Repository navigation
v0.1.0 — API, data and AI handoff boundary checks
First public release of BoundaryGuard, an Apache-2.0 CLI for repeatable API, response-data, and AI handoff checks.
Implemented:
- GET-only REST authorization cases planned and classified with Overstep 1.5.0.
- Per-identity positive controls and returned-object identity verification.
- JSON Schema contracts for successful and denied responses.
- Explicit text-file handoff boundaries, Gitleaks 8.30.1 scanning, and exact-byte ZIP bundles with SHA256 manifests.
- Secret-free reports, strict configuration, auth-only Overstep matrix export, and synthetic safe/leaky/expired demos.
Validation: 94 tests passed locally. Python 3.11 and 3.14 CI both passed tests, lint, and package builds. The built wheel passed its working demo outside the source checkout. Publication-source secret scan found zero matches.
CI: https://github.com/Chorolee/boundaryguard/actions/runs/37578945837
Scope: initial release; declared GET JSON endpoints and selected UTF-8 files only. No direct database/RLS proof, MCP runtime enforcement, complete PII detection, or production-service integration is claimed. Gitleaks is installed separately with the pinned-hash installer in the source distribution.
See README.md for setup and SECURITY.md for private vulnerability reporting.
Package registry note: the PyPI project named boundaryguard is unrelated to this repository. Install this release from the attached wheel or source distribution. The project is now PermitProbe; v0.1.1 contains the renamed package and CLI. PermitProbe 0.1.1 is published at https://pypi.org/project/permitprobe/0.1.1/.