Week of April 13: Agent evidence, TCP diagnosis, and corpus coverage

Improved Agent evidence rendering, TCP diagnostics, upload readiness, and contextual detections.
agentbug fixesperformancesecurityplatform

Agent

  • Improved Codex Agent evidence rendering, cache and endpoint evidence cards, transcript rendering, and error handling.
  • Fixed stale starter-brief runs, upload insight readiness, and Codex tool transcript rendering.
  • Added on-demand deep TCP diagnosis and richer analysis UX around packet evidence.

Analyzer

  • Added modeled TCP composite views, viewport-aware TCP charts, PMTUD fallback detection, malware delivery chain detection, and legacy exfiltration signals.
  • Expanded contextual severity handling for timing, transport, and TLS-SIP cases.
  • Restored corpus case library surfaces and connected PCAP inventory into admin and packet-stats documentation.

Performance

  • Guarded PCAP sparklines against huge histograms and gated the web delivery detector with PacketStats.
  • Used lightweight upload status streams for live upload insights.

Bug fixes and security

  • Tightened auth behavior, magic login expiry coverage, tool execution fallbacks, dependency age policy, and runtime compatibility.
  • Fixed paginated totals in PCAP lists and local Wireshark column sync drift.