You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 0d7f14d
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: mods/sec-default/.claude-plugin/plugin.json
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,7 @@
1
1
{
2
2
"name": "sec-default",
3
3
"version": "0.1.0",
4
-
"description": "Security default for organizations: seated outermost, it keeps the organization's classic hooks, prompt content, settings and tool policy out of reach of the plugins a person installs, and adds no policy of its own.",
4
+
"description": "Security default for organizations: seated outermost, it keeps the organization's classic hooks, prompt content, settings and tool policy out of reach of the plugins a person installs, and adds no policy of its own; one managed option, allowManagedModsOnly, limits mods to the organization's.",
Copy file name to clipboardExpand all lines: mods/sec-default/README.md
+60-8Lines changed: 60 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -10,11 +10,12 @@ plugin keeps exactly those out of the user tier's reach and adds no policy
10
10
of its own. Everything else passes through untouched.
11
11
12
12
It has three moves and nothing else: continue past the user tier
13
-
(`next.to(e, "append")`), refuse a user-tier caller by name (`{ deny }`
14
-
when `next.origin.tier` is `user`), or pass (`next(e)`). A subject's
15
-
provenance is the event's pinned `e.provider`; policy is read through
16
-
`$.settings.read({ source: "policy" })`, one read serving a burst; both
17
-
fail closed, so an unreadable policy counts as a policy in force.
13
+
(`next.to(e, "append")`), refuse a user-tier caller or module by name
14
+
(`{ deny }` when `next.origin.tier` is `user`, `{ refuse }` when a module's
15
+
pinned `e.tier` is), or pass (`next(e)`). A subject's provenance is the
16
+
event's pinned `e.provider`; policy is read through
17
+
`$.settings.read({ source: "policy" })`, one read serving a burst of tool
18
+
calls; both fail closed, so an unreadable policy counts as a policy in force.
18
19
19
20
`hooks/register.ts` is the module; `hooks/policy/` reads the managed
20
21
settings it decides by.
@@ -29,18 +30,69 @@ settings it decides by.
29
30
|`tool.describe`, `command.describe`, `agent.offer`, `agent.spawn`| When the subject's pinned `e.provider.tier` is `prepend` or `append` (a policy-installed plugin, the managed folder, a policy MCP server), continue past the user tier; a subject provided by `user`, `builtin` or `core` passes. |
30
31
|`tool.register`| A caller in `prepend` or `append` continues past the user tier. A `user`-tier caller is refused by name while managed settings hold `allowedMcpServers` (set at all, empty included); otherwise it passes. |
31
32
|`tool.list`| The tools of the organization's managed MCP servers are listed as the organization's tiers listed them; every other tool as the user tier left it. With no policy to read, or a refusal from either listing, the organization's listing stands whole. |
33
+
|`plugin.register`| A hooks module in the `user` tier (one a person installed, named with `--plugin-dir`, or keeps in their mods folder) is refused while managed settings set this plugin's `allowManagedModsOnly` option; otherwise it passes. Modules in `prepend`, `append` and `builtin` are never asked about. |
"description": "Security default: from the outermost seat, continues past the user tier on the organization's classic hooks, prompt content, settings and subjects, refuses a user-tier tool.register under an MCP allowlist, and restores the organization's tools in tool.list",
2
+
"description": "Security default: from the outermost seat, continues past the user tier on the organization's classic hooks, prompt content, settings and subjects, refuses a user-tier tool.register under an MCP allowlist, restores the organization's tools in tool.list, and refuses a user-tier hooks module at plugin.register while managed settings set its allowManagedModsOnly option",
0 commit comments