Week of April 6: security, on-prem, and Codex streaming

Shipped on-prem onboarding, stronger capture access controls, signed sharing, and live Codex steering.
securityagenton premanoncapbug fixes

Security

  • Hardened memory endpoints, capture file access, anonymous fallback behavior, XML import, CSV export, BYO key storage, and Codex tool identity checks.
  • Escaped untrusted report metadata and report prompt content before rendering.
  • Reapplied capture ACL checks to workspace Agent runs and added signed viewer access for private lab captures.

On-prem

  • Added on-prem onboarding, registry-driven secret provisioning, initial admin bootstrap guidance, and cleaner local data root handling.
  • Improved Wireshark runtime packaging, production base image pinning, and env layout deduplication.

Agent

  • Added live Codex steering, thread state passthrough, shared prompt actions, and trace-specific starter brief previews.
  • Migrated the backend AI runtime off LangChain toward the native PacketSafari Agent runtime.

Anoncap

  • Added the anoncap landing page, adaptive slicing, unsupported-payload policy controls, map reports, and upload report flows.

Bug fixes

  • Fixed manual archive and restore actions, missing capture-file handling, packetstats regeneration, analyzer runtime fallbacks, and frontend content entry syntax.