Skip to content

fix: reshape skill verify security signals#2402

Merged
Patrick-Erichsen merged 1 commit into
mainfrom
pe/verify-security-signals
May 26, 2026
Merged

fix: reshape skill verify security signals#2402
Patrick-Erichsen merged 1 commit into
mainfrom
pe/verify-security-signals

Conversation

@Patrick-Erichsen
Copy link
Copy Markdown
Contributor

Summary

  • Flatten clawhub skill verify envelope metadata so skill, publisher, and selected version fields are top-level.
  • Move ClawScan verdict fields to security.* and scanner evidence to security.signals.*.
  • Document the verify endpoint shape and update the durable security/moderation intent note.

Tests

  • bunx vitest run -c vitest.config.ts convex/httpApiV1.handlers.test.ts --testNamePattern "verification|Skill Card"
  • bun run --cwd packages/clawhub test:src -- src/cli/commands/inspect.test.ts src/schema/schemas.test.ts
  • bunx vitest run -c vitest.config.ts packages/schema/src/schemas.test.ts
  • bun run ci:packages
  • bunx tsc --noEmit
  • bunx tsc -p packages/schema/tsconfig.json --noEmit
  • bunx tsc -p packages/clawhub/tsconfig.json --noEmit
  • bun run ci:static

Notes

  • Autoreview did not produce a clean marker locally because Codex review crashed or spawned nested review processes; fallback Claude had low credit and Droid was unauthenticated.

@Patrick-Erichsen Patrick-Erichsen requested a review from a team as a code owner May 26, 2026 01:41
@vercel
Copy link
Copy Markdown
Contributor

vercel Bot commented May 26, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clawhub Ready Ready Preview, Comment May 26, 2026 1:45am

@clawsweeper
Copy link
Copy Markdown

clawsweeper Bot commented May 26, 2026

ClawSweeper status: review started.

I am starting a fresh review of this pull request: fix: reshape skill verify security signals This is item 1/1 in the current shard. Shard 0/1.

This placeholder means the worker is alive and reading the current context. I will edit this same comment with the actual review when the claws are done clicking.

Crustacean status: shell secured, claws on keyboard, evidence pebbles being sorted.

@Patrick-Erichsen Patrick-Erichsen force-pushed the pe/verify-security-signals branch from 6bd1d34 to 1c68fdc Compare May 26, 2026 01:45
@Patrick-Erichsen Patrick-Erichsen merged commit 07fed45 into main May 26, 2026
22 checks passed
@Patrick-Erichsen Patrick-Erichsen deleted the pe/verify-security-signals branch May 26, 2026 01:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant