Releases: Latestinssan/RTQ
Release list
v0.1.1
RTQ Release v0.1.1 — Updated READMEs, npm keywords, and mobile enhancements
RTQ continues its zero‑third‑party‑dependency approach, now with fully‑documented READMEs and curated npm keywords for every @rtq/* package. The mobile package has been renamed to Rtq, now includes native OS screen‑lock (Android biometric verification with device‑credential fallback, iOS Face/Touch ID support), and ships a placeholder unsigned .ipa asset.
📦 Published npm Monorepo Packages (@rtq/* v0.1.1)
| Package | Version | Link | Role |
|---|---|---|---|
@rtq/security |
0.1.1 | npm | Unified pipeline façade (createRTQ) |
@rtq/cli |
0.1.1 | npm | Security CLI (capabilities, policy, sandbox, audit) |
@rtq/mcp |
0.1.1 | npm | Business‑grade MCP gateway |
@rtq/core |
0.1.1 | npm | Capability registry, ticket store, schema validation |
@rtq/crypto |
0.1.1 | npm | Canonical JSON, SHA‑256, Ed25519 signing |
@rtq/sandbox |
0.1.1 | npm | macOS Seatbelt, Linux bubblewrap, Windows AppContainer |
@rtq/approval |
0.1.1 | npm | QR‑based approval strategies |
@rtq/mobile |
0.1.1 | npm | Rtq – mobile approval host transport & pairing server |
@rtq/risk |
0.1.1 | npm | Authoritative risk engine (raise‑only) |
@rtq/policy |
0.1.1 | npm | Declarative default‑deny rule evaluator |
@rtq/clarification |
0.1.1 | npm | Ambiguity resolution |
@rtq/audit |
0.1.1 | npm | Structured, redacted audit logging |
📱 Mobile Package Enhancements (Rtq)
- Renamed to Rtq (README header updated,
APP_NAME = "Rtq"). - Native OS screen‑lock:
- Android: uses
react-native-biometricswithBiometricPromptand falls back toDEVICE_CREDENTIAL(PIN/pattern/password). - iOS: supports Face ID / Touch ID via the same library.
- Added
ensureBiometricAuth()helper (src/biometric.ts) andSimulatedDevice.approveWithBiometric()method that requires successful biometric verification before signing an approval.
- Android: uses
- Placeholder unsigned
.ipaadded to the package (included infiles).
🚀 Quick Start
npm install @rtq/security # core runtime
# or install the CLI globally
npm install -g @rtq/cliimport { createRTQ } from "@rtq/security";
const rtq = createRTQ({ signingKey: process.env.RTQ_SIGNING_KEY! });
// ...register capabilities, policies, authorize, executeFor mobile approval with biometric verification:
import { createMobileApprovalServer, SimulatedDevice } from "@rtq/mobile";
const server = await createMobileApprovalServer({ /* … */ });
const device = new SimulatedDevice({ name: "my‑device", keyPair: myKeyPair, pinnedHostPublicKey: hostPubKey });
await device.approveWithBiometric(challengePayload);🔬 Verification
- All 12 packages pass the CI suite (
npm run ci). - New biometric flow is covered by unit tests (
tests/mobile/biometric.test.ts).
💡 Why RTQ Was Created
While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS‑level sandboxing, capability scoping, fine‑grained permission gating, and challenge‑response authorization from scratch. RTQ was created to solve this problem for developers everywhere — packaging a security‑focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ enables developers to integrate capability security, OS‑enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge‑response approvals into their applications without having to build security infrastructure from scratch.
v0.1.0
RTQ Release v0.1.0 — Risk-Adaptive Capability Security Runtime
RTQ is a security-focused capability-security runtime for Node.js, TypeScript, Model Context Protocol (MCP) servers, and mobile approval hosts. Security-critical packages declare zero third-party npm runtime dependencies. It turns "can this agent/tool do this?" into an evidence-backed security pipeline:
Command → Capability (registered) → Risk (authoritative) → Policy (default-deny)
→ Clarification (missing critical params) → Approval (human/device)
→ Authorization Ticket (signed, single-use, bound) → Execution (OS-sandboxed)
→ Audit (structured, redacted)
📥 Downloads & Assets
📱 Android Mobile Approval App
- File:
app-release.apk(62.24 MB) - Direct Download: Download app-release.apk
- Downloads Tracker:
- Features: Scans QR challenges generated by RTQ, performs local Ed25519 signing using device platform secure storage, zero-PIN transmission over untrusted transport. Built with Flutter 3.11+ / Dart 3.11+ targeting Android 12+ (Java 17).
📦 Published npm Monorepo Packages (@rtq/* v0.1.0)
All 12 packages are published and live on the npm registry:
| Package | Version | Link | Role |
|---|---|---|---|
@rtq/security |
0.1.0 |
npm package | Main unified pipeline façade (createRTQ) |
@rtq/cli |
0.1.0 |
npm package | Security CLI (capabilities, policy check, sandbox test, verify) |
@rtq/mcp |
0.1.0 |
npm package | Business-Grade MCP integration gateway |
@rtq/core |
0.1.0 |
npm package | Capability registry, ticket store & schema validation |
@rtq/crypto |
0.1.0 |
npm package | Canonical JSON, HMAC-SHA256, nonces, constant-time compare |
@rtq/sandbox |
0.1.0 |
npm package | macOS Seatbelt, Linux bubblewrap, Windows AppContainer wrappers |
@rtq/approval |
0.1.0 |
npm package | Approval strategies & QR/mobile challenge-response protocol |
@rtq/mobile |
0.1.0 |
npm package | Mobile approval host transport and pairing server |
@rtq/risk |
0.1.0 |
npm package | Authoritative risk engine (caller claims can never downgrade) |
@rtq/policy |
0.1.0 |
npm package | Declarative default-deny rule evaluator |
@rtq/clarification |
0.1.0 |
npm package | Ambiguity resolution & structured security parameter questions |
@rtq/audit |
0.1.0 |
npm package | Structured, redacted security event logger |
🚀 Quick Start
Installation
# Install core security runtime
npm install @rtq/security
# Or install the CLI globally
npm install -g @rtq/cliUsage Example
import { createRTQ } from "@rtq/security";
const rtq = createRTQ({ signingKey: process.env.RTQ_SIGNING_KEY! });
rtq.registerCapability({
name: "files.read",
version: 1,
description: "Read a file inside the workspace",
inputSchema: { type: "object", properties: { path: { type: "string" } }, required: ["path"] },
risk: { base: "low" },
execute: async (ctx, input) => ({ ok: true, data: { path: input.path } }),
});
rtq.registerPolicy({ kind: "allow", capability: "files.read", reason: "Workspace reads" });
const auth = await rtq.authorize({ capability: "files.read", version: 1, input: { path: "/workspace/report.md" } });
if (auth.decision === "allowed") {
const outcome = await rtq.execute(auth.ticketId);
console.log("Result:", outcome.result);
}🔬 System Capabilities & Verification
- Verified in CI: 12 automated security invariants (INV-01 through INV-12), 430+ unit/contract/security tests passing, multi-OS platform sandbox enforcement tests (macOS, Linux, Windows), cross-language Node vs Dart protocol vectors.
- Process-Local Ticket Store: Ticket single-use redemption is currently managed in process-local memory. Distributed multi-node replay protection requires a shared ticket store backend.
- Platform Cryptographic Storage: Mobile Ed25519 keypairs use platform secure storage (
flutter_secure_storageutilizing Android Keystore / iOS Keychain where supported). - Host Trusted Computing Base (TCB): RTQ governs authorization, ticket validation, and process sandboxing; handler internal logic remains part of the host application TCB.
💡 Why RTQ Was Created
While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS-level sandboxing, capability scoping, fine-grained permission gating, and challenge-response authorization from scratch. RTQ was created to solve this problem for developers everywhere — packaging a security-focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ enables developers to integrate capability security, OS-enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge-response approvals into their applications without having to build security infrastructure from scratch.