feat(registry): initialize X-Frames Blueprint Registry with 4 demo blueprints

- Add security-assessment-v1, it-incident-triage-v1, common-grounds-deploy-v1, org-bootstrap-v1
- Add index.json registry index with full metadata
- Add BLUEPRINT_SCHEMA_v1_0.json validation schema
- Add SCHEMA.md reference docs

Co-Authored-By: Eyean (EOA0000) <eyean@eios.local>
This commit is contained in:
EIOS Staging Bot
2026-06-10 11:42:30 -04:00
parent f1a313bc2a
commit 958521cbf2
15 changed files with 2111 additions and 2 deletions
+332
View File
@@ -0,0 +1,332 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://eios.xrayvu.com/schemas/blueprint/v1.0",
"title": "EIOS Blueprint Package Schema",
"description": "JSON Schema for all EIOS Blueprint packages — covers X-Frames display templates and Bridge agentic workflow packages.",
"version": "1.0",
"created": "2026-06-09",
"author": "EOA0000 (Eyean / EIOS IA)",
"type": "object",
"required": ["blueprint_id", "version", "name", "blueprint_type", "author", "license", "description"],
"additionalProperties": false,
"properties": {
"blueprint_id": {
"type": "string",
"pattern": "^[a-z0-9][a-z0-9/_-]{2,80}$",
"description": "Globally unique slug identifier. Format: <namespace>/<slug> for Bridge; <slug> for X-Frames. Example: healthcare/patient-discharge-summary-v1 or bp_minimal_dark_001",
"examples": ["healthcare/patient-discharge-summary-v1", "it/incident-triage-v1", "bp_minimal_dark_001"]
},
"version": {
"type": "string",
"pattern": "^(0|[1-9]\\d*)\\.(0|[1-9]\\d*)\\.(0|[1-9]\\d*)(?:-((?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\\.(?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\\+([0-9a-zA-Z-]+(?:\\.[0-9a-zA-Z-]+)*))?$",
"description": "Semantic version (MAJOR.MINOR.PATCH). Breaking parameter/API changes = MAJOR.",
"examples": ["1.0.0", "1.2.3", "2.0.0-beta.1"]
},
"name": {
"type": "string",
"minLength": 3,
"maxLength": 80,
"description": "Human-readable display name for marketplace listings."
},
"blueprint_type": {
"type": "string",
"enum": [
"xframes_template",
"bridge_workflow",
"bridge_system_selection",
"bridge_architecture",
"bridge_library",
"bridge_configuration",
"bridge_hybrid"
],
"description": "Discriminator for package structure interpretation. xframes_template = X-Frames room display template. bridge_* = Bridge platform agentic package types."
},
"author": {
"type": "object",
"required": ["entity_id", "display_name"],
"additionalProperties": false,
"properties": {
"entity_id": {
"type": "string",
"pattern": "^E[A-Z0-9]{2}[0-9]{4}$",
"description": "EIOS entity ID of the Blueprint creator (e.g. EOU0227, EOO9788)."
},
"display_name": {
"type": "string",
"description": "Public display name for marketplace attribution."
},
"url": {
"type": "string",
"format": "uri",
"description": "Optional: creator profile or repository URL."
}
}
},
"license": {
"type": "string",
"enum": ["MIT", "Apache-2.0", "GPL-3.0", "AGPL-3.0", "CC-BY-4.0", "CC-BY-SA-4.0", "proprietary", "commercial"],
"description": "OSI-approved license or proprietary/commercial for paid Blueprints."
},
"description": {
"type": "string",
"minLength": 20,
"maxLength": 300,
"description": "Short description for search result cards (≤300 chars)."
},
"long_description": {
"type": "string",
"description": "Full markdown description rendered on the Blueprint detail page."
},
"domain": {
"type": "string",
"enum": [
"healthcare",
"legal",
"finance",
"government",
"education",
"technology",
"infrastructure",
"security",
"devops",
"communications",
"hr",
"marketing",
"general"
],
"description": "Industry/functional domain for marketplace categorization."
},
"tags": {
"type": "array",
"items": { "type": "string", "pattern": "^[a-z0-9][a-z0-9-]{0,30}$" },
"minItems": 1,
"maxItems": 15,
"uniqueItems": true,
"description": "Searchable tags. lowercase-hyphenated."
},
"certification": {
"type": "string",
"enum": ["community", "verified", "certified", "healthcare-certified"],
"default": "community",
"description": "Certification tier. community = free/unvetted; verified = $500 fee, basic review; certified = $2K, full audit; healthcare-certified = $5K, HIPAA/regulatory."
},
"pricing": {
"type": "object",
"required": ["model"],
"additionalProperties": false,
"properties": {
"model": {
"type": "string",
"enum": ["free", "one_time", "subscription", "usage"],
"description": "Pricing model. Free blueprints may still have a license fee."
},
"amount_credits": {
"type": "integer",
"minimum": 0,
"description": "Platform credits charged. 0 = free. For subscription: per-month. For one_time: total."
},
"usage_unit": {
"type": "string",
"description": "For usage model: what is billed per execution (e.g. 'per_run', 'per_document')."
},
"revenue_split": {
"type": "object",
"description": "Revenue distribution. Defaults to 70% creator / 30% platform.",
"properties": {
"creator_pct": { "type": "number", "minimum": 0, "maximum": 100 },
"platform_pct": { "type": "number", "minimum": 0, "maximum": 100 }
}
}
}
},
"requires": {
"type": "object",
"additionalProperties": false,
"properties": {
"eios_version": {
"type": "string",
"description": "Semver range constraint on EIOS platform version (e.g. '>=1.0.0 <2.0.0')."
},
"xframes_version": {
"type": "string",
"description": "Required for xframes_template type. Semver range."
},
"bridge_version": {
"type": "string",
"description": "Required for bridge_* types. Semver range."
},
"platform_features": {
"type": "array",
"items": { "type": "string" },
"description": "Named platform feature flags required (e.g. 'mem0', 'lightrag', 'otel')."
},
"actor_harnesses": {
"type": "array",
"items": {
"type": "string",
"enum": ["claude-code", "aider", "openhands", "gemini-cli", "browser-use", "custom"]
},
"description": "For bridge_workflow: harnesses that must be available to execute this blueprint."
}
}
},
"dependencies": {
"type": "array",
"items": {
"type": "object",
"required": ["blueprint_id", "version"],
"properties": {
"blueprint_id": { "type": "string" },
"version": { "type": "string" }
}
},
"description": "Other blueprints this one depends on (installed automatically)."
},
"parameters": {
"type": "object",
"description": "For bridge_* types: parameterizable inputs. Keys are parameter names; values are parameter specs.",
"additionalProperties": {
"type": "object",
"required": ["type", "description"],
"properties": {
"type": {
"type": "string",
"enum": ["string", "integer", "number", "boolean", "enum", "array", "object"]
},
"description": { "type": "string" },
"required": { "type": "boolean", "default": false },
"default": {},
"enum_values": {
"type": "array",
"description": "For type=enum: allowed values."
},
"sensitive": {
"type": "boolean",
"default": false,
"description": "If true: value is a credential/secret, never logged or transmitted."
}
}
}
},
"entry_point": {
"type": "string",
"description": "For bridge_workflow: relative path to the main workflow definition file (e.g. 'workflow.yaml' or 'main.py')."
},
"oss": {
"type": "object",
"additionalProperties": false,
"description": "OSS publishing metadata. Present if this blueprint is intended for public release.",
"properties": {
"publish_ready": { "type": "boolean" },
"target_repository": { "type": "string", "format": "uri" },
"tier": {
"type": "string",
"enum": ["tier1", "tier2", "tier3"],
"description": "tier1 = publish immediately; tier2 = after internal hardening; tier3 = keep proprietary."
},
"stripping_required": {
"type": "boolean",
"description": "If true: must strip EIOS-internal references before publishing."
}
}
},
"xframes": {
"type": "object",
"description": "X-Frames-specific fields. Required when blueprint_type = xframes_template.",
"required": ["template_name", "system_name", "category"],
"additionalProperties": false,
"properties": {
"template_name": { "type": "string" },
"system_name": {
"type": "string",
"pattern": "^[A-Z][A-Z0-9_]{1,40}$",
"description": "UPPER_SNAKE_CASE system identifier used in X-Frames runtime."
},
"category": {
"type": "string",
"enum": ["minimal", "standard", "verbose", "developer", "presentation", "custom"]
},
"platforms": {
"type": "array",
"items": { "type": "string", "enum": ["cli", "web", "mobile"] }
}
}
},
"marketplace": {
"type": "object",
"description": "Marketplace listing metadata (auto-populated/updated by platform).",
"additionalProperties": false,
"properties": {
"published_at": { "type": "string", "format": "date-time" },
"updated_at": { "type": "string", "format": "date-time" },
"downloads": { "type": "integer", "minimum": 0 },
"stars": { "type": "integer", "minimum": 0 },
"installs": { "type": "integer", "minimum": 0 },
"status": {
"type": "string",
"enum": ["draft", "submitted", "under_review", "published", "deprecated", "archived"]
}
}
},
"changelog": {
"type": "array",
"description": "Version history. Most recent first.",
"items": {
"type": "object",
"required": ["version", "date", "changes"],
"properties": {
"version": { "type": "string" },
"date": { "type": "string", "format": "date" },
"changes": { "type": "string" }
}
}
}
},
"if": {
"properties": { "blueprint_type": { "const": "xframes_template" } }
},
"then": {
"required": ["xframes"],
"properties": {
"requires": {
"required": ["xframes_version"]
}
}
},
"else": {
"if": {
"properties": { "blueprint_type": { "pattern": "^bridge_" } }
},
"then": {
"required": ["domain", "parameters"],
"properties": {
"requires": {
"required": ["bridge_version"]
}
}
}
}
}
+21 -2
View File
@@ -1,3 +1,22 @@
# blueprints
# X-Frames Blueprint Registry
EIOS Blueprint Package Registry — submit, discover, and install EIOS blueprints
The official EIOS Blueprint Package Registry. Blueprints are composable, schema-validated
packages that encode workflows, tools, and deployment templates for the EIOS platform.
## Contents
- `blueprints/` — blueprint packages (one subdirectory per blueprint)
- `index.json` — machine-readable registry index
- `BLUEPRINT_SCHEMA_v1_0.json` — validation schema
- `SCHEMA.md` — schema documentation
## Available Blueprints
| Blueprint | Type | License |
|-----------|------|---------|
| Security Assessment Report Generator | bridge_workflow | commercial |
| IT Incident Triage Workflow | bridge_workflow | commercial |
| Common Grounds Deployment Package | deployment_template | internal |
| Organization Bootstrap Kit | eios_tool | internal |
## Submission
Blueprints are submitted via `eac-blueprint submit` CLI or the Blueprint API at port 32740.
+15
View File
@@ -0,0 +1,15 @@
# Blueprint Schema Reference
All blueprints in this registry conform to [BLUEPRINT_SCHEMA_v1_0.json](BLUEPRINT_SCHEMA_v1_0.json).
## Required Fields
- `blueprint_id` — unique namespace/id string (e.g. `security/assessment-report-v1`)
- `version` — semver string
- `name` — human-readable name
- `blueprint_type` — one of: `bridge_workflow`, `eios_tool`, `harness_config`, `deployment_template`
- `author` — `entity_id`, `display_name`
- `license` — `commercial`, `open_source`, `internal`
- `description` — short description (≤200 chars)
## Submission
See [EIOS Blueprint Marketplace](https://ecp.xrayvu.com) for submission instructions.
@@ -0,0 +1,14 @@
# Changelog — Common Grounds Deploy Blueprint
## [1.0.0] — 2026-06-09
### Initial Release
- Preflight: OS detection, disk/RAM sanity check
- Installs Apache 2.4, PHP 8.x, SQLite3, Git
- Deploys Common Grounds from Gitea (branch/tag configurable)
- Apache VirtualHost configuration with mod_rewrite
- SQLite database initialization with admin account
- Optional Let's Encrypt SSL via certbot
- HTTP health check with graceful DNS-not-ready warning
- Outputs: wiki_url, admin_url, install_path
@@ -0,0 +1,129 @@
# Common Grounds Wiki Deployment Blueprint
**Blueprint ID**: `infrastructure/common-grounds-deploy-v1`
**Version**: 1.0.0
**License**: MIT
**Author**: XRAY VU (EOO9788)
Deploy a self-hosted [Common Grounds](https://grnds.xrayvu.com) wiki on any Debian/Ubuntu server in under 5 minutes.
---
## What This Blueprint Does
1. Runs a preflight check (OS compatibility, disk/RAM)
2. Installs Apache, PHP 8.x, SQLite3, and Git
3. Clones the Common Grounds source from Gitea
4. Configures an Apache VirtualHost for your domain
5. Initializes the wiki database with an admin account
6. (Optional) Provisions Let's Encrypt SSL via certbot
7. Verifies the site is reachable via HTTP(S)
**Total time**: ~3–5 minutes on a standard VPS.
---
## Requirements
- Debian 11/12 or Ubuntu 22.04/24.04
- SSH access with sudo privileges
- Domain DNS A record pointing to the server (for SSL)
- Minimum: 1 vCPU, 512MB RAM, 2GB disk
---
## Parameters
| Parameter | Required | Default | Description |
|-----------|----------|---------|-------------|
| `target_host` | ✅ | — | Server IP or hostname |
| `ssh_user` | ✗ | `root` | SSH user with sudo |
| `ssh_key_path` | ✗ | EIOS default | SSH private key path |
| `domain_name` | ✅ | — | e.g. `wiki.example.com` |
| `enable_https` | ✗ | `false` | Run certbot for SSL |
| `certbot_email` | ✗ | — | Required if enable_https=true |
| `wiki_title` | ✗ | `Common Grounds Wiki` | Site title |
| `admin_username` | ✗ | `admin` | Initial admin username |
| `admin_password` | ✗ | `changeme123` | **Change after first login** |
| `source_ref` | ✗ | `main` | Git branch or tag |
| `install_path` | ✗ | `/var/www/common-grounds` | Installation path |
---
## Usage
### Via EIOS Bridge CLI (planned)
```bash
eios-blueprint install infrastructure/common-grounds-deploy-v1
eios-blueprint run infrastructure/common-grounds-deploy-v1 \
--param target_host=203.0.113.10 \
--param domain_name=wiki.example.com \
--param admin_password=YourSecurePassword \
--param enable_https=true \
--param certbot_email=admin@example.com
```
### Via params file
```yaml
# params.yaml
target_host: "203.0.113.10"
domain_name: "wiki.example.com"
enable_https: true
certbot_email: "admin@example.com"
admin_password: "YourSecurePassword"
wiki_title: "My Team Wiki"
```
```bash
eios-blueprint run infrastructure/common-grounds-deploy-v1 --params params.yaml
```
---
## Post-Install
1. Visit `http://your-domain.com/` — you should see the Common Grounds homepage
2. Log in at `/admin` with your `admin_username` / `admin_password`
3. **Change the admin password immediately**
4. Configure your wiki title and theme via the admin panel
---
## Outputs
| Output | Description |
|--------|-------------|
| `wiki_url` | Public URL of the wiki |
| `admin_url` | Admin panel URL |
| `install_path` | Server filesystem path |
---
## About Common Grounds
Common Grounds is the open-source wiki framework developed by XRAY VU, powering
[Atomic Grounds](https://grnds.xrayvu.com) — a live instance demonstrating the
framework's capabilities. It is designed for:
- Simple deployment (no Docker required, runs on shared hosting)
- Rich content with wiki-style linking
- Multi-user with role-based access
- Exportable content (Markdown, PDF via BIDS integration)
**Source**: https://github.com/xrayvu/common-grounds *(planned)*
**Live demo**: https://grnds.xrayvu.com
---
## License
MIT License — free to use, modify, and distribute.
See [LICENSE](LICENSE) for full terms.
---
*infrastructure/common-grounds-deploy-v1 | EIOS Blueprint Package | 2026-06-09*
@@ -0,0 +1,139 @@
# EIOS Blueprint Package — Common Grounds Deploy
# Conforms to: BLUEPRINT_SCHEMA_v1_0.json
blueprint_id: "infrastructure/common-grounds-deploy-v1"
version: "1.0.0"
name: "Common Grounds Wiki Deployment"
blueprint_type: "bridge_configuration"
author:
entity_id: "EOO9788"
display_name: "XRAY VU"
url: "https://grnds.xrayvu.com"
license: "MIT"
description: "Deploy a self-hosted Common Grounds wiki on any Debian/Ubuntu server in under 5 minutes. Includes Apache config, PHP, SQLite database, and optional SSL setup."
long_description: |
Common Grounds is the open-source wiki framework powering Atomic Grounds
(grnds.xrayvu.com). This Blueprint automates a complete installation:
1. System dependency check + install (Apache, PHP 8.x, SQLite3)
2. Common Grounds source deployment (from Git or tarball)
3. Apache VirtualHost configuration (HTTP and optionally HTTPS via certbot)
4. Database initialization and default seed content
5. Post-install health check verifying the site is accessible
The result is a fully operational wiki at your chosen domain within minutes,
with no manual shell work required.
**Target audience**: Anyone deploying an internal knowledge base, community wiki,
or operational reference site — from solo operators to regulated enterprises.
**Resource footprint**: ~200MB disk; 256MB RAM minimum; PHP + SQLite (no PostgreSQL needed).
domain: "infrastructure"
tags:
- "wiki"
- "self-hosted"
- "apache"
- "php"
- "sqlite"
- "knowledge-base"
- "common-grounds"
- "oss"
certification: "community"
pricing:
model: "free"
amount_credits: 0
requires:
bridge_version: ">=0.1.0"
eios_version: ">=1.0.0"
platform_features: []
actor_harnesses: ["claude-code"]
dependencies: []
entry_point: "workflow.yaml"
parameters:
target_host:
type: string
description: "SSH host or IP address of the target Debian/Ubuntu server."
required: true
ssh_user:
type: string
description: "SSH username with sudo privileges on the target host."
required: false
default: "root"
ssh_key_path:
type: string
description: "Path to SSH private key on the actor's host. Default uses EIOS SSH key."
required: false
default: "/opt/LIFERAFT/secure/eou/EOU0227/ssh/id_ed25519"
sensitive: false
domain_name:
type: string
description: "Fully-qualified domain name for the wiki (e.g. wiki.example.com). Used in Apache VirtualHost."
required: true
enable_https:
type: boolean
description: "If true, runs certbot to provision Let's Encrypt SSL after DNS propagation is confirmed."
required: false
default: false
certbot_email:
type: string
description: "Email address for Let's Encrypt notifications. Required when enable_https is true."
required: false
wiki_title:
type: string
description: "Title displayed in the wiki header."
required: false
default: "Common Grounds Wiki"
admin_username:
type: string
description: "Username for the initial admin account."
required: false
default: "admin"
admin_password:
type: string
description: "Password for the initial admin account. CHANGE AFTER FIRST LOGIN."
required: false
default: "changeme123"
sensitive: true
source_ref:
type: string
description: "Git tag or branch to deploy. Defaults to 'main'."
required: false
default: "main"
install_path:
type: string
description: "Filesystem path for the wiki installation."
required: false
default: "/var/www/common-grounds"
oss:
publish_ready: true
tier: "tier1"
stripping_required: false
marketplace:
status: "draft"
changelog:
- version: "1.0.0"
date: "2026-06-09"
changes: "Initial release. Covers Debian/Ubuntu; Apache + SQLite; optional certbot SSL."
@@ -0,0 +1,204 @@
# Common Grounds Deploy — Workflow Definition
# Blueprint: infrastructure/common-grounds-deploy-v1
# Entry point for bridge_configuration execution
name: "Common Grounds Wiki Deployment"
version: "1.0.0"
executor: "claude-code"
# Workflow steps execute sequentially.
# Each step is a shell command or a named sub-workflow invoked on target_host via SSH.
# Variable substitution: {{ param_name }} resolves from blueprint.yaml parameters.
steps:
- id: "preflight"
name: "Preflight — connectivity and OS check"
type: "ssh_command"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
set -e
echo "=== Common Grounds Deploy — Preflight ==="
echo "Host: $(hostname)"
echo "OS: $(lsb_release -d 2>/dev/null | cut -f2 || cat /etc/os-release | grep PRETTY_NAME | cut -d= -f2)"
echo "Disk free: $(df -h / | tail -1 | awk '{print $4}')"
echo "RAM free: $(free -h | grep Mem | awk '{print $4}')"
# Verify Debian/Ubuntu
if ! grep -qiE 'debian|ubuntu' /etc/os-release; then
echo "ERROR: This blueprint requires Debian or Ubuntu."
exit 1
fi
echo "PREFLIGHT PASS"
on_failure: "abort"
- id: "install_deps"
name: "Install system dependencies"
type: "ssh_command"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
set -e
export DEBIAN_FRONTEND=noninteractive
apt-get update -qq
apt-get install -y -qq apache2 php php-sqlite3 php-mbstring php-xml git curl
# Enable Apache modules
a2enmod rewrite
a2enmod headers
systemctl enable apache2
systemctl start apache2
echo "DEPS INSTALLED"
on_failure: "abort"
- id: "deploy_source"
name: "Deploy Common Grounds source"
type: "ssh_command"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
set -e
INSTALL_PATH="{{ install_path }}"
SOURCE_REF="{{ source_ref }}"
# Clone or update
if [ -d "$INSTALL_PATH/.git" ]; then
cd "$INSTALL_PATH"
git fetch origin
git checkout "$SOURCE_REF"
git pull
echo "SOURCE UPDATED"
else
mkdir -p "$(dirname $INSTALL_PATH)"
git clone --branch "$SOURCE_REF" https://github.com/xrayvu/common-grounds.git "$INSTALL_PATH"
echo "SOURCE CLONED"
fi
# Set permissions
chown -R www-data:www-data "$INSTALL_PATH"
chmod -R 755 "$INSTALL_PATH"
chmod -R 775 "$INSTALL_PATH/data" 2>/dev/null || true
on_failure: "abort"
- id: "configure_apache"
name: "Configure Apache VirtualHost"
type: "ssh_command"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
set -e
DOMAIN="{{ domain_name }}"
INSTALL_PATH="{{ install_path }}"
VHOST_FILE="/etc/apache2/sites-available/${DOMAIN}.conf"
# Write vhost
cat > "$VHOST_FILE" << 'VHOSTEOF'
<VirtualHost *:80>
ServerName DOMAIN_PLACEHOLDER
DocumentRoot INSTALL_PATH_PLACEHOLDER/public
DirectoryIndex index.php
<Directory INSTALL_PATH_PLACEHOLDER/public>
AllowOverride All
Require all granted
</Directory>
ErrorLog /var/log/apache2/DOMAIN_PLACEHOLDER-error.log
CustomLog /var/log/apache2/DOMAIN_PLACEHOLDER-access.log combined
</VirtualHost>
VHOSTEOF
# Replace placeholders (avoid shell quoting issues in heredoc)
sed -i "s|DOMAIN_PLACEHOLDER|$DOMAIN|g" "$VHOST_FILE"
sed -i "s|INSTALL_PATH_PLACEHOLDER|$INSTALL_PATH|g" "$VHOST_FILE"
a2ensite "${DOMAIN}.conf"
a2dissite 000-default.conf 2>/dev/null || true
apache2ctl configtest
systemctl reload apache2
echo "APACHE CONFIGURED"
on_failure: "abort"
- id: "init_database"
name: "Initialize wiki database and admin account"
type: "ssh_command"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
set -e
INSTALL_PATH="{{ install_path }}"
WIKI_TITLE="{{ wiki_title }}"
ADMIN_USER="{{ admin_username }}"
ADMIN_PASS="{{ admin_password }}"
# Run Common Grounds install script (if present)
if [ -f "$INSTALL_PATH/install.php" ]; then
php "$INSTALL_PATH/install.php" \
--title "$WIKI_TITLE" \
--admin-user "$ADMIN_USER" \
--admin-pass "$ADMIN_PASS" \
--db-path "$INSTALL_PATH/data/wiki.db" \
--non-interactive
echo "DB INITIALIZED via install.php"
elif [ -f "$INSTALL_PATH/scripts/init_db.sh" ]; then
bash "$INSTALL_PATH/scripts/init_db.sh" "$INSTALL_PATH/data/wiki.db" "$WIKI_TITLE" "$ADMIN_USER" "$ADMIN_PASS"
echo "DB INITIALIZED via init_db.sh"
else
echo "WARNING: No install script found — database may need manual initialization."
echo "Run: php $INSTALL_PATH/install.php --help"
fi
on_failure: "warn"
- id: "enable_https"
name: "Provision Let's Encrypt SSL (optional)"
type: "conditional_ssh_command"
condition: "{{ enable_https }}"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
set -e
DOMAIN="{{ domain_name }}"
EMAIL="{{ certbot_email }}"
if [ -z "$EMAIL" ]; then
echo "ERROR: certbot_email is required when enable_https=true"
exit 1
fi
apt-get install -y -qq python3-certbot-apache
certbot --apache -d "$DOMAIN" --non-interactive --agree-tos -m "$EMAIL"
echo "SSL PROVISIONED"
on_failure: "warn"
skip_if_condition_false: true
- id: "health_check"
name: "Post-install health check"
type: "ssh_command"
host: "{{ target_host }}"
user: "{{ ssh_user }}"
key: "{{ ssh_key_path }}"
command: |
DOMAIN="{{ domain_name }}"
PROTOCOL="http"
if [ "{{ enable_https }}" = "true" ]; then PROTOCOL="https"; fi
URL="${PROTOCOL}://${DOMAIN}/"
echo "Checking $URL ..."
STATUS=$(curl -s -o /dev/null -w "%{http_code}" --max-time 10 "$URL" || echo "000")
echo "HTTP status: $STATUS"
if [ "$STATUS" = "200" ] || [ "$STATUS" = "302" ]; then
echo "HEALTH CHECK PASS — wiki is reachable at $URL"
else
echo "HEALTH CHECK WARN — got HTTP $STATUS (DNS may not be propagated yet)"
echo "Verify manually: curl -v $URL"
fi
on_failure: "warn"
outputs:
- name: "wiki_url"
description: "URL of the deployed wiki"
value: "{{ 'https' if enable_https else 'http' }}://{{ domain_name }}/"
- name: "admin_url"
description: "Admin login URL"
value: "{{ 'https' if enable_https else 'http' }}://{{ domain_name }}/admin"
- name: "install_path"
description: "Filesystem path of the wiki installation"
value: "{{ install_path }}"
+100
View File
@@ -0,0 +1,100 @@
# IT Incident Triage Workflow Blueprint
**Blueprint ID**: `it/incident-triage-v1`
**Version**: 1.0.0
**Type**: `bridge_workflow`
**Pricing**: 150 credits/month (70% creator / 30% platform)
**Author**: XRAY VU (EOO9788)
Automates the first 10–15 minutes of every IT incident with consistent,
structured triage — from alert to incident channel summary.
---
## What This Blueprint Does
1. **Classifies severity** (P1/P2/P3/P4) using an AI classifier with configurable criteria
2. **Creates ITSM ticket** in ECP ITSM (or compatible system) with pre-filled fields
3. **Notifies on-call engineer** via Matrix DM
4. **Triggers PagerDuty** (optional) for P1/P2 incidents
5. **Gathers diagnostics** via SSH: service status, logs, disk/RAM, network
6. **Posts structured summary** to the incident channel
Total execution time: **under 2 minutes** (quick diagnostic mode).
---
## Requirements
- EIOS Bridge platform with `matrix` + `itsm` features enabled
- Claude Code harness available
- Matrix server (m.xrayvu.com or compatible)
- ECP ITSM module running
---
## Parameters
| Parameter | Required | Description |
|-----------|----------|-------------|
| `incident_title` | ✅ | One-line description of the incident |
| `affected_service` | ✅ | Service name (e.g. `auth-api`, `database`) |
| `reporter_entity_id` | ✅ | EIOS entity ID of reporter (e.g. `EOU0227`) |
| `matrix_incident_room` | ✅ | Matrix room for incident updates |
| `oncall_matrix_id` | ✅ | Matrix ID of on-call engineer |
| `affected_host` | ✗ | Server IP/hostname for SSH diagnostics |
| `severity_hint` | ✗ | Initial severity estimate (P1–P4, default P2) |
| `pagerduty_routing_key` | ✗ | PagerDuty routing key (omit to skip) |
| `itsm_project` | ✗ | ITSM project code (default: INFRA) |
| `diagnostic_depth` | ✗ | `quick` (2min) or `full` (10min), default quick |
---
## Example Usage
```bash
eios-blueprint run it/incident-triage-v1 \
--param incident_title="auth-api returning 503 for all login requests" \
--param affected_service="ecp-auth" \
--param affected_host="10.0.0.89" \
--param reporter_entity_id="EOU0227" \
--param matrix_incident_room="#incidents:m.xrayvu.com" \
--param oncall_matrix_id="@chris:m.xrayvu.com" \
--param severity_hint="P1" \
--param diagnostic_depth="full"
```
---
## Outputs
| Output | Description |
|--------|-------------|
| `incident_id` | Generated incident ID (e.g. `INC-20260609142233`) |
| `severity` | Determined severity (P1/P2/P3/P4) |
| `itsm_ticket_id` | Created ITSM ticket ID |
| `summary_posted` | Whether incident channel received the summary |
---
## Customization
This Blueprint is designed to be forked and customized:
- Change severity thresholds in the classifier prompt
- Add additional notification channels (Slack, email)
- Wire to your ITSM system via connector
- Extend diagnostic commands for your stack
---
## Certification Path
This Blueprint is currently `community` tier. To achieve `certified` tier:
- Validate with 3 documented production incidents
- Submit for security review ($2,000 fee)
- Provides: SLA guarantee + enterprise support eligibility
---
*it/incident-triage-v1 | EIOS Blueprint Package | 2026-06-09*
@@ -0,0 +1,142 @@
# EIOS Blueprint Package — IT Incident Triage Workflow
# Conforms to: BLUEPRINT_SCHEMA_v1_0.json
blueprint_id: "it/incident-triage-v1"
version: "1.0.0"
name: "IT Incident Triage Workflow"
blueprint_type: "bridge_workflow"
author:
entity_id: "EOO9788"
display_name: "XRAY VU"
url: "https://ecp.xrayvu.com"
license: "commercial"
description: "Automated P1/P2 incident triage: classify severity, notify on-call, create ITSM ticket, dispatch an actor to gather diagnostics, and summarize for the incident commander."
long_description: |
This Blueprint automates the first 10–15 minutes of every IT incident — the
most chaotic and error-prone window. When an alert fires or a user reports
an issue, the workflow:
1. **Classifies severity** (P1/P2/P3/P4) using configurable impact criteria
2. **Notifies on-call** via Matrix DM, PagerDuty, or both
3. **Creates an ITSM ticket** in ECP ITSM with pre-filled fields
4. **Dispatches a diagnostic actor** (Claude Code) to gather logs, check services, and
produce a structured diagnostic report
5. **Posts a summary** to the incident channel for the incident commander
What used to take 10–20 minutes of manual work now happens in under 2 minutes,
with a consistent structure every time.
**Integration points**:
- Input: alert webhook (PagerDuty/Grafana/custom), Matrix message, or CLI trigger
- ITSM: ECP ITSM module (or ServiceNow/Jira via connector)
- Notification: Matrix room + optional PagerDuty
- Diagnostics: SSH to affected host, `journalctl`, `ss`, `df`, `systemctl`
**Certification path**: This Blueprint is designed to be submitted for `certified`
tier after validation with 3 production incidents.
domain: "technology"
tags:
- "incident-management"
- "itsm"
- "triage"
- "on-call"
- "automation"
- "devops"
- "monitoring"
- "matrix"
certification: "community"
pricing:
model: "subscription"
amount_credits: 150
revenue_split:
creator_pct: 70
platform_pct: 30
requires:
bridge_version: ">=0.1.0"
eios_version: ">=1.0.0"
platform_features:
- "matrix"
- "itsm"
actor_harnesses:
- "claude-code"
dependencies: []
entry_point: "workflow.yaml"
parameters:
incident_title:
type: string
description: "Short description of the incident (1 sentence)."
required: true
affected_service:
type: string
description: "Name of the affected service or system."
required: true
affected_host:
type: string
description: "Hostname or IP of the primary affected host (for diagnostics). Leave blank to skip SSH diagnostics."
required: false
severity_hint:
type: enum
description: "Reporter's initial severity estimate. Workflow may upgrade but not downgrade."
required: false
default: "P2"
enum_values: ["P1", "P2", "P3", "P4"]
reporter_entity_id:
type: string
description: "EIOS entity ID of the person reporting the incident (e.g. EOU0227)."
required: true
matrix_incident_room:
type: string
description: "Matrix room ID or alias for incident updates (e.g. #incidents:m.xrayvu.com)."
required: true
oncall_matrix_id:
type: string
description: "Matrix user ID of the current on-call engineer (e.g. @chris:m.xrayvu.com)."
required: true
pagerduty_routing_key:
type: string
description: "PagerDuty Events API v2 routing key. Leave blank to skip PagerDuty."
required: false
sensitive: true
itsm_project:
type: string
description: "ECP ITSM project code for ticket creation."
required: false
default: "INFRA"
diagnostic_depth:
type: enum
description: "How deep the diagnostic actor should go. 'quick' = 2min, 'full' = 10min."
required: false
default: "quick"
enum_values: ["quick", "full"]
oss:
publish_ready: false
tier: "tier2"
stripping_required: true
marketplace:
status: "draft"
changelog:
- version: "1.0.0"
date: "2026-06-09"
changes: "Initial release. P1/P2 classification, Matrix notify, ECP ITSM ticket, SSH diagnostics, summary post."
@@ -0,0 +1,202 @@
# IT Incident Triage — Workflow Definition
# Blueprint: it/incident-triage-v1
# bridge_workflow: executes on Bridge platform via claude-code harness
name: "IT Incident Triage Workflow"
version: "1.0.0"
executor: "claude-code"
timeout_minutes: 15
context:
# Execution context available to all steps as {{ ctx.* }}
incident_id: "INC-{{ timestamp_utc | date('YYYYMMDDHHmmss') }}"
started_at: "{{ timestamp_utc }}"
platform: "eios-bridge"
steps:
- id: "classify_severity"
name: "Classify incident severity"
type: "actor_task"
harness: "claude-code"
prompt: |
You are an IT incident classifier. Given the following incident report,
determine the correct severity level (P1/P2/P3/P4) using these criteria:
P1 — Complete outage or data loss affecting production users NOW
P2 — Significant degradation affecting multiple users or core services
P3 — Partial degradation, workaround available, no data loss
P4 — Minor issue, cosmetic, or low-traffic service affected
Incident title: {{ incident_title }}
Affected service: {{ affected_service }}
Reporter's estimate: {{ severity_hint }}
Respond with a JSON object:
{
"severity": "P1|P2|P3|P4",
"severity_rationale": "one sentence",
"confidence": "high|medium|low",
"escalate_immediately": true|false
}
output_var: "classification"
parse_json: true
on_failure: "use_default"
default_output:
severity: "{{ severity_hint }}"
severity_rationale: "Classification failed — using reporter hint"
confidence: "low"
escalate_immediately: "{{ true if severity_hint == 'P1' else false }}"
- id: "create_itsm_ticket"
name: "Create ITSM ticket"
type: "api_call"
endpoint: "ecp-itsm"
method: "POST"
path: "/api/v1/incidents"
body:
title: "{{ incident_title }}"
severity: "{{ classification.severity }}"
affected_service: "{{ affected_service }}"
reporter: "{{ reporter_entity_id }}"
project: "{{ itsm_project }}"
description: |
Auto-created by IT Incident Triage Blueprint v1.0.0
Incident ID: {{ ctx.incident_id }}
Severity determined: {{ classification.severity }} ({{ classification.confidence }} confidence)
Rationale: {{ classification.severity_rationale }}
status: "open"
output_var: "itsm_ticket"
on_failure: "warn"
- id: "notify_oncall"
name: "Notify on-call engineer via Matrix"
type: "matrix_message"
room: "{{ oncall_matrix_id }}"
message: |
🚨 **{{ classification.severity }} INCIDENT** — {{ incident_title }}
**Service**: {{ affected_service }}
**Incident ID**: {{ ctx.incident_id }}
**ITSM Ticket**: {{ itsm_ticket.ticket_id | default('pending') }}
**Confidence**: {{ classification.confidence }}
{{ '⚡ ESCALATE IMMEDIATELY' if classification.escalate_immediately else '📋 Standard triage in progress' }}
Diagnostic report incoming...
on_failure: "warn"
- id: "notify_pagerduty"
name: "Trigger PagerDuty alert (if configured)"
type: "conditional_api_call"
condition: "{{ pagerduty_routing_key is defined and pagerduty_routing_key != '' }}"
endpoint: "https://events.pagerduty.com/v2/enqueue"
method: "POST"
headers:
Content-Type: "application/json"
body:
routing_key: "{{ pagerduty_routing_key }}"
event_action: "trigger"
payload:
summary: "{{ classification.severity }}: {{ incident_title }}"
severity: "{{ 'critical' if classification.severity == 'P1' else 'error' if classification.severity == 'P2' else 'warning' }}"
source: "eios-bridge-triage"
custom_details:
incident_id: "{{ ctx.incident_id }}"
affected_service: "{{ affected_service }}"
itsm_ticket: "{{ itsm_ticket.ticket_id | default('N/A') }}"
on_failure: "warn"
skip_if_condition_false: true
- id: "run_diagnostics"
name: "Gather host diagnostics"
type: "conditional_actor_task"
condition: "{{ affected_host is defined and affected_host != '' }}"
harness: "claude-code"
prompt: |
You are a diagnostic engineer. Connect to the affected host and gather
information about the incident. Use {{ diagnostic_depth }} mode.
Host: {{ affected_host }}
Service: {{ affected_service }}
Incident: {{ incident_title }}
{% if diagnostic_depth == 'quick' %}
Quick mode (2 min): Check these and report:
1. `systemctl status {{ affected_service }} 2>/dev/null || echo 'service not found in systemd'`
2. `journalctl -u {{ affected_service }} --since "5 minutes ago" --no-pager -n 50 2>/dev/null || journalctl --since "5 minutes ago" --no-pager -n 50`
3. `df -h / && free -h`
4. `ss -tlnp | grep -E ':(80|443|8080|8443|3000|5000|8000)' || true`
{% else %}
Full mode (10 min): Gather comprehensive diagnostics:
1. Service status + recent logs (last 200 lines)
2. System resources: disk, memory, CPU load
3. Network: listening ports, active connections
4. Recent kernel messages: `dmesg | tail -30`
5. Process list: `ps aux --sort=-%cpu | head -20`
6. Recent auth attempts: `journalctl -u ssh --since "30 minutes ago" --no-pager -n 20`
{% endif %}
Produce a structured diagnostic report with:
- executive_summary: 2-3 sentences
- likely_cause: your best hypothesis
- immediate_actions: list of 1-3 concrete steps
- raw_findings: the actual command outputs
output_var: "diagnostics"
on_failure: "warn"
default_output:
executive_summary: "Diagnostic skipped — no host specified or connection failed."
likely_cause: "Unknown"
immediate_actions: ["Manually SSH to affected host", "Check service status", "Review logs"]
raw_findings: ""
skip_if_condition_false: true
- id: "post_incident_summary"
name: "Post incident summary to incident channel"
type: "matrix_message"
room: "{{ matrix_incident_room }}"
message: |
## 🚨 Incident {{ ctx.incident_id }} — {{ classification.severity }}
**{{ incident_title }}**
**Service**: {{ affected_service }}
**ITSM**: {{ itsm_ticket.ticket_id | default('Ticket creation failed') }}
**Reported by**: {{ reporter_entity_id }}
**Started**: {{ ctx.started_at }}
---
**Severity Assessment** ({{ classification.confidence }} confidence):
{{ classification.severity_rationale }}
---
**Diagnostics**:
{{ diagnostics.executive_summary | default('No diagnostics available') }}
**Likely cause**: {{ diagnostics.likely_cause | default('Under investigation') }}
**Immediate actions**:
{% for action in diagnostics.immediate_actions | default([]) %}
- {{ action }}
{% endfor %}
---
*Auto-generated by IT Incident Triage Blueprint v1.0.0*
*Incident commander: {{ oncall_matrix_id }}*
on_failure: "abort"
outputs:
- name: "incident_id"
description: "Generated incident ID"
value: "{{ ctx.incident_id }}"
- name: "severity"
description: "Determined severity level"
value: "{{ classification.severity }}"
- name: "itsm_ticket_id"
description: "Created ITSM ticket ID"
value: "{{ itsm_ticket.ticket_id | default('N/A') }}"
- name: "summary_posted"
description: "Whether summary was posted to incident channel"
value: "{{ true }}"
+158
View File
@@ -0,0 +1,158 @@
blueprint_id: "bridge/org-bootstrap-v1"
version: "1.0.0"
blueprint_type: "bridge_configuration"
name: "Bridge Organization Bootstrap"
description: |
Bootstraps a new organization in The Bridge in under 15 minutes.
Creates the entity registry entries, default roles, Matrix rooms, ITSM
project, and welcome message for a new Bridge client or implementation partner.
long_description: |
The Organization Bootstrap Blueprint is the fastest path to a fully provisioned
Bridge organization. It handles the complete onboarding sequence:
1. Register the organization entity (EOO) and admin user entity (EOU) in the EIOS entity registry
2. Create default role assignments (admin, member, viewer)
3. Provision a Matrix room (org_room_id) scoped to the organization
4. Create an ITSM project for incident and request tracking
5. Send a welcome message to the admin user via Matrix
6. Generate a summary report with all provisioned resources and next steps
Designed for Bridge implementation partners onboarding new clients, or for
self-service setup by technical organizations joining The Bridge ecosystem.
author:
entity_id: "EOO9788"
display_name: "XRAY VU"
license: "MIT"
pricing:
model: "free"
amount_credits: 0
certification: "community"
domain: "technology"
tags:
- "onboarding"
- "organization"
- "setup"
- "configuration"
- "entity-registry"
- "bridge"
- "matrix"
- "itsm"
marketplace:
status: "published"
oss:
publish_ready: true
tier: "tier1"
stripping_required: false
requires:
bridge_version: ">=0.1.0"
platform_features:
- "entity-registry"
- "matrix"
- "itsm"
parameters:
# Required — organization identity
org_display_name:
type: string
required: true
description: "Human-readable organization name (e.g. 'Acme Corp')"
example: "Carriers Edge"
org_entity_id:
type: string
required: true
description: "EIOS entity ID for the organization — format EOOxxxx (e.g. EOO0042)"
example: "EOO0042"
pattern: "^EOO[0-9]{4}$"
admin_user_entity_id:
type: string
required: true
description: "EIOS entity ID for the admin user — format EOUxxxx"
example: "EOU0100"
pattern: "^EOU[0-9]{4}$"
admin_display_name:
type: string
required: true
description: "Admin user's display name"
example: "Jane Smith"
admin_email:
type: string
required: true
description: "Admin user's email address"
example: "jane@acmecorp.com"
# Optional — organization configuration
org_domain:
type: string
required: false
default: ""
description: "Primary domain of the organization (e.g. acmecorp.com)"
org_industry:
type: string
required: false
default: "general"
description: "Industry vertical for taxonomy"
enum_values:
- "general"
- "healthcare"
- "finance"
- "education"
- "logistics"
- "technology"
- "government"
- "nonprofit"
create_matrix_room:
type: boolean
required: false
default: true
description: "Create a Matrix room for the organization"
create_itsm_project:
type: boolean
required: false
default: true
description: "Create an ITSM project for the organization"
itsm_project_key:
type: string
required: false
default: ""
description: "ITSM project key (auto-derived from org_entity_id if empty)"
send_welcome_message:
type: boolean
required: false
default: true
description: "Send a welcome Matrix message to the admin user"
assign_implementation_partner:
type: string
required: false
default: ""
description: "Entity ID of the implementation partner (leave empty for self-service)"
org_tier:
type: string
required: false
default: "community"
description: "Organization tier in The Bridge"
enum_values:
- "community"
- "verified"
- "enterprise"
entry_point: "workflow.yaml"
+192
View File
@@ -0,0 +1,192 @@
workflow_id: "bridge/org-bootstrap-v1/workflow"
version: "1.0.0"
description: "Organization Bootstrap — provision a new Bridge org end-to-end"
steps:
- id: validate_entity_ids
name: "Validate Entity IDs"
type: actor_task
harness: "claude-code"
prompt: |
Validate the following entity IDs are not already registered in the EIOS entity registry.
Check `/opt/EIOS/data/entities/registry/entity_registry.yaml` for existing entries.
Organization entity ID: {{ org_entity_id }}
Admin user entity ID: {{ admin_user_entity_id }}
Return JSON: {"org_available": true/false, "user_available": true/false, "conflicts": []}
parse_json: true
output_var: validation_result
on_failure: "abort"
- id: register_organization
name: "Register Organization Entity"
type: actor_task
harness: "claude-code"
depends_on: ["validate_entity_ids"]
condition: "{{ validation_result.org_available }}"
skip_if_condition_false: false
on_condition_false: "abort_with_message: Organization entity ID {{ org_entity_id }} already exists in registry"
prompt: |
Register a new organization entity in the EIOS entity registry.
Entity details:
- entity_id: {{ org_entity_id }}
- entity_type: EOO (Organization)
- display_name: {{ org_display_name }}
- domain: {{ org_domain }}
- industry: {{ org_industry }}
- tier: {{ org_tier }}
- created_at: (current UTC timestamp)
- admin_entity_id: {{ admin_user_entity_id }}
Write the entity record to:
`/opt/EIOS/data/entities/registry/orgs/{{ org_entity_id }}.yaml`
Follow the schema at `/opt/LIFERAFT/repo/eios/data/_staging/ENTITY_SCHEMA_v1_0.yaml` if it exists.
Use standard EIOS entity YAML format otherwise.
Return JSON: {"entity_path": "<path written>", "success": true}
parse_json: true
output_var: org_registration
on_failure: "abort"
- id: register_admin_user
name: "Register Admin User Entity"
type: actor_task
harness: "claude-code"
depends_on: ["register_organization"]
prompt: |
Register the admin user entity for the new organization.
Entity details:
- entity_id: {{ admin_user_entity_id }}
- entity_type: EOU (User)
- display_name: {{ admin_display_name }}
- email: {{ admin_email }}
- org_entity_id: {{ org_entity_id }}
- roles: ["org_admin"]
- created_at: (current UTC timestamp)
Write the entity record to:
`/opt/EIOS/data/entities/registry/users/{{ admin_user_entity_id }}.yaml`
Return JSON: {"entity_path": "<path written>", "success": true}
parse_json: true
output_var: user_registration
on_failure: "abort"
- id: create_matrix_room
name: "Create Matrix Room"
type: conditional_actor_task
harness: "claude-code"
depends_on: ["register_admin_user"]
condition: "{{ create_matrix_room }}"
skip_if_condition_false: true
prompt: |
Create a Matrix room for the organization using the Matrix API.
Organization: {{ org_display_name }} ({{ org_entity_id }})
Steps:
1. Create a room with alias `#{{ org_entity_id | lower }}_main:m.xrayvu.com`
2. Set room name to "{{ org_display_name }} — Main"
3. Set room topic to "{{ org_display_name }} organization room — The Bridge"
4. Set join_rule to "invite" (private)
5. Invite {{ admin_user_entity_id }} as admin
Use the Matrix client-server API via the eios-matrix tools or the Matrix admin API.
Matrix homeserver: m.xrayvu.com
Return JSON: {"room_id": "!...:m.xrayvu.com", "room_alias": "#...:m.xrayvu.com", "success": true}
parse_json: true
output_var: matrix_result
default_output: '{"room_id": null, "room_alias": null, "success": false}'
on_failure: "continue_with_warning"
- id: create_itsm_project
name: "Create ITSM Project"
type: conditional_actor_task
harness: "claude-code"
depends_on: ["register_admin_user"]
condition: "{{ create_itsm_project }}"
skip_if_condition_false: true
prompt: |
Create an ITSM project for the new organization.
Organization: {{ org_display_name }} ({{ org_entity_id }})
Project key: {{ itsm_project_key if itsm_project_key else org_entity_id }}
Use the ECP ALM/ITSM API at the local ECP platform endpoint.
Create a project with:
- name: "{{ org_display_name }} — Operations"
- key: {{ itsm_project_key if itsm_project_key else org_entity_id }}
- org_entity_id: {{ org_entity_id }}
- admin: {{ admin_user_entity_id }}
- default queues: Incidents, Requests, Changes
Return JSON: {"project_id": "<id>", "project_key": "<key>", "success": true}
parse_json: true
output_var: itsm_result
default_output: '{"project_id": null, "project_key": null, "success": false}'
on_failure: "continue_with_warning"
- id: send_welcome_message
name: "Send Welcome Message"
type: conditional_actor_task
harness: "claude-code"
depends_on: ["create_matrix_room"]
condition: "{{ send_welcome_message and create_matrix_room }}"
skip_if_condition_false: true
prompt: |
Send a welcome message to the newly created organization Matrix room.
Room ID: {{ matrix_result.room_id }}
Organization: {{ org_display_name }}
Admin: {{ admin_display_name }} ({{ admin_user_entity_id }})
Send a formatted welcome message that includes:
- Welcome to The Bridge heading
- Organization entity ID: {{ org_entity_id }}
- Admin user: {{ admin_display_name }} ({{ admin_email }})
- Quick-start links (ITSM project, documentation, support room)
- Next steps: invite team members, configure integrations, review the Blueprint marketplace
Use the Matrix client API to send an m.room.message event with msgtype m.text.
Return JSON: {"event_id": "$...", "success": true}
parse_json: true
output_var: welcome_result
default_output: '{"event_id": null, "success": false}'
on_failure: "continue_with_warning"
- id: generate_summary_report
name: "Generate Bootstrap Summary Report"
type: actor_task
harness: "claude-code"
depends_on: ["send_welcome_message", "create_itsm_project"]
prompt: |
Generate a bootstrap summary report for the new organization.
Provisioned resources:
- Organization entity: {{ org_entity_id }} ({{ org_display_name }})
- Admin user entity: {{ admin_user_entity_id }} ({{ admin_display_name }})
- Organization registry path: {{ org_registration.entity_path }}
- User registry path: {{ user_registration.entity_path }}
- Matrix room: {{ matrix_result.room_id if matrix_result.success else "NOT CREATED" }}
- ITSM project: {{ itsm_result.project_key if itsm_result.success else "NOT CREATED" }}
Write a Markdown summary report to:
`/opt/EIOS/data/entities/registry/orgs/{{ org_entity_id }}_bootstrap_report.md`
The report should include:
1. Bootstrap summary table (all resources + status)
2. Next steps checklist (invite team, configure integrations, first Blueprint)
3. Credentials and access information
4. Support contacts (Bridge support Matrix room, documentation links)
5. Timestamp and session ID
Return JSON: {"report_path": "<path>", "success": true}
parse_json: true
output_var: report_result
on_failure: "continue_with_warning"
@@ -0,0 +1,153 @@
# EIOS Blueprint Package — Security Assessment Report Generator
# Conforms to: BLUEPRINT_SCHEMA_v1_0.json
blueprint_id: "security/assessment-report-v1"
version: "1.0.0"
name: "Security Assessment Report Generator"
blueprint_type: "bridge_workflow"
author:
entity_id: "EOO9788"
display_name: "XRAY VU"
url: "https://ecp.xrayvu.com"
license: "commercial"
description: "Generates a structured security assessment report from interview notes and questionnaire responses. Covers 8 control domains with findings, risk ratings, and remediation recommendations."
long_description: |
Transforms raw security questionnaire responses and interview notes into a
professional, structured security assessment report in 5–10 minutes.
This Blueprint emerged from the CarriersEdge Business Email Compromise (BEC)
assessment engagement (XRVU-2026-CE-001) and generalizes the methodology into
a reusable workflow applicable to any organization seeking a rapid security
gap analysis.
**Control domains covered** (NIST CSF 2.0 aligned):
1. Email Security (SPF, DKIM, DMARC, BEC defenses)
2. Identity & Access Management
3. Endpoint Protection
4. Network Security
5. Data Protection & Classification
6. Incident Response Readiness
7. Training & Awareness
8. Third-Party / Supply Chain Risk
**Output**: Markdown + optionally PDF (via BIDS integration):
- Executive summary
- Risk rating per domain (Critical/High/Medium/Low/Informational)
- Specific findings with evidence
- Prioritized remediation roadmap (90-day / 1-year)
- Estimated effort/cost per recommendation
**Use cases**:
- Pre-engagement security posture baseline
- Vendor/supplier assessment
- Annual security review automation
- M&A due diligence screening
- Insurance questionnaire support
domain: "security"
tags:
- "security"
- "assessment"
- "risk"
- "nist-csf"
- "email-security"
- "bec"
- "gap-analysis"
- "compliance"
- "report"
certification: "community"
pricing:
model: "usage"
amount_credits: 50
usage_unit: "per_report"
revenue_split:
creator_pct: 70
platform_pct: 30
requires:
bridge_version: ">=0.1.0"
eios_version: ">=1.0.0"
platform_features: []
actor_harnesses:
- "claude-code"
dependencies: []
entry_point: "workflow.yaml"
parameters:
organization_name:
type: string
description: "Name of the organization being assessed."
required: true
organization_size:
type: enum
description: "Approximate employee count bracket."
required: true
enum_values: ["1-10", "11-50", "51-200", "201-1000", "1000+"]
industry:
type: string
description: "Industry sector (e.g. 'logistics', 'healthcare', 'financial services')."
required: true
assessment_scope:
type: string
description: "Brief description of what is in scope (e.g. 'corporate email and endpoints only')."
required: false
default: "Full organization security posture"
questionnaire_responses:
type: string
description: |
Raw questionnaire responses. Paste the intake questionnaire answers here.
Plain text or Markdown accepted. The actor will parse and extract findings.
required: true
interview_notes:
type: string
description: "Notes from discovery interviews or additional context. Plain text."
required: false
default: ""
report_date:
type: string
description: "Report date in YYYY-MM-DD format. Defaults to today."
required: false
assessor_entity_id:
type: string
description: "EIOS entity ID of the assessor (used for report attribution)."
required: false
default: "EOA0000"
generate_pdf:
type: boolean
description: "If true and BIDS is available, also generates a PDF version via BIDS."
required: false
default: false
output_path:
type: string
description: "Filesystem path for the output report file (on the actor's host)."
required: false
default: "/opt/LIFERAFT/repo/eios/data/_staging/eoo/EOO9788/security-assessments/"
oss:
publish_ready: false
tier: "tier2"
stripping_required: true
marketplace:
status: "draft"
changelog:
- version: "1.0.0"
date: "2026-06-09"
changes: "Initial release. 8 NIST CSF domains; findings extraction; risk rating; 90-day roadmap; BIDS PDF optional."
@@ -0,0 +1,258 @@
# Security Assessment Report Generator — Workflow Definition
# Blueprint: security/assessment-report-v1
# bridge_workflow: executes on Bridge platform via claude-code harness
name: "Security Assessment Report Generator"
version: "1.0.0"
executor: "claude-code"
timeout_minutes: 15
context:
report_id: "SAR-{{ timestamp_utc | date('YYYYMMDD') }}-{{ organization_name | slug | upper }}"
report_date_resolved: "{{ report_date | default(timestamp_utc | date('YYYY-MM-DD')) }}"
steps:
- id: "parse_and_classify"
name: "Parse questionnaire responses and classify findings"
type: "actor_task"
harness: "claude-code"
prompt: |
You are a senior cybersecurity assessor. Analyze the following questionnaire
responses and extract security findings for each of the 8 control domains.
**Organization**: {{ organization_name }}
**Size**: {{ organization_size }} employees
**Industry**: {{ industry }}
**Scope**: {{ assessment_scope }}
**Questionnaire Responses**:
{{ questionnaire_responses }}
{% if interview_notes %}
**Interview Notes**:
{{ interview_notes }}
{% endif %}
For each of the 8 control domains below, produce a structured assessment:
1. Email Security (SPF/DKIM/DMARC, BEC defenses, MFA on email)
2. Identity & Access Management (MFA, privileged access, offboarding)
3. Endpoint Protection (AV/EDR, patch management, disk encryption)
4. Network Security (firewall, segmentation, VPN, monitoring)
5. Data Protection & Classification (backup, encryption, data inventory)
6. Incident Response Readiness (IR plan, tabletop exercises, contacts)
7. Training & Awareness (phishing simulations, security training frequency)
8. Third-Party / Supply Chain Risk (vendor assessment, contract clauses)
For each domain, produce a JSON object:
{
"domain": "domain name",
"risk_rating": "Critical|High|Medium|Low|Informational",
"score": <0-10 where 10=fully mature>,
"findings": [
{
"id": "F001",
"title": "concise finding title",
"severity": "Critical|High|Medium|Low|Informational",
"description": "what was found",
"evidence": "what the questionnaire said that supports this",
"recommendation": "specific remediation action"
}
],
"positive_observations": ["things they're doing well"],
"summary": "2-3 sentence domain summary"
}
Respond with a JSON array of 8 domain objects.
If a domain has insufficient information, mark risk_rating as "Unknown" and
note what information would be needed.
output_var: "domain_assessments"
parse_json: true
on_failure: "abort"
- id: "generate_executive_summary"
name: "Generate executive summary"
type: "actor_task"
harness: "claude-code"
prompt: |
You are a senior cybersecurity assessor writing for a non-technical executive audience.
Based on these domain assessments for {{ organization_name }}:
{{ domain_assessments | tojson(indent=2) }}
Write an executive summary (300-500 words) that:
1. States the overall security posture in plain language
2. Identifies the top 3 risk areas requiring immediate attention
3. Notes 2-3 areas where the organization is doing well
4. Provides a clear, non-technical statement of business risk
5. Sets expectations for the remediation roadmap
Do NOT use jargon without explaining it.
Tone: professional, direct, constructive — not alarmist.
Respond with the executive summary as a markdown string (no JSON wrapper).
output_var: "executive_summary"
on_failure: "warn"
default_output: "Executive summary generation failed. Review domain findings directly."
- id: "generate_remediation_roadmap"
name: "Generate prioritized remediation roadmap"
type: "actor_task"
harness: "claude-code"
prompt: |
You are a cybersecurity advisor generating a practical remediation roadmap.
Organization: {{ organization_name }} ({{ organization_size }} employees, {{ industry }})
Domain assessments: {{ domain_assessments | tojson(indent=2) }}
Generate a prioritized remediation roadmap as a JSON object with two phases:
{
"immediate_actions": [ // 30-90 days: critical/high findings
{
"priority": 1,
"finding_ids": ["F001", "F002"],
"action": "specific action to take",
"rationale": "why this is urgent",
"estimated_effort": "hours|days|weeks",
"estimated_cost": "free|<$1K|$1K-$5K|$5K-$20K|$20K+",
"responsible_party": "IT team|CISO|Vendor|All staff"
}
],
"strategic_improvements": [ // 6-12 months: medium findings + architecture
{ ... same structure ... }
],
"overall_risk_score": <0-100>,
"maturity_level": "Initial|Developing|Defined|Managed|Optimizing"
}
Limit immediate_actions to top 5 most impactful items.
Limit strategic_improvements to top 7 items.
output_var: "roadmap"
parse_json: true
on_failure: "warn"
default_output:
immediate_actions: []
strategic_improvements: []
overall_risk_score: 0
maturity_level: "Unknown"
- id: "assemble_report"
name: "Assemble final report document"
type: "actor_task"
harness: "claude-code"
prompt: |
Assemble a complete security assessment report in Markdown format.
Use these inputs:
- Report ID: {{ ctx.report_id }}
- Date: {{ ctx.report_date_resolved }}
- Organization: {{ organization_name }}
- Industry: {{ industry }}
- Size: {{ organization_size }}
- Scope: {{ assessment_scope }}
- Assessor entity: {{ assessor_entity_id }}
- Executive summary: {{ executive_summary }}
- Domain assessments: {{ domain_assessments | tojson(indent=2) }}
- Roadmap: {{ roadmap | tojson(indent=2) }}
Structure the report as follows:
# Security Assessment Report: {{ organization_name }}
## Report ID: [id] | Date: [date] | Assessor: [entity]
## Executive Summary
[executive_summary]
## Assessment Scope
[scope description]
## Overall Risk Posture
Overall Risk Score: [X/100] | Maturity Level: [level]
[summary table of all 8 domains with risk rating and score]
## Domain Findings
### 1. Email Security
[findings for each domain in detail]
... (repeat for all 8 domains)
## Remediation Roadmap
### Immediate Actions (30–90 Days)
[immediate actions table]
### Strategic Improvements (6–12 Months)
[strategic improvements table]
## Methodology & Limitations
This assessment is based on questionnaire responses and interview notes only.
It is not a penetration test or technical audit. Findings should be validated
by technical staff before remediation prioritization.
---
*Generated by EIOS Bridge — Security Assessment Blueprint v1.0.0*
*{{ ctx.report_id }}*
Output ONLY the complete markdown report. No additional commentary.
output_var: "report_markdown"
on_failure: "abort"
- id: "write_report_file"
name: "Write report to filesystem"
type: "file_write"
path: "{{ output_path }}{{ ctx.report_id }}.md"
content: "{{ report_markdown }}"
create_dirs: true
on_failure: "abort"
- id: "generate_pdf"
name: "Generate PDF via BIDS (optional)"
type: "conditional_actor_task"
condition: "{{ generate_pdf }}"
harness: "claude-code"
prompt: |
Generate a PDF version of this security assessment report using BIDS.
Report path: {{ output_path }}{{ ctx.report_id }}.md
BIDS API: http://localhost:8401
Run:
curl -s -X POST http://localhost:8401/api/render \
-H "Content-Type: application/json" \
-d '{
"source": "{{ output_path }}{{ ctx.report_id }}.md",
"output": "{{ output_path }}{{ ctx.report_id }}.pdf",
"template": "security_assessment",
"engine": "weasyprint"
}'
Report the HTTP status and output path.
output_var: "pdf_result"
on_failure: "warn"
skip_if_condition_false: true
outputs:
- name: "report_id"
description: "Unique report identifier"
value: "{{ ctx.report_id }}"
- name: "report_path"
description: "Filesystem path of the generated report"
value: "{{ output_path }}{{ ctx.report_id }}.md"
- name: "pdf_path"
description: "PDF report path (if generated)"
value: "{{ output_path }}{{ ctx.report_id }}.pdf"
- name: "overall_risk_score"
description: "Aggregated risk score (0-100, higher = worse)"
value: "{{ roadmap.overall_risk_score }}"
- name: "maturity_level"
description: "NIST CSF maturity level"
value: "{{ roadmap.maturity_level }}"
- name: "critical_findings_count"
description: "Number of Critical severity findings across all domains"
value: "{{ domain_assessments | selectattr('risk_rating', 'eq', 'Critical') | list | length }}"
+52
View File
@@ -0,0 +1,52 @@
{
"registry": "X-Frames Blueprint Registry",
"version": "1.0.0",
"updated": "2026-06-10",
"schema": "BLUEPRINT_SCHEMA_v1_0.json",
"blueprints": [
{
"id": "infrastructure/common-grounds-deploy-v1",
"version": "1.0.0",
"name": "Common Grounds Wiki Deployment",
"blueprint_type": "bridge_configuration",
"license": "MIT",
"description": "Deploy a self-hosted Common Grounds wiki on any Debian/Ubuntu server in under 5 minutes. Includes Apache config, PHP, SQLite database, and optional SSL setup.",
"author": "EOO9788",
"registry_path": "blueprints/common-grounds-deploy-v1/",
"url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/common-grounds-deploy-v1/blueprint.yaml"
},
{
"id": "it/incident-triage-v1",
"version": "1.0.0",
"name": "IT Incident Triage Workflow",
"blueprint_type": "bridge_workflow",
"license": "commercial",
"description": "Automated P1/P2 incident triage: classify severity, notify on-call, create ITSM ticket, dispatch an actor to gather diagnostics, and summarize for the incident commander.",
"author": "EOO9788",
"registry_path": "blueprints/it-incident-triage-v1/",
"url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/it-incident-triage-v1/blueprint.yaml"
},
{
"id": "bridge/org-bootstrap-v1",
"version": "1.0.0",
"name": "Bridge Organization Bootstrap",
"blueprint_type": "bridge_configuration",
"license": "MIT",
"description": "Bootstraps a new organization in The Bridge in under 15 minutes.\nCreates the entity registry entries, default roles, Matrix rooms, ITSM\nproject, and welcome message for a new Bridge client or implemen",
"author": "EOO9788",
"registry_path": "blueprints/org-bootstrap-v1/",
"url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/org-bootstrap-v1/blueprint.yaml"
},
{
"id": "security/assessment-report-v1",
"version": "1.0.0",
"name": "Security Assessment Report Generator",
"blueprint_type": "bridge_workflow",
"license": "commercial",
"description": "Generates a structured security assessment report from interview notes and questionnaire responses. Covers 8 control domains with findings, risk ratings, and remediation recommendations.",
"author": "EOO9788",
"registry_path": "blueprints/security-assessment-v1/",
"url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/security-assessment-v1/blueprint.yaml"
}
]
}