Skip to content

Releases: Latestinssan/RTQ

Release list

v0.1.1

Choose a tag to compare

@Latestinssan Latestinssan released this 22 Sep 16:04

RTQ Release v0.1.1 — Updated READMEs, npm keywords, and mobile enhancements

GitHub All Releases
npm version
License

RTQ continues its zero‑third‑party‑dependency approach, now with fully‑documented READMEs and curated npm keywords for every @rtq/* package. The mobile package has been renamed to Rtq, now includes native OS screen‑lock (Android biometric verification with device‑credential fallback, iOS Face/Touch ID support), and ships a placeholder unsigned .ipa asset.


📦 Published npm Monorepo Packages (@rtq/* v0.1.1)

Package Version Link Role
@rtq/security 0.1.1 npm Unified pipeline façade (createRTQ)
@rtq/cli 0.1.1 npm Security CLI (capabilities, policy, sandbox, audit)
@rtq/mcp 0.1.1 npm Business‑grade MCP gateway
@rtq/core 0.1.1 npm Capability registry, ticket store, schema validation
@rtq/crypto 0.1.1 npm Canonical JSON, SHA‑256, Ed25519 signing
@rtq/sandbox 0.1.1 npm macOS Seatbelt, Linux bubblewrap, Windows AppContainer
@rtq/approval 0.1.1 npm QR‑based approval strategies
@rtq/mobile 0.1.1 npm Rtq – mobile approval host transport & pairing server
@rtq/risk 0.1.1 npm Authoritative risk engine (raise‑only)
@rtq/policy 0.1.1 npm Declarative default‑deny rule evaluator
@rtq/clarification 0.1.1 npm Ambiguity resolution
@rtq/audit 0.1.1 npm Structured, redacted audit logging

📱 Mobile Package Enhancements (Rtq)

  • Renamed to Rtq (README header updated, APP_NAME = "Rtq").
  • Native OS screen‑lock:
    • Android: uses react-native-biometrics with BiometricPrompt and falls back to DEVICE_CREDENTIAL (PIN/pattern/password).
    • iOS: supports Face ID / Touch ID via the same library.
    • Added ensureBiometricAuth() helper (src/biometric.ts) and SimulatedDevice.approveWithBiometric() method that requires successful biometric verification before signing an approval.
  • Placeholder unsigned .ipa added to the package (included in files).

🚀 Quick Start

npm install @rtq/security   # core runtime
# or install the CLI globally
npm install -g @rtq/cli
import { createRTQ } from "@rtq/security";
const rtq = createRTQ({ signingKey: process.env.RTQ_SIGNING_KEY! });
// ...register capabilities, policies, authorize, execute

For mobile approval with biometric verification:

import { createMobileApprovalServer, SimulatedDevice } from "@rtq/mobile";
const server = await createMobileApprovalServer({ /* … */ });
const device = new SimulatedDevice({ name: "my‑device", keyPair: myKeyPair, pinnedHostPublicKey: hostPubKey });
await device.approveWithBiometric(challengePayload);

🔬 Verification

  • All 12 packages pass the CI suite (npm run ci).
  • New biometric flow is covered by unit tests (tests/mobile/biometric.test.ts).

💡 Why RTQ Was Created

While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS‑level sandboxing, capability scoping, fine‑grained permission gating, and challenge‑response authorization from scratch. RTQ was created to solve this problem for developers everywhere — packaging a security‑focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ enables developers to integrate capability security, OS‑enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge‑response approvals into their applications without having to build security infrastructure from scratch.

v0.1.0

Choose a tag to compare

@Latestinssan Latestinssan released this 20 Sep 11:07

RTQ Release v0.1.0 — Risk-Adaptive Capability Security Runtime

GitHub All Releases
npm version
License

RTQ is a security-focused capability-security runtime for Node.js, TypeScript, Model Context Protocol (MCP) servers, and mobile approval hosts. Security-critical packages declare zero third-party npm runtime dependencies. It turns "can this agent/tool do this?" into an evidence-backed security pipeline:

Command → Capability (registered) → Risk (authoritative) → Policy (default-deny)
       → Clarification (missing critical params) → Approval (human/device)
       → Authorization Ticket (signed, single-use, bound) → Execution (OS-sandboxed)
       → Audit (structured, redacted)

📥 Downloads & Assets

📱 Android Mobile Approval App

  • File: app-release.apk (62.24 MB)
  • Direct Download: Download app-release.apk
  • Downloads Tracker: APK Downloads
  • Features: Scans QR challenges generated by RTQ, performs local Ed25519 signing using device platform secure storage, zero-PIN transmission over untrusted transport. Built with Flutter 3.11+ / Dart 3.11+ targeting Android 12+ (Java 17).

📦 Published npm Monorepo Packages (@rtq/* v0.1.0)

All 12 packages are published and live on the npm registry:

Package Version Link Role
@rtq/security 0.1.0 npm package Main unified pipeline façade (createRTQ)
@rtq/cli 0.1.0 npm package Security CLI (capabilities, policy check, sandbox test, verify)
@rtq/mcp 0.1.0 npm package Business-Grade MCP integration gateway
@rtq/core 0.1.0 npm package Capability registry, ticket store & schema validation
@rtq/crypto 0.1.0 npm package Canonical JSON, HMAC-SHA256, nonces, constant-time compare
@rtq/sandbox 0.1.0 npm package macOS Seatbelt, Linux bubblewrap, Windows AppContainer wrappers
@rtq/approval 0.1.0 npm package Approval strategies & QR/mobile challenge-response protocol
@rtq/mobile 0.1.0 npm package Mobile approval host transport and pairing server
@rtq/risk 0.1.0 npm package Authoritative risk engine (caller claims can never downgrade)
@rtq/policy 0.1.0 npm package Declarative default-deny rule evaluator
@rtq/clarification 0.1.0 npm package Ambiguity resolution & structured security parameter questions
@rtq/audit 0.1.0 npm package Structured, redacted security event logger

🚀 Quick Start

Installation

# Install core security runtime
npm install @rtq/security

# Or install the CLI globally
npm install -g @rtq/cli

Usage Example

import { createRTQ } from "@rtq/security";

const rtq = createRTQ({ signingKey: process.env.RTQ_SIGNING_KEY! });

rtq.registerCapability({
  name: "files.read",
  version: 1,
  description: "Read a file inside the workspace",
  inputSchema: { type: "object", properties: { path: { type: "string" } }, required: ["path"] },
  risk: { base: "low" },
  execute: async (ctx, input) => ({ ok: true, data: { path: input.path } }),
});

rtq.registerPolicy({ kind: "allow", capability: "files.read", reason: "Workspace reads" });

const auth = await rtq.authorize({ capability: "files.read", version: 1, input: { path: "/workspace/report.md" } });
if (auth.decision === "allowed") {
  const outcome = await rtq.execute(auth.ticketId);
  console.log("Result:", outcome.result);
}

🔬 System Capabilities & Verification

  • Verified in CI: 12 automated security invariants (INV-01 through INV-12), 430+ unit/contract/security tests passing, multi-OS platform sandbox enforcement tests (macOS, Linux, Windows), cross-language Node vs Dart protocol vectors.
  • Process-Local Ticket Store: Ticket single-use redemption is currently managed in process-local memory. Distributed multi-node replay protection requires a shared ticket store backend.
  • Platform Cryptographic Storage: Mobile Ed25519 keypairs use platform secure storage (flutter_secure_storage utilizing Android Keystore / iOS Keychain where supported).
  • Host Trusted Computing Base (TCB): RTQ governs authorization, ticket validation, and process sandboxing; handler internal logic remains part of the host application TCB.

💡 Why RTQ Was Created

While developing Aartiq, a disproportionate amount of engineering time was spent repeatedly implementing OS-level sandboxing, capability scoping, fine-grained permission gating, and challenge-response authorization from scratch. RTQ was created to solve this problem for developers everywhere — packaging a security-focused capability security runtime into a clean suite of reusable packages. Developed and validated through automated security testing, RTQ enables developers to integrate capability security, OS-enforced sandboxing, Model Context Protocol (MCP) policy enforcement, and mobile QR challenge-response approvals into their applications without having to build security infrastructure from scratch.