aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--AGENTS.md10
-rw-r--r--docs/BACKLOG.md42
2 files changed, 52 insertions, 0 deletions
diff --git a/AGENTS.md b/AGENTS.md
index a8741f4..2dc08cc 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -367,3 +367,13 @@ settles only what they share.
- `docs/BACKLOG.md`, open items, with the cause verified in the code rather
than assumed. Read it before starting work; add to it rather than fixing
something unasked.
+
+The author also keeps an idea note OUTSIDE this repository, in his Obsidian
+vault at `~/Documents/Obsidian/note/notes on abusectl.md`. It is an inbox,
+written as things occur to him while developing or using the tool, split into
+done and not-done and in no particular order. **The note is the inbox, the
+backlog is the tracked list.** Reconcile them in both directions when starting
+substantial work: an idea in the note that is real work earns a backlog entry
+with its cause verified in the code, and a backlog item he has marked done in
+the note can be closed. Do not edit the note unasked; it is his, not the
+repository's.
diff --git a/docs/BACKLOG.md b/docs/BACKLOG.md
index 79c0ab1..60405c0 100644
--- a/docs/BACKLOG.md
+++ b/docs/BACKLOG.md
@@ -7,6 +7,7 @@ number and gains a status rather than being renumbered.
|---|------|------|--------|
| 1 | Skip boilerplate namespace URLs | XS | open |
| 2 | An IDN indicator resolves to no contact | S | open |
+| 3 | Expose kept cases so qtmaildir can tag spam | ? | open, unsized |
## 1. Skip boilerplate namespace URLs
@@ -67,3 +68,44 @@ where the attacker wants the tool to normalise on their behalf, and a
consultant chasing one indicator by hand is a smaller cost than a query made
about a name the user never saw. Wait for a real IDN indicator in a sweep before
building it.
+
+## 3. Expose kept cases so qtmaildir can tag spam
+
+**Source.** The author's idea note, not a defect found in the code. Unlike
+items 1 and 2 the cause here has NOT been verified against the code, because
+there is nothing built yet to verify: this is a feature request, and it is
+recorded unsized on purpose.
+
+**Observed.** Case directories are permanent by design, so over time they
+become a local corpus of messages the user has already judged to be phishing.
+Nothing reads them back. The idea is that qtmaildir could ask this tool
+whether an incoming message resembles one, and tag it as spam when it does.
+
+**Approach.** Undecided, and the shape matters more than the code. The
+umbrella design already fixes the coupling between the two repositories: the
+manifest format and a command name in qtmaildir's config, with no submodule.
+A read-only subcommand answering a question about one message fits that
+contract; a daemon, a socket or a shared database does not, and the umbrella
+design rules out a database of this tool's own.
+
+**Constraints, and the real tension.** Deciding a message is spam by
+resemblance is a classifier, and this tool has so far been deliberately
+mechanical: it reports what a message declared, and refuses rather than
+guesses when the trust boundary is unset. A resemblance score is the first
+thing here that would be an opinion rather than an observation, and a wrong
+one either hides real mail or teaches the user to distrust the tag.
+
+There is also a quieter question about what a match is allowed to be based on.
+The obvious signals are the ones already in a manifest, a sending IP, a
+domain, a URL shape, an attachment hash. Those are safe. Matching on the
+message body would mean holding attacker-supplied text against new mail, and
+`source.eml` is unredacted, so anything built here must not become a route by
+which a stored recipient identifier reaches a comparison that is later
+reported or logged. Property 1 governs what may be published, and a tag is not
+a report, but the path from one to the other is short.
+
+**Before building.** Ask the author what "fits certain requisites" means to
+him concretely, since that phrase is doing all the work in the note, and
+whether he wants a judgement or only the facts, for instance a subcommand that
+answers "this IP appears in three kept cases" and leaves the tagging decision
+to qtmaildir. The second is much more in keeping with the rest of the tool.