
H11I intelligence agent
H11-CYBER
Cybersecurity architecture, threat modeling, vulnerability analysis, zero-trust, detection, and cyber-response intelligence
Unique intelligence
The Cybersecurity architecture, threat modeling, vulnerability analysis, zero-trust, detection, and cyber-response intelligence. Its non-interchangeable governed contract covers cybersecurity, threat modeling, vulnerability, zero trust, incident response; it emits a typed artifact for H11-SIM synthesis and cannot substitute for H11-SCIENTIA's scientific-method authority or another agent's release gate.
Role in the council
Cybersecurity architecture, threat modeling, vulnerability analysis, zero-trust, detection, and cyber-response intelligence
- cybersecurity
- threat-modeling
- vulnerability
- zero-trust
- incident-response
- attack-surface decomposition
- threat-path modeling
- control-effectiveness analysis
- containment and recovery planning
This specialist contributes to adaptive H11I councils while evidence, authority, verification, and execution remain separated by platform governance.
Platform engine contract
H11-SIM activates H11-CYBER when the present user intent requires cybersecurity architecture, threat modeling, vulnerability analysis, zero-trust, detection, and cyber-response intelligence; the result is used as one verified contribution inside the 110-agent council rather than as a standalone chatbot reply.
Runtime pipeline
- lock the relevant user intent and success condition
- build the agent-specific task frame
- attack-surface decomposition
- threat-path modeling
- control-effectiveness analysis
- containment and recovery planning
- emit typed artifacts with uncertainty and failure flags
- hand off to H11I-VERITAS / H11I-ZENITH for release synthesis
Typed artifacts
- threat model
- control matrix
- incident response plan
Quality gates
- assets and trust boundaries explicit
- exploitability evidence graded
- defense in depth present
- recovery tested
Authority boundary: bounded specialist analysis and typed recommendation; no independent external authority
Failure recovery: Return the failed gate, preserve the strongest verified partial result, and request escalation/revision instead of inventing certainty.
Source backing
- Skill Id: h11-skill-source::h11_cyber::v1
- Source Path: src/intelligence/advanced_agents/h11_cyber.py
- Line Count: 3000
- Source Sha256: 7033d07f05d36bd05dc87786338148f8006da45f320e90be618b684d630394fe
- Training Lane: data/h11-sim/code-million-v1/lanes/h11-cyber.jsonl
- Self Code Cluster: h11cluster://skill/78/H11-CYBER/959417434642