Skip to content

Mcp reliability and defectdojo export - #110

Open
derrouic wants to merge 3 commits into
blacklanternsecurity:mainfrom
derrouic:mcp-reliability-and-defectdojo-export
Open

derrouic wants to merge 3 commits into
blacklanternsecurity:mainfrom
derrouic:mcp-reliability-and-defectdojo-export

Conversation

@derrouic

Copy link
Copy Markdown

Fix skill-router startup handshake and graph pruning; add DefectDojo export

create_server() built the ChromaDB collection — loading the
all-MiniLM-L6-v2 sentence-transformers model as a side effect — before
calling mcp.run(). The server therefore did not answer the MCP
`initialize` handshake for ~43 s, well past the client's budget, and the
connection failed with -32001.

The failure was intermittent because seven MCP servers start
concurrently, so whether it lost the race depended on CPU contention. It
also presented as a broken server: probed by hand, the module imports and
starts fine.

Raising MCP_TIMEOUT only widened the window; the race remained. The
collection is now built lazily behind a memoised accessor called from the
tool bodies, so the handshake no longer waits on model loading.

Measured: handshake 42.7 s -> 1.8 s. The one-time ~12 s model load moves
to whichever of search_skills/get_skill/list_skills runs first.

Carried in this commit from the same investigation: MCP_TIMEOUT in
settings.json as a safety margin, and the mcp[cli] pin that made startup
behaviour reproducible while diagnosing.
…d cwe

Two changes to state-server, both touching update_vuln.

1. Pruning fired on the value passed, not on a transition
--------------------------------------------------------
update_vuln called _prune_sibling_vulns() whenever status="actioned" was
*passed*, not when the status actually *changed*. Since the prune query
matches on in_graph = 1, every redundant re-assert hid whichever siblings
happened to be visible at that moment, cascading a little further with
each call.

Observed in a live engagement: consolidation writes that re-asserted an
already-actioned status hid 15 distinct, independently-scored findings
from the dashboard graph, with no signal to the caller. The docstrings
already described transition semantics — the code did not implement them.

Both update_vuln and update_access now read the prior value first and
fire prune/restore only on a genuine transition. Redundant writes are a
graph no-op and omit siblings_pruned/siblings_restored from the response.

2. cvss_vector and cwe are now columns (schema v23)
---------------------------------------------------
Both were previously recorded as free text inside `details`, so any
downstream consumer had to recover them by regex — and every
vulnerability-management tool treats them as first-class fields.
Additive migration, idempotent, verified against a copy of a live
44-finding database. The vector is stored verbatim: not parsed, not
validated, not scored.
Turns the vulns table into DefectDojo Findings, either as a Generic
Findings Import file (--out, no network) or pushed to
/api/v2/import-scan/ (--push). unique_id_from_tool is stable per vuln, so
re-exporting updates existing findings instead of duplicating them.
Standard library only.

Three decisions worth stating:

Info-severity findings are skipped by default. In red-run they are mostly
refuted candidates and scope notes; importing them makes controls that
held look like open issues. --include-info overrides.

Provenance links are flattened into each finding's description under a
"Provenance" heading. DefectDojo cannot represent the chain structurally,
so the choice is prose or nothing.

The tool prints what it did not export on every run. DefectDojo models
vulnerabilities; red-run models an engagement. blocked, access,
credentials and pivot_map have no counterpart and are dropped — and
`blocked` in particular is what lets a reader tell "secure" apart from
"not looked at". The omission is deliberate, so it is made visible rather
than silent.

The export carries the findings, not the narrative. It complements the
engagement report; it does not replace it.
@github-actions

github-actions Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@derrouic

Copy link
Copy Markdown
Author

I have read the CLA Document and I hereby sign the CLA

bls-cla-bot Bot added a commit to blacklanternsecurity/CLA that referenced this pull request Aug 11, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant