Cover image for project: Nexus IAST Agent IN PROGRESS

Technical summary

IAST plugin that observes real requests in PHP applications and detects when user input reaches SQL, command, file, deserialization or redirect sinks. Its standalone agent runs in basic mode or with uopz hooks, sends authenticated findings to NEXUS, and provides deduplication, heartbeat, self-test and automatic task creation with per-project routing.

Executed scope

  • Standalone runtime agent agent/nexus-iast.php (417 lines): boot (config + optional config_file), captureSources, isTainted/matchingSource, report (with sample_rate, max_findings, stack trace via debug_backtrace), per-vuln-type checks with heuristics, tryUopzHooks (hooks on shell_exec/exec/system/passthru/file_get_contents/fopen/unserialize), flush at shutdown (curl or file_get_contents stream, X-IAST-Token header), NexusIast::exec/readFile (helpers without uopz) and NexusIastPDO extends PDO (instrumented query/exec/prepare).
  • Schema (iast_install() on load, no install.sql): iast_findings (id PK, agent_id, project, vuln_type, severity, file_path, line_number, function_name, user_input, sink_function, stack_trace MEDIUMTEXT, request_url, request_method, evidence, fingerprint, status, task_id, indexes per agent/type/sev/status/fp/created) + iast_agents (agent_id PK, label, project, last_seen_at, findings_count, meta JSON) + light migration of the source column (runtime/self_test/manual).
  • 13 API actions via PluginManager::registerApiAction — iast_stats, iast_settings, iast_settings_save, iast_findings (page/limit + severity/status/vuln_type/agent_id/q filters), iast_finding_status (open/resolved/ignored), iast_agents, iast_ingest (public with token, batch ≤ 100), iast_self_test, iast_purge_demo, iast_capabilities, iast_fastr, iast_fastr_suggest, iast_agent_snippet (snippet tuned to the host's recommended mode).
  • Environment detection iast_env_capabilities(): profile from signals (open_basedir, disabled sensitive functions, uopz, max_execution_time) → shared_hosting/vps_full/vps_or_shared_basic, recommended mode (full if uopz, otherwise basic), with guidance limits; works on shared and VPS (requires_vps: false).
  • Multi-project: iast_resolve_task_project() with default (always the default project), from_agent (uses the agent's project if it exists in NEXUS) and map (agent→project routes, up to 50, validated against active projects via projects_read()).
  • Task creation: iast_create_task_for_finding() — title [IAST][SEV] TYPE via SINK, markdown description with input/evidence, resolved project, severity-based priority (critical 4 → low 1), pending status; triggered when auto_create_tasks and severity ≥ min_severity_for_task.
  • Ingestion: iast_validate_ingest_token (X-IAST-Token header or body, hash_equals; without a configured token accepts master/session), iast_fingerprint, dedupe by window (dedupe_hours 1–168), heartbeat upsert in iast_agents.
  • /iast command via fastr.json (arg_suggest_action: iast_fastr_suggest): stats, findings, open, env, selftest with readable markdown replies.
  • Alpine.js UI tab.php (25 KB): sub-tabs Findings (filters + self-test + demo purge), Agents (heartbeat), Install (snippet with endpoint/token/recommended mode) and Config (token with rotate, auto_create_tasks, min_severity, dedupe_hours, project_mode and routes).
  • Core whitelist: iast_ingest in the auth bypass of api.php (line ~58, alongside incoming_webhook/github_callback).

Stack and tooling

  • PHP 8 (no framework) — standalone agent compatible with any PHP app
  • MySQL 8 (iast_findings, iast_agents)
  • cURL (agent telemetry) + stream fallback (allow_url_fopen)
  • uopz (uopz_set_return — full mode, optional)
  • Alpine.js + Tailwind CSS
  • NEXUS plugin system (PluginManager + auth whitelist in api.php)

Operational tags

  • IAST
  • Runtime
  • PHP
  • DevSecOps
  • SQLi
  • CMDi
  • Security Agent
  • Plugin NEXUS

Operational outcome

  • Real runtime coverage: findings generated from actual requests (not static analysis), with stack trace, URL, method and tainted input — complementing NEXUS SAST/DAST.
  • Works on any host: basic mode on shared/VPS without root/SSH, and full mode on VPS with uopz for automatic native hooks without changing app code.
  • Zero app impact: findings sent at shutdown (async curl, 800 ms timeout), configurable sample_rate and max_findings for CPU-limited hosts.
  • Fingerprint dedupe + agent heartbeats keep the dashboard accurate and noise-free; self-test validates the pipeline without producing false positives in production (one-click demo purge).
  • Task integration: high-severity findings become tasks automatically in the right project (default/from_agent/map), with severity-based priority.
  • /iast in chat: stats, findings, environment and self-test straight from the comment editor.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS PHP runtime IAST (DevSecOps) that observes real requests inside the target app and reports user input reaching dangerous sinks — basic mode (shared/VPS, no root) and full mode (VPS + uopz) — with automatic multi-project task creation.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.