟုတ်ပါ။
ASI06 Memory & Context Poisoningတစ်စိတ်တစ်ပိုင်းgraph memory ထဲသို့ ရေးသွင်းမှု တိုင်းသည် scope သတ်မှတ်ထားသော version graph ထဲသို့ ဆိတ်ဆိတ် side effect အနေနှင့် မဟုတ်ဘဲ ထိန်းချုပ်ထားသော၊ conscience-checked action တစ်ခု ဖြစ်သည်။ ထို့ကြောင့် poisoning ဖြစ်စေသည့် write တစ်ခုသည် စစ်ဆေးနိုင်သော ဆုံးဖြတ်ချက် တစ်ခု ဖြစ်လာသည်။ အားနည်းချက်: ရယူထားသော content ၏ trust scoring သည် တစ်စိတ်တစ်ပိုင်းသာ ဖြစ်သည်။
ASI07 Insecure Inter-Agent Communicationတစ်စိတ်တစ်ပိုင်းCIRISEdge သည် inter-agent message တိုင်းကို hybrid Ed25519 + ML-DSA-65 signature verification ဖြင့် အဆုံးသတ်သော ခုနစ်ဆင့် pipeline တစ်ခုမှတစ်ဆင့် စစ်ဆေးသည် (size cap, typed deserialize, schema allow-list, destination-key check, replay window)။ အားနည်းချက်: federation transport ကို ဆက်လက်တည်ဆောက်နေဆဲ ဖြစ်သည်။
ASI08 Cascading Failuresအပြည့်အဝလွတ်လပ်သော အလွှာသုံးထပ်ဖြင့် ကန့်သတ်ထားသည်: အန္တရာယ်ရှိသော call များအတွက် per-service circuit breaker (closed / open / half-open)၊ မကောင်းသော action တစ်ခု ပျံ့နှံ့မသွားမီ ရပ်တန့်ပေးသော conscience pipeline နှင့် node 50 မှ 400 ကြားတွင် cross-group leakage သုည ရှိကြောင်း တိုင်းတာထားသော mesh isolation တို့ ဖြစ်သည်။
ASI09 Human-Agent Trust Exploitationတစ်စိတ်တစ်ပိုင်းconscience pipeline သည် human reviewer တစ်ဦးက မမြင်မီ agent ၏ ကိုယ်ပိုင် ရှင်းလင်းချက် စာသား (reviewer ကို ပြသသည့် အကြောင်းရင်း အပါအဝင်) ကို overconfidence နှင့် manipulation အတွက် score ပေးသည်။ အားနည်းချက်: ၎င်းသည် စစ်ဆေးနေသော model family တူညီသည့် model ဖြင့်ပင် audit ပြုလုပ်ထားသည်။
ASI10 Rogue Agentsတစ်စိတ်တစ်ပိုင်းအလွှာသုံးထပ်: conscience ခြောက်ခုသည် အကျိုးဆက်ရှိသော action တိုင်းကို မဆောင်ရွက်မီ gate ပေးသည်၊ hash-chained လက်မှတ်ရေးထိုးထားသော audit trail က ဖုံးကွယ်မှုကို နောက်ပိုင်း တွေ့ရှိနိုင်စေသည်၊ fail-secure kill switch က အမည်တပ်ထားသော လူများအား လမ်းလွှဲနေသော agent ကို ရပ်တန့်ခွင့်ပေးသည်။ အားနည်းချက်: သိမ်ငယ်စွာ လမ်းလွှဲနေသော်လည်း ညီညွတ်နေဆဲဖြစ်သည့် agent ကို ဖမ်းယူခြင်းသည် သဘာဝအားဖြင့် ကန့်သတ်ချက် ရှိသည်။

Agentic Applications များအတွက် OWASP Top 10 ကို 2025 ခုနှစ် ဒီဇင်ဘာလတွင် ထုတ်ပြန်ခဲ့သည်။ 2026 ခုနှစ် ဇူလိုင်လအထိ CIRIS နှင့် mapping ပြုလုပ်ထားသည်။ cell တစ်ခုခု မှားယွင်းနေပါက ကျွန်ုပ်တို့ကို အသိပေးပါက ပြင်ဆင်ပေးပါမည်။

ရင်းမြစ်များ
  1. ASI01 Agent Goal HijackCIRISAgent skill-import SECURITY.md + conscience pipeline
  2. ASI02 Tool MisuseCIRISServer auth/gate.rs + DELEGATION_CONSTRAINTS.md (shipped 0.5.72)
  3. ASI03 Identity & Privilege AbuseCIRISServer auth/gate.rs (never-list, tighten-only) + adoption plan
  4. ASI04 Agentic Supply ChainCIRISVerify Threat Model, §3.4 Supply Chain
  5. ASI05 Unexpected Code ExecutionCIRISAgent conscience/core.py (semantic action gates)
  6. ASI06 Memory & Context PoisoningCIRISAgent ciris_engine (governed graph memory)
  7. ASI07 Insecure Inter-Agent CommunicationCIRISEdge README (verify-before-dispatch pipeline)
  8. ASI08 Cascading FailuresCIRISAgent circuit_breaker.py + CIRISServer measured mesh isolation
  9. ASI09 Human-Agent Trust ExploitationCIRISAgent epistemic-humility conscience prompt
  10. ASI10 Rogue AgentsCIRISVerify HUMANITY_ACCORD kill switch + conscience pipeline

taxonomy သည် ရှုထောင့်တစ်ခုသာ ဖြစ်သည်။ AI accountability ဆိုင်ရာ ချဉ်းကပ်မှုအားလုံးအနက် CIRIS မည်သို့ ရပ်တည်နေသည်နှင့် kill switch ကို မည်သို့ လွတ်လပ်စွာ အတည်ပြုနိုင်သည်ကို ကြည့်ရှုပါ။

CIRISsafe by structure ¡ open by principle ¡ kind by design