Skip to content

Commit 2add48d

Browse files
committed
Add proof-of-work outcomes and skills
1 parent 6b30cae commit 2add48d

9 files changed

Lines changed: 213 additions & 9 deletions

File tree

‎ops/mission-report.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
Generated by `python3 scripts/mission_control.py generate`.
44

5-
Generated at UTC: `2026-05-31T20:04:45Z`
5+
Generated at UTC: `2026-06-03T14:14:37Z`
66

77
## Recent Work
88

‎ops/outcomes.md‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ This file is generated from public sent logs only. It never posts outreach and d
88

99
| Metric | Value |
1010
| --- | ---: |
11-
| Generated at UTC | 2026-05-31T20:04:45Z |
11+
| Generated at UTC | 2026-06-03T14:14:37Z |
1212
| Tracked outbound artifacts | 10 |
1313
| Pull requests tracked | 6 |
1414
| Issue comments tracked | 4 |
@@ -20,12 +20,12 @@ This file is generated from public sent logs only. It never posts outreach and d
2020
| Kind | Source | URL | Thread | State | Merged | Issue Comments | Review Comments | Last Updated | Notes |
2121
| --- | --- | --- | --- | --- | --- | ---: | ---: | --- | --- |
2222
| issue_comment | leads/sent/2026-05-24-github-outreach-001.md | https://github.com/Forgia-Labs/forgia/issues/17#issuecomment-4527520156 | https://github.com/Forgia-Labs/forgia/issues/17 | OPEN | - | 2 | - | 2026-05-24T05:41:00Z | parent issue state only |
23-
| issue_comment | leads/sent/2026-05-24-github-outreach-001.md | https://github.com/open-gsd/get-shit-done-redux/issues/52#issuecomment-4527520911 | https://github.com/open-gsd/get-shit-done-redux/issues/52 | OPEN | - | 4 | - | 2026-05-26T21:03:34Z | parent issue state only |
23+
| issue_comment | leads/sent/2026-05-24-github-outreach-001.md | https://github.com/open-gsd/get-shit-done-redux/issues/52#issuecomment-4527520911 | https://github.com/open-gsd/get-shit-done-redux/issues/52 | OPEN | - | 5 | - | 2026-06-01T21:28:46Z | parent issue state only |
2424
| issue_comment | leads/sent/2026-05-24-github-outreach-001.md | https://github.com/vibecoder10/economy-fastforward/issues/448#issuecomment-4527521811 | https://github.com/vibecoder10/economy-fastforward/issues/448 | OPEN | - | 1 | - | 2026-05-24T05:42:01Z | parent issue state only |
2525
| issue_comment | leads/sent/2026-05-24-github-outreach-002.md | https://github.com/mailpile/python-passcrow/issues/16#issuecomment-4527551073 | https://github.com/mailpile/python-passcrow/issues/16 | OPEN | - | 1 | - | 2026-05-24T05:59:31Z | parent issue state only |
26-
| pull_request | leads/sent/2026-05-24-github-outreach-002.md | https://github.com/RoshanDavis/whisper/pull/9 | https://github.com/RoshanDavis/whisper/pull/9 | OPEN | False | 2 | 0 | 2026-05-24T06:01:09Z | - |
26+
| pull_request | leads/sent/2026-05-24-github-outreach-002.md | https://github.com/RoshanDavis/whisper/pull/9 | https://github.com/RoshanDavis/whisper/pull/9 | MERGED | True | 3 | 0 | 2026-06-01T21:51:00Z | - |
2727
| pull_request | leads/sent/2026-05-24-github-outreach-002.md | https://github.com/ag-tech-group/hera-streamer-invitational-2026-web/pull/75 | https://github.com/ag-tech-group/hera-streamer-invitational-2026-web/pull/75 | MERGED | True | 1 | 0 | 2026-05-27T10:50:23Z | - |
28-
| pull_request | leads/sent/2026-05-24-github-outreach-003.md | https://github.com/inkognitroz/inkognitroz.github.io/pull/167 | https://github.com/inkognitroz/inkognitroz.github.io/pull/167 | OPEN | False | 0 | 0 | 2026-05-31T15:19:55Z | - |
28+
| pull_request | leads/sent/2026-05-24-github-outreach-003.md | https://github.com/inkognitroz/inkognitroz.github.io/pull/167 | https://github.com/inkognitroz/inkognitroz.github.io/pull/167 | CLOSED | False | 1 | 0 | 2026-06-03T09:57:34Z | - |
2929
| pull_request | leads/sent/2026-05-25-github-outreach-004.md | https://github.com/lettucebo/CostcoTwPriceMatch/pull/46 | https://github.com/lettucebo/CostcoTwPriceMatch/pull/46 | OPEN | False | 0 | 0 | 2026-05-25T00:44:32Z | - |
3030
| pull_request | leads/sent/2026-05-25-github-outreach-005.md | https://github.com/Sayap-Garuda-Indah/inventory/pull/45 | https://github.com/Sayap-Garuda-Indah/inventory/pull/45 | OPEN | False | 0 | 0 | 2026-05-25T14:22:33Z | - |
31-
| pull_request | leads/sent/2026-06-01-github-outreach-006.md | https://github.com/langgenius/dify/pull/36873 | https://github.com/langgenius/dify/pull/36873 | OPEN | False | 0 | 0 | 2026-05-31T20:04:25Z | - |
31+
| pull_request | leads/sent/2026-06-01-github-outreach-006.md | https://github.com/langgenius/dify/pull/36873 | https://github.com/langgenius/dify/pull/36873 | MERGED | True | 0 | 1 | 2026-06-01T01:58:32Z | - |

‎ops/scoreboard.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ Generated by `python3 scripts/mission_control.py generate`.
66

77
| Metric | Value |
88
| --- | ---: |
9-
| Generated at UTC | 2026-05-31T20:04:45Z |
9+
| Generated at UTC | 2026-06-03T14:14:37Z |
1010
| Sent log files | 6 |
1111
| GitHub PRs opened | 6 |
1212
| GitHub issue comments sent | 4 |

‎scripts/validate_repo.py‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,8 @@
6969
"memory/operating-notes.md",
7070
"skills/pipeline/README.md",
7171
"skills/pipeline/public-safe-booking-funnel.md",
72+
"skills/pipeline/public-security-policy-pr.md",
73+
"skills/pipeline/webcrypto-session-key-hardening.md",
7274
".github/workflows/validate.yml",
7375
".github/workflows/pages.yml",
7476
".github/ISSUE_TEMPLATE/audit-fit-check.yml",

‎site/index.html‎

Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,35 @@ <h2 id="signal-title">The failure pattern is getting clearer: fast demos, weak t
7878
</div>
7979
</section>
8080

81+
<section class="section proof-work" aria-labelledby="proof-title">
82+
<div class="section-heading">
83+
<p class="eyebrow">Proof of work</p>
84+
<h2 id="proof-title">Merged open-source contributions, not slideware.</h2>
85+
<p>
86+
FreeCodex contributes practical security and readiness fixes through normal
87+
open-source review. These public PRs show the work pattern without implying
88+
affiliation, endorsement, certification, or paid customer status.
89+
</p>
90+
</div>
91+
<div class="proof-grid" aria-label="Merged public proof-of-work PRs">
92+
<article class="proof-item">
93+
<h3>Dify</h3>
94+
<p>Added a <code>SECURITY.md</code> disclosure path to a large public AI-agent repository.</p>
95+
<a class="text-link" href="https://github.com/langgenius/dify/pull/36873">Merged PR #36873</a>
96+
</article>
97+
<article class="proof-item">
98+
<h3>Whisper</h3>
99+
<p>Updated session WebCrypto key handling so operational keys are non-extractable.</p>
100+
<a class="text-link" href="https://github.com/RoshanDavis/whisper/pull/9">Merged PR #9</a>
101+
</article>
102+
<article class="proof-item">
103+
<h3>Hera</h3>
104+
<p>Delivered a small public safety/readiness fix for an event web project.</p>
105+
<a class="text-link" href="https://github.com/ag-tech-group/hera-streamer-invitational-2026-web/pull/75">Merged PR #75</a>
106+
</article>
107+
</div>
108+
</section>
109+
81110
<section class="section" id="scope" aria-labelledby="scope-title">
82111
<div class="section-heading">
83112
<p class="eyebrow">What gets checked</p>

‎site/styles.css‎

Lines changed: 29 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -260,7 +260,8 @@ h3 {
260260
}
261261

262262
.feature-grid,
263-
.price-grid {
263+
.price-grid,
264+
.proof-grid {
264265
display: grid;
265266
gap: 16px;
266267
}
@@ -443,6 +444,30 @@ h3 {
443444
grid-template-columns: repeat(3, 1fr);
444445
}
445446

447+
.proof-grid {
448+
grid-template-columns: repeat(3, 1fr);
449+
}
450+
451+
.proof-work .section-heading p:last-child,
452+
.proof-item p {
453+
color: var(--muted);
454+
line-height: 1.65;
455+
}
456+
457+
.proof-item {
458+
min-height: 188px;
459+
padding: 22px;
460+
background: var(--surface);
461+
border: 1px solid var(--line);
462+
border-radius: var(--radius);
463+
box-shadow: 0 12px 32px rgba(15, 36, 51, 0.08);
464+
}
465+
466+
.proof-item code {
467+
font-family: "SFMono-Regular", Consolas, "Liberation Mono", monospace;
468+
font-size: 0.9em;
469+
}
470+
446471
.price {
447472
padding: 24px;
448473
}
@@ -518,6 +543,7 @@ h3 {
518543
.feature-grid,
519544
.signal-list,
520545
.price-grid,
546+
.proof-grid,
521547
.split-section,
522548
.request {
523549
grid-template-columns: 1fr 1fr;
@@ -593,7 +619,8 @@ h3 {
593619

594620
.feature-grid,
595621
.signal-list,
596-
.price-grid {
622+
.price-grid,
623+
.proof-grid {
597624
grid-template-columns: 1fr;
598625
}
599626

‎skills/pipeline/README.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,3 +30,5 @@ A workflow becomes a skill when it has:
3030
- Outreach log to scoreboard synthesis.
3131
- Static security headers audit: `skills/pipeline/static-security-headers-audit.md`.
3232
- Public-safe booking funnel: `skills/pipeline/public-safe-booking-funnel.md`.
33+
- Public security policy PR: `skills/pipeline/public-security-policy-pr.md`.
34+
- WebCrypto session key hardening: `skills/pipeline/webcrypto-session-key-hardening.md`.
Lines changed: 69 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,69 @@
1+
# Public Security Policy PR
2+
3+
Status: candidate
4+
5+
Use this workflow when a large public repository has no visible `SECURITY.md`, but already has or can safely use a private vulnerability reporting channel such as GitHub Security Advisories.
6+
7+
## Trigger
8+
9+
Good fits:
10+
11+
- a public issue explicitly asks for a missing security policy
12+
- GitHub metadata shows no enabled security policy
13+
- the repository already exposes a private advisory/contact path
14+
- the change can be documentation-only and bounded
15+
16+
Do not use this to disclose vulnerability details, request private access, or invent a security response process for maintainers.
17+
18+
## Inputs
19+
20+
- Public repository URL.
21+
- Public issue requesting a security policy, if present.
22+
- Existing private vulnerability reporting path.
23+
- Repository default branch and documentation conventions.
24+
25+
Never include credentials, private reports, exploit details, or confidential vulnerability material.
26+
27+
## Workflow
28+
29+
1. Confirm neither `SECURITY.md` nor `.github/SECURITY.md` exists.
30+
2. Confirm the repository's private vulnerability reporting path from public metadata or docs.
31+
3. Add a concise `SECURITY.md` that points reporters to the private channel.
32+
4. Warn reporters not to disclose vulnerabilities in public issues, discussions, or pull requests.
33+
5. Keep scope to reporting guidance, disclosure etiquette, and update guidance.
34+
6. Avoid unsupported claims about SLAs, bounties, supported versions, or guaranteed security response.
35+
7. Open a small PR that references the source issue and states that no sensitive details are included.
36+
37+
## Validation
38+
39+
```bash
40+
git diff --check
41+
gh api repos/OWNER/REPO/contents/SECURITY.md
42+
gh api repos/OWNER/REPO/contents/.github/SECURITY.md
43+
gh repo view OWNER/REPO --json isSecurityPolicyEnabled,contactLinks
44+
```
45+
46+
Expected checks:
47+
48+
- existing policy paths return 404 before the PR
49+
- private reporting channel is verified from public metadata
50+
- PR body contains no payment link, credentials, private data, or vulnerability details
51+
- docs-only diff is small enough for maintainer review
52+
53+
## Failure Modes
54+
55+
Stop or revise when:
56+
57+
- no official private reporting channel is visible
58+
- a policy already exists in the repo or shared org `.github` repository
59+
- the proposed text claims unsupported SLA, bounty, or version support
60+
- the PR would expose vulnerability details or encourage public disclosure
61+
- the repository asks security reports to use a different official channel
62+
63+
## Evidence
64+
65+
This candidate is based on a merged documentation PR in `langgenius/dify`:
66+
67+
- Source issue: https://github.com/langgenius/dify/issues/36692
68+
- Merged PR: https://github.com/langgenius/dify/pull/36873
69+
- Result: maintainer approved and merged the bounded `SECURITY.md` addition.
Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
# WebCrypto Session Key Hardening
2+
3+
Status: candidate
4+
5+
Use this workflow when a public issue asks for session-only WebCrypto keys to be non-extractable, and the relevant key import or derivation paths are visible in public client code.
6+
7+
## Trigger
8+
9+
Good fits:
10+
11+
- an issue explicitly identifies `extractable: true` on session-only keys
12+
- ECDH, ECDSA, AES-GCM, or shared-secret paths are easy to isolate
13+
- registration, backup, or explicit export paths can be kept unchanged
14+
- the fix is a narrow boolean change with clear build validation
15+
16+
Do not use this as a general cryptography redesign or certified security guarantee.
17+
18+
## Inputs
19+
20+
- Public issue describing the key extractability concern.
21+
- WebCrypto import, unwrap, derive, and export call sites.
22+
- Build/test commands from the target repository.
23+
- Any documented key lifecycle or registration flow.
24+
25+
Never request private keys, credentials, account access, production secrets, or real user data.
26+
27+
## Workflow
28+
29+
1. Map each WebCrypto key call site to its lifecycle role.
30+
2. Separate session-only operational keys from registration, backup, export, or wrapping flows.
31+
3. Set session-only imported or derived keys to `extractable: false`.
32+
4. Leave legitimate export paths unchanged unless the issue explicitly covers them.
33+
5. Keep the diff minimal and avoid unrelated crypto refactors.
34+
6. Run the target build/test command.
35+
7. Report unrelated pre-existing failures separately instead of hiding them.
36+
37+
## Validation
38+
39+
Target repo checks should include at least:
40+
41+
```bash
42+
npm run build
43+
git diff --check
44+
```
45+
46+
When available, also run focused tests for:
47+
48+
- key import
49+
- key derivation
50+
- message encryption/decryption
51+
- registration or key export flows that must stay functional
52+
53+
Expected review notes:
54+
55+
- identify which call sites were changed
56+
- state which export/registration paths were intentionally not changed
57+
- avoid claiming the app is secure because of this single hardening step
58+
59+
## Failure Modes
60+
61+
Stop or revise when:
62+
63+
- a key must be exportable for a documented product flow
64+
- the app serializes or backs up the same key later in the lifecycle
65+
- the change breaks registration, recovery, migration, or wrapped-key storage
66+
- validation requires private credentials or production data
67+
- the issue requires broader cryptographic design review beyond a bounded PR
68+
69+
## Evidence
70+
71+
This candidate is based on a merged public WebCrypto hardening PR:
72+
73+
- Source issue: https://github.com/RoshanDavis/whisper/issues/8
74+
- Merged PR: https://github.com/RoshanDavis/whisper/pull/9
75+
- Result: maintainer merged the scoped `extractable: false` session-key change.

0 commit comments

Comments
 (0)