本卡屬 FR-108(母卡見建卡後補號),第 4 棒:
plugin/五檔、五支 SQL migration、各層__init__。25 檔,只掃不修。FR-101 J2 同型:工具幾乎必零產出,本棒價值在人工六項。
套件怎麼被主專案「接上」(缺哪些零件會拒絕啟動)、宣告了 8 顆權限點又真的守了幾顆、五支隨套件出貨的資料庫腳本用什麼身分寫入、16 張表的隔離規則寫對了沒。
D1 只驗了 routing 那半的守門殼,assembly.py 有沒有「缺 auth_required 拒絕掛載」是這棒答。FR-098 A1 與 FR-101 J2 都證明骨架棒的價值在人工。
plugin/assembly.py、plugin/__init__.py)。mount_routes(bp, auth_required=None) 預設 None=35 條全裸——create_blueprint/register 有沒有 _assert_api_wiring 那種缺必填拒絕掛載(jedi-asset/jedi-issue 都有);license_guard/capability_guard/identity_guard 三軸缺了是 fail loudly(api/guards.py _guard())還是靜默;mount_api=False 逃生門;同 app 掛兩次的覆寫語意。plugin/contract.py:33-40)。8 顆全客戶層(DEV is_platform=f):plugin.* 四顆只有 .update 真的掛在三支寫入上、.create/.read/.delete 誰在用;detection-profile.* 四顆一顆都沒掛(D2 ④)。與 FR-098 第 80 項/FR-101 J2 ① 同一種產品決策題,標明並建議三處一起裁。migrations/001-005)。002 RLS:7 張表 policy——5 張只有 1 條 FOR ALL policy(detection_executions/_groups/job_execution_detection_tools/_agents/tenant_detection_tool_configs),USING 有 is_super_admin OR tenant_id = ANY(allowed_tenant_paths) 但沒有 WITH CHECK(FOR ALL 時 WITH CHECK 預設等於 USING,確認 PostgreSQL 語意、不要憑印象);detection_profiles select policy 含 scope='SYSTEM'——SHARED 的子樹分享靠什麼;003/004 seed 寫 detection_tools(8 筆)與公版 profile(tenant_id 寫 ROOT?)用什麼身分、有沒有 SET LOCAL is_super_admin;005 ui_routes;五支重跑冪等。9 張零隔離表逐張依「有沒有主人」判準給結論(detection_profile_controls 疑有主人)。plugin/migrations.py 只提供不執行)。宿主 scripts/init/migrate.sh --single-transaction(FR-101 J2 已驗一次,本棒確認同一條路徑)。__init__ 的對外 import 面。有沒有把內部 helper 或 crypto 相關 export 到頂層讓宿主誤用。plugin/contract.py docstring、DetectionAdapters 各欄 Optional 與預設)。哪些 port 缺了會靜默降級(如 crypto=None → _resolve_credentials 回 {}=派工帶空憑證,D3 ② 已標,本棒確認契約層有沒有把 crypto 列必填)。_resolve_credentials 解密租戶工具憑證明文交給 agent(主專案 detection_task_payload_provider.py+本套件 detection_orchestration_service.py:1397)。那條是 agent 控制面不驗身分的問題,撞到標「重複 CM-1595」,但本套件這側「憑證解密後的流向與落點」是新的觀察面。detection_executions/_groups/job_execution_detection_tools/_agents/tenant_detection_tool_configs 各 1 條 FOR ALL policy;detection_profiles/_versions 各 4 條)、9 張零隔離:detection_tools/detection_tool_param_schemas/detection_profile_taxonomies/detection_profile_controls(四張是碼表或公版內容,依「有沒有主人」判準可能正確)與 job_execution_comments/_devices/_org_units/_surveys(屬 flow-control 不在本套件)。8 顆能力點 is_platform 全 f。detection_tools 8 筆、tenant_detection_tool_configs 7 筆(1 租戶)、detection_profiles 11 筆(2 租戶)、detection_executions 76 筆。common/guard.py 與 api/guards.py 是「未接線 fail loudly」設計(_guard() 缺 adapter 直接 RuntimeError)——與 FR-098 A1 ⑤ 同款正面案例,驗證它真的做到即可,不要當漏洞報。第一步:驗 scope 檔數,對上 25 才啟動: