Skip to content

Secure policy evaluation with repository MCP CLI and MetaHarness - #2

Merged
ruvnet merged 2 commits into
mainfrom
fix/required-field-existence
Sep 10, 2026
Merged

Secure policy evaluation with repository MCP CLI and MetaHarness#2
ruvnet merged 2 commits into
mainfrom
fix/required-field-existence

Conversation

@ruvnet

@ruvnet ruvnet commented Sep 10, 2026

Copy link
Copy Markdown
Owner

Implements the secure local increment tracked in #3. Missing fields fail closed across operators; regex, input bodies and provider calls are bounded. Requests use a constant time bearer check, closed CORS and independent analysis models. Local policy evaluation needs no provider.

Adds official SDK 2 CLI/MCP, generated MetaHarness maintainer/security/release/benchmark profiles with sessions and field memory adapter, pinned Autogenous hard gate, ADR, README header, usage and ecosystem links, and CI artifact delivery.

Validation: 20 Python regression/API tests; 3 real SDK stdio runtime tests; 7 generated profile tests; 6 Rust gate tests; build, doctor and benchmark schema validation pass. pip-audit and npm audit report zero advisories. Policy fixture p95 4.727 microseconds across 10000 evaluations. Production provider load, deployed field memory and membership remain operator configured. No SOTA claim or automatic promotion. See docs/validation.md and docs/ADR-002-secure-local-agent.md.

Acceptance: all checks on this exact PR head must pass before merge.

@ruvnet ruvnet changed the title Fix missing required fields passing existence checks Secure policy evaluation with repository MCP CLI and MetaHarness Sep 10, 2026
@ruvnet
ruvnet marked this pull request as ready for review September 10, 2026 23:29
@ruvnet
ruvnet merged commit 65df339 into main Sep 10, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant