Architecture
SERV compiler
How advisory prose becomes a typed checklist through a strict JSON schema.
compileAdvisory() in src/lib/serv.ts calls SERV Reasoning’s OpenAI-compatible chat completions API at https://inference-api.openserv.ai/v1 with model gpt-5.4-mini (override with SERV_MODEL).
Strict JSON schema
The response must match the pich_checklist schema in strict mode. The checklist has these fields:
ts
interface Checklist {
advisory_id: string;
title: string;
package: string;
affected_ranges: { range: string; source_quote: string }[];
fixed_versions: string[];
predicates: { id: PredicateId; expected: "present" | "absent"; rationale: string; source_quote: string }[];
unexpressible_conditions: { condition: string; kind: "required_condition" | "mitigation"; source_quote: string }[];
deployment_assumptions: string[];
required_evidence: string[];
recommended_response: string;
}Prompt rules
- Only the 8 predicate ids in the vocabulary may be used.
- Every
source_quotemust be copied character for character from the advisory. - A platform the advisory calls protected becomes
expected: "absent". - Attacker actions, such as sending a crafted header, are never app conditions.
- Conditions the vocabulary cannot express go to
unexpressible_conditions, marked required or mitigation.
Requests also attach SERV’s serv_shadow_agent tool with a hint restating the quote and vocabulary rules. Set SERV_SHADOW_AGENT=0 to leave it off. The client times out after 90 seconds and retries once.