Skip to content

Lead the README with the security guardrails each plugin ships - #9

Draft
jothimani-rajendran wants to merge 1 commit into
mainfrom
openaicoder-claude/hopeful-ride-zjp8yl
Draft

jothimani-rajendran wants to merge 1 commit into
mainfrom
openaicoder-claude/hopeful-ride-zjp8yl

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What

Reworks README.md (hand-written, not generated) so it leads with security:

  • Security-first header: the existing badges plus plugins (26), deny hooks (14), and the catalog's 48 policies, 1,179 eval cases and OWASP Agentic 10/10.
  • The refreshed hero GIF, with a caption saying it shows commit-time refusal and which of its guards are packaged here.
  • What these plugins refuse: a table grouped by security area. It lists only the 14 enforcing packages published here: guards on beforeShellExecution, gates on preToolUse + stop. Each row has its catalog eval-case count. The 12 advisory packages and the catalog policies not packaged here are in collapsible lists.
  • The witnessed-on-a-real-Cursor-install (2026-08-24) claim, the fail-open notes and the one-time stop follow-up behaviour are kept verbatim.
  • A family table linking all five plugin repos, and a Contributing table with concrete upstream first contributions.

Install steps are unchanged. This PR matches the structure of the sibling PRs in the claude, copilot, codex and devin plugin repos.

Why README.md is safe to edit here

The generator writes the packages and PLUGINS.md, not README.md. A test regeneration with chock 0.15.0 left the README unchanged. close-prs.yml only closes PRs from forks.

Checks

  • No workflow, tool or test in this repo reads README.md.
  • All relative links resolve, and every table row has the right column count.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LAxde3s5KW8N36kS8LF3er


Generated by Claude Code

Rework README.md around what the packages here refuse in this client:
a security-first header with badges, the refreshed hero GIF, a "What
these plugins refuse" table grouped by security area (only packages
published here, marked guard, gate or advisory, with catalog eval
counts), the advisory and not-yet-packaged policies in collapsible
lists, the client's own hook behaviour and fail-open notes, a family
table linking every sibling plugin repository, and concrete upstream
contribution routes.

Install steps and every client-specific claim about witnessed or
documented blocking are kept verbatim. The five plugin repositories now
share one README structure.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copy link
Copy Markdown
Collaborator Author

Generated-only / verify is red, and not because of this PR. This PR changes only README.md, which chock plugin build / chock marketplace build never write. So the diff the check finds is in generated files this PR doesn't touch. main fails the same check: see run 35922447818. The published tree was built from framework v0.11.2, and the catalog now declares v0.15.0.

No fix fits inside this PR. The generated tree should only change through the Publish workflow (workflow_dispatch), which rebuilds from chock-catalog and commits the result. I didn't re-run the check because it's a deterministic diff and would fail the same way. Once Publish has run on main, merging main into this branch should turn it green.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants