Skip to content

docs: reviewer on-ramp (REVIEWING.md), SECURITY.md, audit-status note - #52

Merged
cuihtlauac merged 1 commit into
mainfrom
security-review-onramp
Sep 22, 2026
Merged

cuihtlauac merged 1 commit into
mainfrom
security-review-onramp

Conversation

@cuihtlauac

Copy link
Copy Markdown
Member

Makes hostile security review cheap and gives findings a place to land. Framed around the falsifiable invariant rather than 'please review my project'.

  • REVIEWING.md — one invariant; 7 falsifiable claims (C1–C7) each with the file to attack; trust boundary as exact functions (handle_connection + gate chain, ValidatedRequest::validate, classify_key/prompt_tty, exec_*); a 'where we have NO assurance' section (TUI rendering layer first); container one-liner.
  • SECURITY.md — GitHub private vulnerability reporting (now enabled) + @cuihtlauac, best-effort response, scope/out-of-scope, not-yet-audited status.
  • README — visible '⚠️ Not yet independently audited' note linking both.

Decisions applied: note-only (keep distributing), private vuln reporting enabled, best-effort GitHub-handle contact, no outreach text yet.

Please edit for voice/accuracy before merging — these are public security claims.

🤖 Generated with Claude Code

Make hostile security review cheap and give findings somewhere to land.

- REVIEWING.md: the one invariant, 7 falsifiable claims (C1–C7) each pointing
  at the file to attack, the trust boundary as exact functions (handle_connection
  + its gate chain, ValidatedRequest::validate, classify_key/prompt_tty, exec_*),
  a "where we have NO assurance" section led by the TUI rendering layer, and a
  container one-liner.
- SECURITY.md: private-vulnerability-reporting channel + maintainer contact,
  best-effort response, scope/out-of-scope, not-yet-audited status.
- README: visible "not yet independently audited" note linking both.

GitHub private vulnerability reporting has been enabled on the repo.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@cuihtlauac
cuihtlauac merged commit 2506b4f into main Sep 22, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant