import type { HookEvent } from '../../src/types.js'; import { scanForExfiltration } from '../../src/rules/exfiltration-patterns.js'; import { writeAuditLog } from '../../src/utils/logger.js'; import { formatAlert } from '../../src/utils/alert.js'; const handler = async (event: HookEvent): Promise => { try { const { type, action, context, sessionKey, timestamp, messages } = event; if (type !== 'message' || action !== 'sent') return; const content = context.content ?? ''; if (!content) return; const result = scanForExfiltration(content); if (!result.matched) return; const alertText = formatAlert(result.findings); messages.push( `🚫 **Exfiltration Detector — CRITICAL WARNING**\n` + `Possible data exfiltration attempt detected in AI response!\n` + `The response may contain crafted links designed to beacon your data to an external server.\n\n` + alertText + `\n\n> Review the response carefully before acting on any links or images.`, ); writeAuditLog({ timestamp: timestamp.toISOString(), event: `${type}:${action}`, sessionKey, channel: context.channelId, isGroup: context.isGroup, alerts: result.findings, metadata: { messageLength: content.length }, }); } catch (err) { console.error( '[security-guardrails:exfiltration-detector] Error:', err instanceof Error ? err.message : String(err), ); writeAuditLog({ timestamp: new Date().toISOString(), event: 'hook_error', sessionKey: event.sessionKey, alerts: [], metadata: { hook: 'exfiltration-detector', error: err instanceof Error ? err.message : String(err) }, }); } }; export default handler;