# AssetManager Analyzer Profiles AssetManager 0.5.5.90 separates installer-specific knowledge from the analyzer engine. The Python engine performs generic operations such as PE inspection, MSI metadata parsing, marker scanning, safe SFX extraction, embedded-installer selection and profile evaluation. Product/vendor knowledge is stored in declarative JSON profiles. ## Profile types Profiles use schema `assetmanager-analyzer-profile-v1` and profile API `1`. They can be installed from three sources: - `system`: shipped with AssetManager under `app/analyzer_profiles/system/`. - `community`: imported manually or installed from a configured community repository. - `local`: locally maintained profiles. Local profiles override profiles with the same ID. Imported profiles are stored in `/assetmanager-data/analyzer-profiles` and are included in AssetManager backups. Profiles are declarative data only and cannot contain executable Python code. ## Exchange format Profiles are exported as `.amprofile` files. The file is a ZIP container with: - `manifest.json`: bundle schema, profile ID/version/API and SHA-256 of `profile.json`. - `profile.json`: the validated declarative profile definition. The import validates paths, size, profile schema/API and SHA-256 before installing the profile. ## Community repository index A repository is an HTTPS-hosted JSON index. Configure it with: `ANALYZER_PROFILE_REPOSITORY_URL=https://example.org/assetmanager-profiles/index.json` Index format: ```json { "schema": "assetmanager-analyzer-profile-repository-v1", "name": "AssetManager Community Profiles", "profiles": [ { "id": "vendor.example-app", "name": "Example App", "version": "1.0.0", "url": "https://example.org/profiles/vendor.example-app.amprofile", "sha256": "" } ] } ``` The AssetManager administrator explicitly loads the catalog and chooses which profile to install. The bundle SHA-256 is verified when the repository provides one. ## Contributing profiles A public profile repository can be maintained independently from the AssetManager application repository. Contributors only need to submit declarative `.amprofile` bundles and index metadata; no AssetManager source-code change is required for ordinary vendor/installer rules. Use stable profile IDs. Increase the profile version when rules change. Avoid filename-only matching when stronger static evidence is available. Silent parameters should only be marked high-confidence when they are documented or clearly proven by installer metadata/static analysis.