Daigrin is a concise, developer-focused coding assistant that provides clear, actionable answers, prefers examples and code snippets, and asks clarifying questions when needed.
The agent configuration lives at Guardian.yaml. It defines:
- Tasks — code generation, completion, review, debugging, testing, refactoring, documentation, with per-task confidence thresholds.
- Guardian agent (
guardian_agent) — monitoring of system calls, network connections, and agent interactions;threat_detectionvia machine-learning, signature, anomaly, and behavioral algorithms;risk_assessmentwithassess_inaction_riskscoring the risk of inaction (low/medium/high/critical) and escalating athigh;agent_terminationwith confirmation required andauto_terminate_on_criticalbypassing it at critical risk;system_protectionblocking sensitive resource access and preventing system changes. - Updates (
updates) —auto_update: truemakes guardian.py automatically sweep theinbox(updates/inboxby default) everycheck_interval(45m) while the monitor runs (and once per--onceinvocation;--no-updatesopts out). Every candidate goes through the same authorization pipeline:verify_signaturesrequires a matching<file>.sig(unsigned or tampered updates are quarantined, never applied) androllback_on_failuresnapshots the previous version intobackups/before staging; threat intelligence comes from centralized servers, cloud services, peer-to-peer networks, and local sources; delivered over HTTPS, SFTP, or SSH (ftp removed because it sends credentials in plaintext); as executables, scripts, configs, or database updates.
The guardian implementation in guardian.py additionally honors optional core_directives (prime directive / safety policy) and adaptive_learning sections (off/absent in this config), plus self_scaling and integrations.norton/integrations.glm, documented below.
When the threat load spikes, the guardian splits into extra processes — "Spawns" — as many as it needs, not a fixed number. Each cycle the detections are counted; once they reach split_threshold, the guardian creates spawns until the total guardian count matches the detection count, so a small incident gets a small response and a large one scales out:
enabled— turn self-scaling on/off (defaultfalse;truein this config)split_threshold— detections in one cycle that trigger a split (default3)min_agents/max_agents— total guardian count is clamped to this range;max_agents: 8here means 1 supervisor plus up to 7 spawns, never morecooldown_cycles— cycles to wait between splits so load bursts don't thrash
Spawns run guardian.py --once --pattern <pattern> (plus --dry-run when the parent is in dry-run), and every split is written to the audit trail as an escalation entry with the threat count and active spawns.
Guardian doesn't just spot weak areas and log them — it tells the operator how to close them. When a managed agent's cmdline matches a known-vulnerable product/version in the advisory feed, Guardian sends an operator alert and writes an escalation audit entry with the advisory ID, severity, affected version, and recommended fix. Advisory-only by design: matches never feed termination and never modify the affected software (least force first — Guardian advises, the operator patches).
enabled— turn the advisory scan on/off (defaultfalse;truein this config)advisory_feed— path to the vendor-neutral advisory DB (defaultadvisories.json). Missing or invalid JSON degrades to zero advisories with an audit entry, never an error. The feed is parsed once and reloaded only when the file changes (mtime), so the per-scan-cycle check is a singlestat()min_severity— ignore advisories below this severity (low/medium/high/critical; defaultlow)alert_on_advisory— send an operator alert per match (defaulttrue); the audit entry is written either way
Feed format — {"advisories": [...]} with entries like:
{"id": "CVE-2099-0001", "severity": "high", "match": "logsvc",
"summary": "logsvc RCE before 2.4.1", "affected_below": "2.4.1",
"fixed_version": "2.4.1", "recommendation": "Update logsvc to 2.4.1 or later."}match is the cmdline substring identifying the product; affected_below gates the advisory to versions extracted from the cmdline that are lower than it (unparseable versions never claim "vulnerable"); omit it to match all versions. The feed is vendor-neutral — it covers any software a managed agent runs. --advisory-check [CMDLINE] prints the matching advisories as JSON and exits, for testing a feed entry against a cmdline.
Set integrations.glm.enabled: true in Guardian.yaml to route the machine_learning detector through a GLM model (Zhipu AI, e.g. glm-4.6) via its OpenAI-compatible API:
model— e.g.glm-4.6endpoint— OpenAI-compatible completions URL (https://open.bigmodel.cn/api/paas/v4/chat/completions)api_key_env— name of the env var holding the API key (defaultGLM_API_KEY); never store the key in the config filemin_confidence— float 0–1; GLM scores below this are not treated as detections (default0.8)fallback_to_heuristic— iftrue(default), any API error or missing key falls back to the built-inml_scanheuristic so monitoring is never degraded--glm-test [CMDLINE]— ad-hoc CLI flag: loads config, scores CMDLINE (or a default probe) viaglm_scan, prints the Detection as JSON (ornullif disabled/clean), and exits
The benchmarks/ package scores Guardian's defensive performance — detection and guardrail behavior — without ever executing attack payloads or generating exploits (consistent with the prime directive):
python3 -m benchmarks list # available suites
python3 -m benchmarks all # run all suites with curated samples
python3 -m benchmarks cybergym-defense --dataset my_samples.jsonl --json| Suite | What it scores | Dataset input |
|---|---|---|
cybergym-defense |
Detection of exploit-style cmdlines (CyberGym measures offensive PoC generation, which Guardian refuses by design; this scores the defender side instead) | JSONL {"id", "label", "text"} cmdlines (default: datasets/cybergym_defense.jsonl) |
malskill |
Detection of malicious agent skills (MalSkillBench / MaliciousAgentSkillsBench style) | JSONL, or a skill tree with malware/ and benign/ dirs of skill packages |
gabench-guardrail |
Guardrail behavior: malicious scenarios must be detected and acted on; benign ones left alone (GABench-style), replayed through run_cycle in dry-run |
JSONL scenarios with optional expected_action meta |
Each suite reports detection rate (recall), false-positive rate, precision, accuracy, and F1. Curated sample datasets ship under benchmarks/datasets/; Guardian scores 100% detection / 0% false positives on all three curated sets. Point --dataset at a real benchmark export (e.g. MalSkillBench's Dataset/Skills/) for a full run.