Skip to content

Lead README with the security findings and supply-chain framing - #82

Draft
jothimani-rajendran wants to merge 2 commits into
mainfrom
openaicoder-claude/hopeful-ride-zjp8yl
Draft

jothimani-rajendran wants to merge 2 commits into
mainfrom
openaicoder-claude/hopeful-ride-zjp8yl

Conversation

@jothimani-rajendran

Copy link
Copy Markdown
Collaborator

What

README-only refresh. The README now opens with security: context-report as supply-chain trust for agent context, meaning a signed, re-derivable report of whether a plugin, hook, skill, AGENTS.md or MCP server actually works.

  • Header: a new tagline, plus a second row of brand badges for in-toto Statement/v1, Sigstore via actions/attest, 11 report rows and the v0.1 draft spec. All existing badges are kept.
  • "Why it matters": a table that pairs each measured finding with what it means for security:
    • 3 of 18 public plugins are reachable but not executable (exit 126).
    • Every hook that runs allows on malformed input, so it fails open.
    • Latency and context-token costs vary by two orders of magnitude.
    • No efficacy row reaches PASSED.
  • Signing: a paragraph taken from the spec's Envelope section covering DSSE, Sigstore, Fulcio, Rekor and gh attestation verify. It says producers SHOULD sign; it does not claim the CLI signs.
  • "What a report proves": a table covering all 11 rows. For each row it gives the question, why it matters for security, and its honest v0.1 producer status (measured, claimed or NotAvailable).
  • Family table: now has column headers. chock-catalog figures are updated to 48 policies (19 enforced-at-commit, 9 in-agent, 20 advisory), 1,179 eval cases and 1,019 replayed in CI. The generated family-*.svg figure still says 39; it was not touched because figures are script-generated.
  • Contribute: a table of the first contributions, each with the file it lives in.

The quickstart section is byte-identical, so docs/quickstart.sh does not drift. Every existing figure, number and caveat is kept.

Definition of done

  • python -m ruff check . and python -m ruff format --check . clean
  • python -m pytest -q green (407 passed, 1 skipped)
  • Schema changes: n/a
  • chock check and chock sync --repo . --check clean (pinned chock v0.9.0)

Also checked:

  • The quickstart.yml drift check matches.
  • The quickstart block runs in a fresh directory and ends with well-formed and bound: True.
  • The figures job regenerated all figures with no diff.

Claims

  • No row is described as re-derivable unless the reference producer measures it. Rows that are not measured are shown as NotAvailable, and efficacy is shown as claimed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01LAxde3s5KW8N36kS8LF3er


Generated by Claude Code

Open with the measured security findings (3 of 18 public plugins
reachable but not executable; every hook that runs allows on malformed
input, i.e. fails open; the cost spread) and position the report as a
signed in-toto / Sigstore attestation for agent context. Add badges, a
"what a report proves" row table, a labelled family table with current
catalog figures, and a contribution table. The quickstart block and
every existing figure and fact are kept unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>
Replace the "refuses the dangerous action" sentence in "Part of
open-coder-ai" with the application-security positioning: chock checks
the code agents write at the agent's hook where one exists, at commit
and in CI; context-report is the supply-chain evidence for the agent
context those guards ship as.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Claude <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants