Week of April 6: security, on-prem, and Codex streaming
On-premises onboarding, capture access controls, signed sharing, and live Codex steering strengthen secure PacketSafari investigation workflows and reporting.
securityagenton premanoncapbug fixes
Security
- Hardened memory endpoints, capture file access, anonymous fallback behavior, XML import, CSV export, BYO key storage, and Codex tool identity checks.
- Escaped untrusted report metadata and report prompt content before rendering.
- Reapplied capture ACL checks to workspace Agent runs and added signed viewer access for private lab captures.
On-prem
- Added on-prem onboarding, registry-driven secret provisioning, initial admin bootstrap guidance, and cleaner local data root handling.
- Improved packet-engine consistency and on-prem configuration reliability.
Agent
- Added live Codex steering, thread state passthrough, shared prompt actions, and trace-specific starter brief previews.
- Improved Agent continuity and reduced dependency on intermediary AI components.
Anoncap
- Added the anoncap landing page, adaptive slicing, unsupported-payload policy controls, map reports, and upload report flows.
Bug fixes
- Fixed manual archive and restore actions, missing capture handling, PacketStats recovery, analyzer fallbacks, and content rendering errors.
