docs: v4.4.2 documentation hardening pass + scanner-verdict README badges#211
Open
msaleme wants to merge 1 commit into
Open
docs: v4.4.2 documentation hardening pass + scanner-verdict README badges#211msaleme wants to merge 1 commit into
msaleme wants to merge 1 commit into
Conversation
Reframed GTG-1002 capability table in docs/ADVANCED.md for unambiguous defensive intent: column headers from "Real GTG-1002 Activity" / "What We Test" to "Adversary behavior we probe for" / "Detection probes the harness sends"; cell content reworded from active to defensive voice. Added top-of-section defensive framing paragraph and reading guide above the table. Anchored both CVE-2026-25253 references in docs/TEST-INVENTORY.md with inline NVD links. No code changes; no test changes; test count unchanged at 470 across 32 modules. ClawHub bundle republished as v4.4.2; pyproject.toml remains v4.4.0 until next code-change release. Counterpart memory entry: playbook_security_skill_scanner_hardening.md Pattern 5 (bundled-docs adversary-vs-defender table reframing). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docs/ADVANCED.mdGTG-1002 capability table for unambiguous defensive intent; anchorsdocs/TEST-INVENTORY.mdCVE-2026-25253 references with NVD linksWhy now
Anthropic confirmed the MCP RCE is by-design on 2026-04-30. The harness's MCP-015/016/017/018 tests shipped April 12 (v4.2.0). The doc hardening pass + the dev.to longform When a protocol vendor declines to patch, the test harness becomes the spec compound on the three-power leverage: counter-positioning + branding + process power. Public CHANGELOG entry on
mainanchors the timestamp claim.Test plan
scripts/count_tests.pysource of truth)🤖 Generated with Claude Code
Note
Low Risk
Documentation-only changes that reword security content and add references; no code, behavior, or test coverage changes.
Overview
Adds a
4.4.2changelog entry describing a documentation hardening release with no code or test changes.Reframes
docs/ADVANCED.mdGTG-1002 capability content to explicitly describe defensive probes (new framing paragraph + reading guide, and table headers/cells rewritten in defensive voice). Updatesdocs/TEST-INVENTORY.mdto link bothCVE-2026-25253mentions directly to the NVD entry.Reviewed by Cursor Bugbot for commit 17c5126. Bugbot is set up for automated code reviews on this repo. Configure here.