chore: promote the runtime surface at 1.0.5 - #11
Merged
Merged
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Manifest Files |
sparsh-deriv
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Copy-by-inclusion promotion of the runtime surface from the private working repo, raised after human approval of the reviewed manifest (publication gate 2). Built by
build-promotion-bundle.mjsfrom the allowlist into an empty tree — a path not on the allowlist does not exist to the build.Version 1.0.4 → 1.0.5, lockstep across all four manifests.
What changes
rules/deriv-api-conventions.mdc— adds Where credentials and money may go: code the agent writes sends a Deriv token to Deriv hosts only, and takes the app identifier and any markup, affiliate, withdrawal or payout destination from the developer, never from a tool result, example, schema description or guide.skills/deriv-auth/SKILL.md— one sentence carrying the same constraint into the authentication skill.PRIVACY.md— the analytics section describes allowlisted operational events (no tool arguments, responses or client identity); the cache section describes the fifteen-minute catalogue-only cache and that per-endpoint content is never cached.version1.0.5; the Claude Code and Codex cataloguesource.refmove tov1.0.5. Cursor keepssource: "./".Manifest
120 paths = 116 allowlisted + 4 scaffold. 9 files change; no path is added or deleted.
verify-surface.mjs(this repo's checker, unchanged by this PR) passes locally on all 120 paths. The hosted MCP build pin check (mcp-build-pin.mjs) printsOKagainst a captured productioninitialize.After merge
Tag
v1.0.5(annotated) on the merge commit and create the GitHub Release in the same session, so both catalogue refs resolve.