Skip to content

Improve instructions and security - #5

Merged
diegoos merged 2 commits into
mainfrom
feat/improve-instructions
Jul 31, 2026
Merged

Improve instructions and security #5
diegoos merged 2 commits into
mainfrom
feat/improve-instructions

Conversation

@diegoos

@diegoos diegoos commented Jul 29, 2026

Copy link
Copy Markdown
Owner

No description provided.

diegoos added 2 commits July 28, 2026 14:08
- Added a new section in the CHANGELOG to document changes made to `instructions.md`, which has been streamlined for clarity and organization.
- Revised the `active-work/<branch>.md` description in `index.md` to enhance understanding of when to start or resume work.
- Expanded the `instructions.md` to include detailed permission boundaries and precedence for memory management, ensuring better guidance for users.
- Introduced `SECURITY.md` to document trust boundaries and intentional capabilities for hooks, emphasizing the importance of trusting project directories.
- Updated `CHANGELOG.md` to include security-related changes and improvements in the OpenCode plugin, including validation of session IDs and refusal of symlink hook scripts.
- Revised `README.md` to reference the new security document.
- Improved hook script validation in `hooks/opencode/safe-script.ts` to ensure safe execution and prevent symlink escapes.
- Added tests for hook script safety and binding ID validation in `tests/opencode-safe-script.test.ts`.
@diegoos
diegoos merged commit 3a8de1d into main Jul 31, 2026
5 checks passed
@diegoos
diegoos deleted the feat/improve-instructions branch July 31, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant