This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+5 more
Affected surfaces
Summary
AI summaryUpdates Security & Exposure Intelligence, Local-first CSR Generator, and Workflow Improvements across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds infrastructure intelligence target scanner for multiple protocols. Adds infrastructure intelligence target scanner for multiple protocols. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds Service Matrix and Attack Surface Summary reports. Adds Service Matrix and Attack Surface Summary reports. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Improves exposure scoring algorithm for detected assets. Improves exposure scoring algorithm for detected assets. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds metadata leak and version disclosure analysis to scans. Adds metadata leak and version disclosure analysis to scans. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Detects admin/login surfaces during infrastructure scanning. Detects admin/login surfaces during infrastructure scanning. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds local‑first CSR generator supporting RSA 2048/4096 and ECDSA P-256/P-384. Adds local‑first CSR generator supporting RSA 2048/4096 and ECDSA P-256/P-384. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Adds SAN DNS and IP support to local‑first CSR generation. Adds SAN DNS and IP support to local‑first CSR generation. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Expands local‑first secret detection to cover common config secrets, tokens, private keys and credential URLs. Expands local‑first secret detection to cover common config secrets, tokens, private keys and credential URLs. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Improves filesystem permission audit with world‑writable path, SSH, Docker socket and sudoers risk detection. Improves filesystem permission audit with world‑writable path, SSH, Docker socket and sudoers risk detection. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Generates operational runbooks including verification, remediation, rollback and prevention steps. Generates operational runbooks including verification, remediation, rollback and prevention steps. Source: llm_adapter@2026-06-14 Confidence: high |
— |
| Feature | Low |
Enhances separation between remote scans and local audits. Enhances separation between remote scans and local audits. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Adds redirect host analysis and target normalization for domains/URLs. Adds redirect host analysis and target normalization for domains/URLs. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Provides equivalent OpenSSL command output for CSR generation. Provides equivalent OpenSSL command output for CSR generation. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Offers copy/export workflows for private key and CSR. Offers copy/export workflows for private key and CSR. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Improves masking of sensitive values in secret detection. Improves masking of sensitive values in secret detection. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Adds SSH permission checks to permission auditing. Adds SSH permission checks to permission auditing. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Includes Docker socket exposure checks in permission audits. Includes Docker socket exposure checks in permission audits. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Adds sudoers risk analysis to permission auditing. Adds sudoers risk analysis to permission auditing. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Improves command palette coverage for workflow continuity. Improves command palette coverage for workflow continuity. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Reduces stale‑result leakage between scan modes in workflows. Reduces stale‑result leakage between scan modes in workflows. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Enhances history handling for meaningful operational outputs. Enhances history handling for meaningful operational outputs. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
| Feature | Low |
Updates multilingual UI coverage to English, Italian, French, German and Spanish. Updates multilingual UI coverage to English, Italian, French, German and Spanish. Source: granite4.1:30b@2026-06-14-audit Confidence: low |
— |
Full changelog
SysAI Assistant v1.7.0-beta expands Security & Exposure Intelligence with deeper infrastructure scanning, local-first CSR generation, improved operational runbooks, and stronger security audit workflows.
Highlights
Security & Exposure Intelligence
- Infrastructure Intelligence target scanner
- Service Matrix and Attack Surface Summary
- HTTP/HTTPS, SSH, mail, database and web service intelligence
- Redirect host analysis and target normalization for domains and full URLs
- Exposure scoring improvements
- Metadata leak and version disclosure analysis
- Admin/login surface detection
- Better separation between remote scans and local audits
Local-first CSR Generator
- Generate private keys and certificate signing requests locally
- RSA 2048 and RSA 4096 support
- ECDSA P-256 and ECDSA P-384 support
- SAN DNS and IP support
- Equivalent OpenSSL command output
- Copy/export workflows for private key and CSR
- No AI provider usage and no network transmission for CSR material
Secret Detection
- Expanded local-first secret detection
- Better masking of sensitive values
- Support for common config secrets, tokens, private keys and credential URLs
- Safer handling of sensitive local inputs
Permission Auditing
- Filesystem and permission audit improvements
- World-writable path detection
- SSH permission checks
- Docker socket exposure checks
- Sudoers risk analysis
Operational Runbooks
- Generate operational runbooks from troubleshooting and security results
- Verification steps
- Remediation guidance
- Rollback notes
- Prevention recommendations
Workflow Improvements
- Improved command palette coverage
- Better workflow continuity across security and troubleshooting sessions
- Reduced stale-result leakage between scan modes
- Improved history handling for meaningful operational outputs
- Updated multilingual UI coverage for English, Italian, French, German and Spanish
Notes
This is a beta-stage release intended for testing, feedback and operational evaluation.
Always review generated commands, remediation steps and security recommendations before applying them to production infrastructure.
CSR/private key generation is local-first, but private keys are sensitive: store them securely and never share them unintentionally.
Project
GitHub:
https://github.com/shadowbipnode/sysai-assistant
Support development on GitHub Sponsors:
https://github.com/sponsors/shadowbipnode
Lightning donation:
[email protected]
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About shadowbipnode/sysai-assistant
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]