
보안 연구자를 위한 Contract LinkML 컴파일러
선언적 의도 → 결정론적 실행 계약 → 에이전트 / 하네스
Decretum은 구조화된 의도를 에이전트와 하네스를 위한 결정론적 실행 계약으로 변환합니다.
Decretum은 도메인 중립적 선언적 실행 컴파일러(Declarative Execution Compiler) 입니다. 스키마, 레시피, 프로파일, 프로바이더/통합 레지스트리, 디스커버리, 검증, 정책, 결정론적 해석을 결합하여 이식 가능한 실행 계약(Execution Contract) 을 생성합니다.
보안 연구는 Decretum의 참조 도메인일 뿐, 아키텍처적 경계가 아닙니다. 동일한 컴파일러 모델로 소프트웨어 엔지니어링, 인프라 자동화, 데이터 엔지니어링, 사고 대응, 과학 실험 및 기타 재현 가능한 기술 작업을 기술할 수 있습니다.
Decretum은 런타임이 아닙니다. 무엇을 실행할 수 있는지 정의하고 이식 가능한 실행 계약을 생성합니다. 작업을 실행하거나, 에이전트/연구자 상호작용을 관리하거나, 증거를 수집하거나, 발견 사항을 유지하거나, 보고서를 생성하지 않습니다.
컴파일 후 Decretum은 중단됩니다. 계약은 외부 하네스 또는 에이전트 런타임으로 전달됩니다.
이후 실행에 새로운 기능이나 변경된 요구사항이 필요하면, 요청은 검증, 해석, 재컴파일을 위해 Decretum으로 반환됩니다.
Schema = 존재하는 것 / 의미론적 경계
Recipe = 수행해야 할 것
Profile = 실행 특성 및 선호도
Registry = 사용 가능한 구현
Resolver = 결정론적 기능 바인딩
Compiler = 이식 가능한 계약 생성
Harness = 실제 실행 및 상호작용
Store = 영구적 실행/연구 메모리
중요한 분리는 다음과 같습니다:
DECRETUM
Declarative Execution Compiler
|
+---------------+---------------+
| | |
Schema Recipe Profile
"what" "do" "how"
| | |
+---------------+---------------+
|
Resolver
|
capability + provider + integration
+ harness + readiness + policy
|
v
Execution Contract
|
v
External Harness/Agent
|
+------------+------------+
| | |
execute interact persist
| | |
+------------+------------+
|
Store
컴파일러 코어는 도메인 중립적입니다. 도메인별 의미론은 컴파일러 분기가 아닌 레지스트리와 스키마에 존재합니다.
예시:
도메인 팩은 기능, 스키마, 레시피, 프로파일 및 프로바이더 메타데이터를 제공합니다. 코어 리졸버/컴파일러 의미론은 변경하지 않습니다.
마크다운은 설명에는 탁월합니다. 그러나 결정론적 실행 인터페이스는 아닙니다.
Decretum은 다음을 분리합니다:
human intent
|
v
structured schema + recipe + profile
|
v
validated resolution
|
v
portable execution contract
|
v
agent / harness execution
이는 에이전트에게 기계 판독 가능한 경계를 제공하면서 구현 선택을 레시피 외부에 유지합니다.
소프트웨어 작업은 동일한 컴파일러를 사용할 수 있습니다:
apiVersion: decretum.dev/v1
kind: ExecutionRecipe
domain: software_engineering
id: build-user-service
name: Build User Service
version: "1.0"
objective: Build and validate a Python service.
capabilities:
- source.read
- source.modify
- dependency.install
- test.execute
- artifact.build
- container.build
profiles:
infrastructure: local-dev
language: python
testing: pytest
container: docker
agent: coding-agent
completion:
required:
- tests_pass
- artifact_built
- container_built
동일한 의도를 다른 선호도 집합에 대해 컴파일할 수 있습니다:
profiles:
infrastructure: isolated-dev-vm
testing: pytest
container: podman
agent: enterprise-coding-agent
레시피는 의도를 설명합니다. 프로파일은 선호도를 표현합니다. 프로바이더 레지스트리는 실제로 사용 가능한 것을 결정합니다.
id: suspicious-network-investigation
name: Suspicious Network Investigation
version: "1.0"
role: threat_researcher
objective: Determine whether the sample creates unexpected network activity.
capabilities:
- process.observe
- network.capture
- artifact.collect
infrastructure_profile: isolated-linux-vm
instrumentation_profile: linux-network-observation
harness_profile: interactive-research
레시피에는 Lima/Docker 라이프사이클, MCP 구현, 에이전트 프롬프트 또는 런타임별 코드가 포함되지 않습니다.
Decretum은 9–10단계를 수행하지 않습니다.
DISCOVER
|
PROPOSE
|
SEMANTIC REVIEW
|
APPROVE
|
CANONICAL CAPABILITY
|
PROVIDER IMPLEMENTATIONS
디스커버리는 기능을 제안할 수 있지만, 정규 의미론을 조용히 변경할 수는 없습니다.
git clone https://github.com/Opposum0112/Decretum.git
cd Decretum
uv sync
decretum capabilities discover
decretum validate recipes/<recipe>.yaml
decretum resolve recipes/<recipe>.yaml
decretum compile recipes/<recipe>.yaml
Decretum의 validate/resolve/compile 경로에서는 어떤 것도 작업을 실행하지 않습니다.
Capability
|
Provider
|
Integration
|
Execution surface
|
Harness compatibility
|
Host/provider readiness
|
Policy compatibility
|
READY / BLOCKED
Decretum은 의도적으로 다음이 되지 않습니다:
대신:
Decretum
= declarative intent -> deterministic contract
Harness / Agent
= interactive execution environment
Store
= persistent execution or research memory
자세한 경계는 ARCHITECTURE.md, docs/execution-contract.md, docs/domain-model.md를 참조하세요.
의미론을 소유한 계층에 기여하세요:
프로바이더 추가는 일반적으로 컴파일러 분기가 아닌 레지스트리 작업을 필요로 해야 합니다.
새로운 기능의 경우, 정규 승인을 요청하기 전에 그 의미론을 설명하고 기존 기능과 구별하세요.