{"tools":[{"name":"correlate","owner":"correlate","description":"Send the incident's raw SIEM events to the Correlate service and get back observations, relationships, and scored attack chains. Run this FIRST — everything else builds on its output.","risk":"read-only","timeoutMs":15000,"retryPolicy":"none","authPolicy":"platform-key","tracePolicy":"propagate"},{"name":"map_attack","owner":"investigate","description":"Map the correlated observations onto MITRE ATT&CK techniques and produce an ordered kill chain by tactic. Use to explain adversary progression.","risk":"read-only","timeoutMs":2000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"lookup_technique","owner":"investigate","description":"Look up one technique in the pinned official Enterprise ATT&CK 19.1 STIX subset.","risk":"read-only","timeoutMs":1000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"search_techniques","owner":"investigate","description":"Search the pinned official Enterprise ATT&CK 19.1 STIX subset by ID, name, or tactic.","risk":"read-only","timeoutMs":1000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"build_timeline","owner":"investigate","description":"Return the correlated observations in chronological order, optionally scoped to an entity id. Use to reconstruct the sequence of events.","risk":"read-only","timeoutMs":2000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"},{"name":"verify_claim","owner":"evidence","description":"Send a factual claim about the incident to the Evidence service for verification, attaching correlated observations/relationships as evidence. Returns a verdict (SUPPORTED / UNSUPPORTED / …) with per-rule checks and a signed digest. Use to validate the key conclusion.","risk":"read-only","timeoutMs":12000,"retryPolicy":"none","authPolicy":"public-read","tracePolicy":"propagate"}],"specialists":[{"id":"archive.inspect","owner":"zip","canonicalUrl":"https://zip.platphormnews.com","capabilityClass":"artifact-processing","representativeTool":"zip_operation_manifest","acceptedInputs":["ZIP archive"],"outputTypes":["operation manifest","browser-local inspection result"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Browser-local archive processing; the representative server call does not receive archive bytes.","evidenceSemantics":"Artifact-derived content that must retain the archive digest and enter Evidence as an artifact reference.","traceSemantics":"not-observed","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"pdf.inspect","owner":"pdf","canonicalUrl":"https://pdf.platphormnews.com","capabilityClass":"artifact-processing","representativeTool":"pdf_operation_manifest","acceptedInputs":["PDF document"],"outputTypes":["operation manifest","browser-local extraction or transformation result"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Browser-local PDF processing; the representative server call does not store document bytes.","evidenceSemantics":"Extracted document content is artifact evidence, not proof that statements inside the document are true.","traceSemantics":"not-observed","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"table.inspect","owner":"sheets","canonicalUrl":"https://sheets.platphormnews.com","capabilityClass":"reporting-projection","representativeTool":"get_sheets_info","acceptedInputs":["tabular data","spreadsheet metadata"],"outputTypes":["structured sheet metadata","report projection"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Structured inspection backed by the deployed Sheets service.","evidenceSemantics":"A reporting projection; the canonical evidence remains in Evidence.","traceSemantics":"not-observed","verification":"DEGRADED","availability":"degraded","integration":"optional"},{"id":"json.validate","owner":"json","canonicalUrl":"https://json.platphormnews.com","capabilityClass":"validation","representativeTool":"validate_json","acceptedInputs":["JSON text"],"outputTypes":["syntax validation","structured diagnostics"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Deterministic JSON parsing and validation.","evidenceSemantics":"Establishes structural validity only; it does not establish factual truth.","traceSemantics":"propagate-when-invoked","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"xml.validate","owner":"xml","canonicalUrl":"https://xml.platphormnews.com","capabilityClass":"validation","representativeTool":"validate_xml","acceptedInputs":["XML text"],"outputTypes":["syntax validation","safe parser diagnostics"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Deterministic XML validation with DTD and external-entity processing denied.","evidenceSemantics":"Establishes structural validity only; it does not establish factual truth.","traceSemantics":"propagate-when-invoked","verification":"DEGRADED","availability":"degraded","integration":"optional"},{"id":"markdown.project","owner":"markdown","canonicalUrl":"https://markdown.platphormnews.com","capabilityClass":"reporting-projection","representativeTool":"get_markdown_stats","acceptedInputs":["Markdown text"],"outputTypes":["document statistics","Markdown projection"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Deterministic document inspection and projection.","evidenceSemantics":"A presentation format; it is not the authoritative evidence store.","traceSemantics":"propagate-when-invoked","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"script.analyze","owner":"desa","canonicalUrl":"https://desa.platphormnews.com","capabilityClass":"specialist-analysis","representativeTool":"analyze_script","acceptedInputs":["PowerShell or script text"],"outputTypes":["static analysis","decoded indicators","risk findings"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Static analysis only; execution is disabled and belongs to Sandbox.","evidenceSemantics":"Specialist analysis that must be verified against incident observations before becoming a factual claim.","traceSemantics":"propagate-when-invoked","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"msi.inspect","owner":"msi","canonicalUrl":"https://msi.platphormnews.com","capabilityClass":"artifact-processing","representativeTool":"load_demo_database","acceptedInputs":["MSI database"],"outputTypes":["MSI table and property inspection"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"The observed server tool loads a sample database only; arbitrary MSI upload was not verified.","evidenceSemantics":"Showcase-only until a real incident artifact contract is verified.","traceSemantics":"not-observed","verification":"DEGRADED","availability":"degraded","integration":"showcase-only"},{"id":"fingerprint.inspect","owner":"fingerprint","canonicalUrl":"https://fingerprint.platphormnews.com","capabilityClass":"specialist-analysis","representativeTool":"get_fingerprint_info","acceptedInputs":["browser or session signals"],"outputTypes":["deterministic fingerprint metadata"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Deterministic local fingerprint analysis; model assistance was not active in the observed call.","evidenceSemantics":"Automation characteristics do not establish a human identity.","traceSemantics":"propagate-when-invoked","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"indicator.enrich","owner":"threatpulse","canonicalUrl":"https://threatpulse.platphormnews.com","capabilityClass":"external-enrichment","representativeTool":"get_enrichment_status","acceptedInputs":["IP address","domain","URL","hash"],"outputTypes":["provider-attributed intelligence context"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"External intelligence enrichment only.","evidenceSemantics":"No record does not mean safe; enrichment cannot replace incident evidence.","traceSemantics":"propagate-when-invoked","verification":"VERIFIED","availability":"ready","integration":"optional"},{"id":"sandbox.execute","owner":"sandbox","canonicalUrl":"https://sandbox.platphormnews.com","capabilityClass":"bounded-execution","representativeTool":"get_sandbox_status","acceptedInputs":["governed execution request"],"outputTypes":["policy decision","execution receipt","bounded output"],"risk":"bounded-write","authPolicy":"platform-key","executionSemantics":"The provider is reachable, but live execution was disabled in the observed status.","evidenceSemantics":"Execution output requires input digest, policy decision, receipt, and trace before Evidence can reference it.","traceSemantics":"propagate-when-invoked","verification":"DEGRADED","availability":"degraded","integration":"optional"},{"id":"contract.validate","owner":"spec","canonicalUrl":"https://spec.platphormnews.com","capabilityClass":"validation","representativeTool":"validate_openapi","acceptedInputs":["OpenAPI document","JSON schema","service contract"],"outputTypes":["conformance result","contract diagnostics"],"risk":"read-only","authPolicy":"public-read","executionSemantics":"Deterministic contract validation used for release conformance, not a synchronous investigation dependency.","evidenceSemantics":"Proves contract conformance, not incident facts.","traceSemantics":"propagate-when-invoked","verification":"VERIFIED","availability":"ready","integration":"optional"}],"dependencies":[{"name":"correlate","state":"READY","mode":"remote","target":"https://correlate.platphormnews.com","url":"https://correlate.platphormnews.com/api/health","method":"GET","httpStatus":200,"responseSchema":"Envelope{ok,data:CorrelateHealth{status,service,version,contractVersion,ruleSet,storage},error,meta} or legacy CorrelateHealth","auth":"none","durationMs":77,"observedAt":"2026-08-17T02:12:41.839Z","error":null},{"name":"evidence","state":"READY","mode":"remote","target":"https://evidence.platphormnews.com","url":"https://evidence.platphormnews.com/api/health","method":"GET","httpStatus":200,"responseSchema":"Envelope{ok,data:EvidenceHealth{service,status,engine,checks},error,meta}","auth":"none","durationMs":108,"observedAt":"2026-08-17T02:12:41.872Z","error":null},{"name":"attack","state":"READY","mode":"local-engine","target":"pinned ATT&CK mapping engine","url":null,"method":null,"httpStatus":null,"responseSchema":"pinned ATT&CK 19.1 bundle","auth":"none","durationMs":0,"observedAt":"2026-08-17T02:12:41.872Z","error":null}],"traceExport":{"method":"GET","responseSchema":"Envelope{ok:true,data:TraceSummary[],pagination}","auth":"server-side PLATPHORM_API_KEY","state":"MISCONFIGURED","url":"https://trace.platphormnews.com/api/v1/traces?meaningful=include&limit=1","httpStatus":401,"durationMs":97,"observedAt":"2026-08-17T02:12:41.860Z","error":"Trace rejected server-side platform authentication"}}