SysAI Assistant v1.7.0-beta expands Security & Exposure Intelligence with deeper infrastructure scanning, local-first CSR generation, improved operational runbooks, and stronger security audit workflows.
Highlights
Security & Exposure Intelligence
- Infrastructure Intelligence target scanner
- Service Matrix and Attack Surface Summary
- HTTP/HTTPS, SSH, mail, database and web service intelligence
- Redirect host analysis and target normalization for domains and full URLs
- Exposure scoring improvements
- Metadata leak and version disclosure analysis
- Admin/login surface detection
- Better separation between remote scans and local audits
Local-first CSR Generator
- Generate private keys and certificate signing requests locally
- RSA 2048 and RSA 4096 support
- ECDSA P-256 and ECDSA P-384 support
- SAN DNS and IP support
- Equivalent OpenSSL command output
- Copy/export workflows for private key and CSR
- No AI provider usage and no network transmission for CSR material
Secret Detection
- Expanded local-first secret detection
- Better masking of sensitive values
- Support for common config secrets, tokens, private keys and credential URLs
- Safer handling of sensitive local inputs
Permission Auditing
- Filesystem and permission audit improvements
- World-writable path detection
- SSH permission checks
- Docker socket exposure checks
- Sudoers risk analysis
Operational Runbooks
- Generate operational runbooks from troubleshooting and security results
- Verification steps
- Remediation guidance
- Rollback notes
- Prevention recommendations
Workflow Improvements
- Improved command palette coverage
- Better workflow continuity across security and troubleshooting sessions
- Reduced stale-result leakage between scan modes
- Improved history handling for meaningful operational outputs
- Updated multilingual UI coverage for English, Italian, French, German and Spanish
Notes
This is a beta-stage release intended for testing, feedback and operational evaluation.
Always review generated commands, remediation steps and security recommendations before applying them to production infrastructure.
CSR/private key generation is local-first, but private keys are sensitive: store them securely and never share them unintentionally.
Project
GitHub:
https://github.com/shadowbipnode/sysai-assistant
Support development on GitHub Sponsors:
https://github.com/sponsors/shadowbipnode
Lightning donation:
donate@shadowbip.com