Skip to content

feat(security): Complete Phase 8 security audit; document findings an… - #4

Merged
therecluse26 merged 1 commit into
mainfrom
feature/security-audit
Jan 8, 2026
Merged

feat(security): Complete Phase 8 security audit; document findings an…#4
therecluse26 merged 1 commit into
mainfrom
feature/security-audit

Conversation

@therecluse26

Copy link
Copy Markdown
Collaborator

…d apply critical fixes

@therecluse26
therecluse26 merged commit 31dd4ff into main Jan 8, 2026
1 of 9 checks passed
therecluse26 added a commit that referenced this pull request Jul 18, 2026
…low-ddl content (REF-284)

- CLAUDE.md: rename Core Principle #4 to "Strict read-only enforcement";
  replace "writes require capabilities" with unconditional rejection wording;
  fix CLI Surface and MySQL-Specific Constraints to match
- ARCHITECTURE.md: replace fictional Capability Hierarchy + three-tier
  capability check flow with accurate Read-Only Enforcement section;
  remove allow_write/allow_ddl from Capabilities struct example and
  CLI vs MCP comparison; fix Overview, Core Principles, Security Model,
  Error Codes table, and Design Rationale sections; rename ToC entry
- README.md: replace stale "DDL statements require --allow-ddl flag"
  error example with actual CAPABILITY_VIOLATION message; fix
  Architecture security model bullet

Co-Authored-By: Paperclip <noreply@paperclip.ing>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant