Skip to content

ControlSpec v0.1.2 preview — exact-action controls alongside OpenShell

Pre-release
Pre-release

Choose a tag to compare

@claytonsamples claytonsamples released this 30 Sep 21:30
· 4 commits to main since this release
8e2050e

ControlSpec v0.1.2-preview.1 — exact-action controls alongside OpenShell

This experimental release adds a version-pinned NVIDIA OpenShell supervisor
middleware adapter and a nine-scene evidence replay. A synthetic purchase above
the example limit is denied until a separately represented operator approves
the exact action; changing its amount or replaying it cannot obtain a fresh
reservation. A separate target verifies execution tickets and supplies receipts.

Included: authenticated TLS gRPC, strict JSON inputs, real ControlSpec evaluation,
short-lived ApprovalFacts, durable local test records, target idempotency,
missing-proof reconciliation, a real smolagents tool denial example, and raw
reproducible observations. The earlier six-scene demonstration and original seven
reference examples remain available.

Protocol preview only. Actual OpenShell runtime enforcement and native policy
admission were not run. The demo labels that lane unavailable. Native OpenShell
already has body-aware policies; this project explores portable action authority
and evidence alongside it. Scripted operators, synthetic money/targets, local
shared-key evidence and reference non-authority flags are explicit limitations.
This is not production infrastructure or an NVIDIA/Hugging Face endorsed release.

Interactive evidence ·
Reproduction and boundaries ·
Verification

The next useful contribution is an independent OpenShell runtime reproduction
with effective policy capture, native body-rule parity and adversarial route tests.