Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,12 @@ shadow knowledge bases for any codebase.

## Unreleased

### Fixed
- **Reconciliation path containment** — validate untrusted manifest destinations
and filesystem aliases before writing discoveries, cross-references, or
archives. Unsafe paths fail explicitly, including during dry runs, rather
than modifying files outside the shadow tree.

### Changed
- **More concise documentation** — consolidated README onboarding and workflow
guidance, with advanced operations linked to the skill references. Condensed
Expand Down
6 changes: 6 additions & 0 deletions RESPONSIBLE_AI.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,12 @@ them only while active or resumed work needs them. Hash verification detects
unexpected changes to the pinned bundle; it is not an attestation that arbitrary
third-party code is trustworthy.

Reconciliation treats remote manifest paths as untrusted and confines discovery,
back-pointer, archive, and metadata writes to the shadow tree. Unsafe paths and
outward-pointing symlinks stop reconciliation before publication. This does not
validate discovery truth, sandbox experiment code, or protect against concurrent
local filesystem tampering.

A detailed discussion of ShadowFrog, including how it was developed and tested, can be found in our [blog post](https://microsoft.github.io/debug-gym/blog/2026/06/shadow-frog/).

### Intended Uses
Expand Down
5 changes: 5 additions & 0 deletions skills/shadow-frog-dream/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -948,6 +948,11 @@ or manually imitate its branch-deletion steps.

### What the Reconciler Does

Manifest destinations are preflighted before any writes, including in dry runs.
Absolute/traversal paths and symlinks escaping `.shadow/` fail with a nonzero
exit. Repair the indicated manifest field or filesystem alias before retrying;
do not bypass containment checks.

1. **Discovers** new branches (namespace-filtered, not in `_index.md`)
2. **Reads/validates** manifests from remote branches
3. **Merges** discoveries into main's per-file shadows (semantic dedup; on an exact-text duplicate it upgrades the existing entry's metadata — unions labels, raises source trust, promotes `uncertain`→`verified` — but never alters a `refuted` status)
Expand Down
Loading
Loading