Skip to content

Releases: SkillAegis/SkillAegis-Editor

Inject Designer redesign

Choose a tag to compare

@mokaddem mokaddem released this 20 Jul 07:33
v1.3.0
816b0c8

Inject Designer redesign

image

Reworks scenario authoring into two linked, tool-agnostic surfaces (MISP, Suricata,
webhook, Python) that emit byte-compatible CEXF:

  • Scenario Map — a drag-driven board of the whole exercise. Set prerequisites by
    dragging cards/handles onto other injects; drop onto the start rail or timed lane to
    change when an inject fires. Replaces the old read-only dependency table.
  • Guided inject designer — a focused Task → Flow → Completion stepper, replacing the
    single flat form. Surfaces flow fields that were previously JSON-only
    (completion_trigger, followed_by).
  • Completion + live test — a visual condition builder plus a FROM / WHERE / CHECK
    query builder for data_filtering (no hand-written jq), with a raw escape hatch. The
    right pane re-runs the rule against sample data as you type: verdict, score, and a
    per-condition breakdown.

Docs added under docs/: an evaluation-strategies guide and a comparison-operators
reference. README updated with fresh screenshots of all three surfaces.

Also in this release

  • Python against live MISP data — the Python evaluation strategy can now run against
    data queried from MISP, not just the inject payload.
  • Hall-of-fame toggle — new option to hide the hall of fame.
  • Smarter inject tester — infers URL and method from query_context when testing a
    query_search.
  • Bumped the bundled skillaegis-dashboard.

Fixes

  • Docker — the container builds and runs again (the image was broken on main).
  • README install notes now mention the required submodule.

Full changelog: https://github.com//SkillAegis-Editor/compare/v1.2.2...v1.3.0

Two things to adjust before posting:

  • Replace in the changelog link with the repo owner (I can't read it — gh isn't authenticated here; the compare URL works once filled in).
  • If you'd rather keep the note strictly redesign-focused, drop the "Also in this release" / "Fixes" sections — but I'd keep them, since the Docker fix is genuinely notable for anyone who tried the previous main.