Files
ai-agent-book/chapter5/permission-embedded-data-objects/pedo/eval/baxbench_adapter/__init__.py
T
liqiang b119135836
Build latest book artifacts / build (push) Canceled after 0s
dependency resolution / resolve (3.11) (push) Canceled after 0s
dependency resolution / resolve (3.13) (push) Canceled after 0s
deploy-pages / build (push) Canceled after 0s
deploy-pages / deploy (push) Canceled after 0s
i18n consistency check / check (push) Canceled after 0s
provider adoption tests / test (chapter2/context-compression) (push) Canceled after 0s
provider adoption tests / test (chapter2/prompt-injection) (push) Canceled after 0s
provider adoption tests / test (chapter2/system-hint) (push) Canceled after 0s
provider adoption tests / test (chapter3/log-sanitization) (push) Canceled after 0s
web-search-agent tests / test (push) Canceled after 0s
web-search-agent tests / agentbook (push) Canceled after 0s
ai-agent-book 精选快照(<2MB 代码与文档,来自 github.com/bojieli/ai-agent-book)
2026-08-20 13:12:50 +00:00

18 lines
831 B
Python

"""BaxBench-derived adapter benchmark.
Translates a subset of BaxBench (arXiv:2502.11844, ETH Zurich) backend
scenarios into the function-level harness format used by DataGuardBench,
so the same security oracle can be applied to PEDO and RAW conditions.
This is an adapter — not official BaxBench numbers. The contract:
- Each adapter scenario reproduces BaxBench's API surface (same endpoints,
same per-endpoint contract) and security tests (same exploits) for the
subset of CWEs that PEDO architecturally addresses.
- Out-of-scope CWEs (SQL injection at the parsing layer, password hashing,
JWT generation) are reported but not claimed to be in PEDO's scope.
Currently adapted scenarios:
- SecretStorage (BaxBench id "SecretStorage")
Tests: cross-user secret access (CWE-IMPROPER_ACCESS_CONTROL)
"""