kit 5.0.0
With 5.0, kit stops being only a point-in-time
verifier and becomes a continuous, portable, fail-closed governance layer for
the agent loop. Four pillars land, on top of a unified command surface. Nothing
here breaks the 2.x/4.x CLI, config, or plugin contracts — every new capability
is additive and every new gate is opt-in or degrades honestly.
Pillar 1 — Hardware-rooted identity (#289, #290)
- Honest keystore posture.
kit doctorsurfaces WHICH backend signs kit's
identity (Secure Enclave / TPM / external command vs. the file-backed 0600
key) and NEVER silently downgrades: a file-backed key is awarn, and
KIT_REQUIRE_HARDWAREmakes a missing hardware backend a fail-closedfail. kit identity migrate. Move identity onto a hardware backend and revoke
the old file key in one attributable, audited step.
Pillar 2 — Control plane + keyless credentials (#317–#323)
- Offline-verified policy distribution.
kit policy pullfetches an
org-signed.kit-policy.toml, verifies it against the anchored signers
entirely offline, andpull-revocationspropagates revocations monotonically
(never un-revokes). Fleet-RBAC rides the same signed channel. - Offline signed approval tokens.
kit policy approvemints/consumes
identity-signed, offline-verifiable approval tokens for gated operations. - Keyless credentials — sign, don't store. A pure RFC 9421 HTTP Message
Signatures core (src/keyless/http-sig.ts) plus an identity bridge lets kit
sign egress requests for hosts declared in[scope].signinstead of holding a
long-lived secret.kit doctorreports the keyless posture, fail-closed. - Control-plane posture row in
kit doctor+ self-host protocol docs.
Pillar 3 — Exec-broker: one governance floor (#303–#316, #324–#326)
- Pure scope-decision core (
checkEgress/checkFsWrite/scopeEnv) with
fail-closed source resolution: no verified signed scope ⇒ grants nothing. - PreToolUse enforcers
kit gate-egress/kit gate-fsblock Bash network
targets and Write/Edit paths outside the signed[scope], wired via
kit agent-config --broker-gate. - Runtime mediation at the MCP surface, staged safely:
off → observe (dry-run, auditswouldDeny) → enforce. A verified scope now observes by
default ([scope].enforce_runtimeabsent ⇒ observe) — mediation is on out of
the box without breaking anyone; enforce remains an explicit opt-in. - Reconciliation (R1–R4). The duplicate broker core was deleted and the whole
governance floor unified onto ONE exec-broker: CLI gates, the MCP runtime, and
thekit doctorposture all read the same signed decision — there is one
broker, not two.
Pillar 4 — Traveling profile + lifecycle insight (#291–#299, #325)
- Versioned, portable profile.
kit profiledeclares
{skills, mcp, workflows, plugins, vault, gates, scope}with canonical
serialization;show|freeze|checkreport declared-vs-discovered drift;sign
binds the scope/RoE;export/importmove a signed bundle to a fresh host,
integrity-verified offline and fail-closed on tamper/revocation. - Lifecycle insight. A deterministic transcript tool-usage scanner powers
kit insight unused(loaded-but-never-called MCP servers), real
loaded-but-unused verdicts for skills, and a repeat→codify skill-draft scaffold. - BYO-gap closers.
kit triage plugin(supply-chain + manifest-poisoning),
kit triage vault-config(backend-selection), and plugin discovery close the
last unaudited surfaces. - Repo-map (
kit map). A deterministic, zero-LLM import graph of the repo:
kit map <path> [--depth N] [--budget N] [--json]returns the minimal relevant
SLICE around a seed file (the files connected within N import hops, both
directions, plus the external packages) — so an agent loads part of a growing
repo, not the whole tree.--budgetkeeps the N nearest-to-seed files and
logs every drop (never silent truncation). Pure graph core + a
dependency-free TS/JS extractor; relative specifiers that resolve to no known
file are dropped, never guessed. Each slice file is annotated with its owner(s)
— from a committed CODEOWNERS (deterministic, last-match-wins), or the
git-blame top-author when no CODEOWNERS exists (fail-closed: git
absent/errored → no owner, never guessed) — so an agent knows who to route to.
--co-changeadds each seed's historically co-changing files from git history
(coupling imports miss — schema↔migration, code↔test), from one bounded
git log; fail-closed when git is absent. Exposed to agents as thekit_map
MCP tool (paths / depth / budget / co_change), sharing one core (mapReport)
with the CLI so the two surfaces can't disagree. The import graph covers
TS/JS and Python (dotted/relative imports,src/layouts); an unresolved
import is external, never guessed.
Triage delegate — deep skill scanning, borrowed authority (#327–#332)
kit triage skill --deepdelegates to NVIDIA SkillSpector's STATIC Stage 1
(regex + AST + offline OSV) and normalizes its SARIF into kit's verdict,
attributed to the source. kit NEVER runs SkillSpector's LLM stage — enforced by
a scrubbed child env (everySKILLSPECTOR_*+ provider key stripped) and a
static invocation. Fail-closed: an absent binary is askip, never a silent
deep-clean.- Commit-time enforcement.
kit triage check-skillsblocks a staged skill
that lacks a fresh--deeptriage;kit setup --recommendednow wires both
triage gates (check-deps+check-skills) into the pre-commit hook; and
kit doctorreports whether the gates are actually wired.
Unified surface (#271–#288)
- One source of truth.
cli.tswas decomposed into cohesivecommands/*
modules and aCOMMAND_REGISTRYfrom which the CLI verbs, MCP exposure, help,
and stability tiers are all derived — a drift test proves CLI ≡ MCP. - No false green. Six fabricated-success MCP stubs were removed; a tool that
can't really run now says so.
Added — coverage + supply-chain gates (#255–#266, #270)
kit coverage --standardmaps kit's deterministic checks to OWASP ASVS L2,
OWASP LLM Top 10 (2025), and NIST SSDF (800-218A) evidence maps.- Memory write-gate + verified-forget (G1), secret write-gate (G2), calibrated
slopsquat risk score (G4),kit triage mcptool-poisoning/rug-pull (G3), and
the agent-toolchain SBOM over skills/MCP/plugins (G5).
Fixed
kit memory restorenow surfaces the REAL failure cause (missing file, bad
format, permissions) instead of always reporting "wrong passphrase or corrupt
backup" — only a genuine AES-GCM auth failure blames the passphrase now
(restoreFailureMessage, unit-tested).
Changed
- Minimum Node.js is 22+. The public CLI/config/plugin contracts are unchanged;
5.0 is a major version for the scope of new capability, not for any break.
Full changelog: https://github.com/sandstream/kit/blob/v5.0.0/CHANGELOG.md
Verify this release:
git tag -v v5.0.0
npm audit signatures