docs: adopt the reviewed wordings for the restored scopes - #34
Merged
Conversation
Follow-up to the scope restoration, taking the source wordings rather than paraphrasing them: - "was not seen on the hostile side" for the .credentials import exemption, in access_control.go and in the two adversarial `why:` strings that share its shape. - The SD-007 deny-list entry keeps the defect and both grades without the worked payload: a reverse shell chained after an `echo` graded security A in a fenced block, D in a script. - "few enough not to move the entry above", which no longer points at figures this branch deleted. Two cosmetic: a 122-character comment rewrapped to its neighbours' width, and a changelog paragraph that wrapped mid-phrase. adversarial_test.go's URL-span string is deliberately untouched — it is addressed to whoever narrows that skip, and leaving it is what the AGENTS.md bullet was written to protect. Claude-Session: https://claude.ai/code/session_01XAY7LzfeuEZBgSLuzpWUAH
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A tail of #33 that missed the merge. Same rule, four small edits, no new ground.
#33 removed measurements and defeat recipes from comments and prose while keeping the reasoning that stops someone widening a deliberately narrow predicate. In eleven places its first pass had turned a bounded measurement into a universal claim — "0 malicious hits on the bench corpus" becoming "does not appear in hostile ones" — and those were re-bounded before merge. This adopts the reviewed wordings for four of them and fixes two paragraphs that reflowed badly.
pkg/rules/access_control.goadversarial_test.go(twowhy:strings)CHANGELOG.mdSD-007 entryechograded security A, while the identical line in arun.shgraded D"CHANGELOG.mdThe changelog one is the only edit with substance: the merged wording had blurred what the rule actually forgot, and this restores both the defect and the two grades that show it, without the worked payload that was removed in #33.
Also rewrapped two paragraphs that #33 left with orphan tails.
Verification
why:strings inadversarial_test.go. That field is read only as at.Errorfformat argument, so the change is behaviour-neutral by construction.go test ./...— 1085 tests, 12 packages, green.CHANGELOG.mdunchanged structurally againstmain: 13 version headings, 67 entry bullets, every grade-changing warning present.nc -ementions are the bare technique name in prose, which the rule's own entry has always named.https://claude.ai/code/session_01XAY7LzfeuEZBgSLuzpWUAH