Project Sentinel — AI-Assisted Security Platform
Project Description
An AI-assisted web application security analysis platform for local lab targets: deterministic scanners (Semgrep, Trivy, Nuclei) do the finding, a pipeline normalizes and redacts secrets; the LLM only explains grounded, typed evidence, every state-changing action passes HITL plus an API gateway, and results are logged as JSONL with provenance.
Overview
Project Sentinel is an AI-assisted web application security analysis platform running against a local lab target (loopback). Its problem: triaging findings from multiple scanners is hard, and letting an LLM "help read" them without guardrails invites fabricated findings, prompt injection, or secret leakage. Sentinel is for security practitioners who want AI to explain and propose on typed evidence only, never to act on its own.
Architecture & Technical Decisions
The role split is explicit: deterministic scanners (Semgrep, Trivy, Nuclei) find and observe; a normalization pipeline redacts secrets; the agent and renderer explain but must not invent facts; actions on the target happen only after human-in-the-loop approval through the Kong Gateway with a fixed request catalog. The flow: scan → redact → normalize findings → analyze (LiteLLM, optional offline RAG grounding) → JSONL report with provenance → proposal → HITL approve/reject → executor → Kong → target → response guard → evidence recorded as digests rather than raw bodies. The target is hard-limited to loopback with external redirects refused; scanner and target content is treated as untrusted data. The repo keeps two products with separated evidence — Charter (the scan-to-HITL flow) and Workbench (local research) — and the public finding viewer uses stock DefectDojo instead of a bespoke web UI, a notable duplication-avoiding decision.
Key Features
- Secret redaction before storage or agent ingestion, with a dedicated labeled test suite
- JSONL reports with provenance; prose may not invent facts beyond typed fields
- All state-changing requests pass HITL + Kong + a predeclared catalog allowlist
- Response guard and PII controls on target responses
- A seven-scenario demo reproducible from a fresh clone, including secret-free scan-to-redaction
- As-built architecture documentation and weekly reports inside the repo
Status
The pipeline operates via scripts and JSONL reports with no bespoke web UI; live runs require operator credentials and Kong material on the operator machine. Link audit note (2026-10-09): the public documentation sites (vinsoc.manhquy.io.vn, app.vinsoc.manhquy.io.vn) were unreachable at audit time.