ContextSec v0.3.0 — Research Preview
First public research preview of ContextSec, the product-security decision layer for AI coding agents.
Highlights:
- 16 product-risk packs, 116 controls, and 9 cross-context compositions
- Evidence-backed Security Profile, deterministic control checks, Control Evaluation Ledger, and release gate
- Fixed no-argument auth(), Clerk/Drizzle and tenant-key aliases, public client-secret namespaces, and unsupported-stack reporting
- Tenant-scoped Prisma CRUD enumeration plus raw-query abstention
- 40 labeled profile cases, 10/10 mutation verification, and 4/4 immutable real-repository cases
- Positive/negative contracts for every published text and dependency detector
- Windows, macOS, and Ubuntu CI across Python 3.11-3.14
- Local-first, offline, read-only profiling with no target-code execution
Artifact:
- contextsec-v0.3.0.zip
- SHA256: a5acebd589227114d5f80613c35d6219c3e65641449d2a466e83753b2f098125
This is a Research Preview, not a penetration-testing or compliance-certification product. Profile accuracy is measured on a maintainer-authored corpus; the four pinned repositories are case studies, not a representative ecosystem sample.