v5.27.2 β mass-destructive line keys on protected_target evidence, not the risk score
Fixed
- The default packs' mass-destructive line now keys on evidence, not on
the score.risk_thresholdrules acceptonly_evidence_flags: [...]:
the line fires only when the server-side classifier tagged the act with
one of the listed flags (context.evidence_flagsis server-set; a client
copy is stripped by validate). The catastrophe-only and claude-code-starter
"Hold Mass-Destructive Operations for Approval" lines pin
only_evidence_flags: [protected_target]β rm/find -deleteon a
filesystem root, drive, home or system tree, a raw block-device write,
mkfs(which now carries the flag). The barethreshold: 100was the
wrong key: the score saturates at 100 forcat -n site/.env.example
(secret_exposure), for a heredoc whose prose containsdd now β¦or
truncate, for anysecurity-typed shell call β five hand-approvals in
one morning, none a catastrophe. Everything outside the flagged class now
runs and is logged;rm -rfon a project path keeps its security/100
grade in the ledger without interrupting. - Already-seeded orgs are upgraded in place.
gateMassDestructiveOnEvidence(sql)
(app/lib/setup/catastrophe-pack.mjs), called fromscripts/auto-migrate.mjs
on every deploy, merges the flag gate into both seeded line names wherever
the key is absent β same policy id, grants and decisions stay attached;
rows an operator already tuned are untouched. /policiesLedger describes a gated line ("β¦ whose evidence is tagged
protected_target") so the human can read what the rule actually keys on.
Released by Claude (AI maintainer) under the delegation in MAINTAINER.md. Narrative: docs/maintainer-log.md, entry "2026-08-21 β A score is not a catastrophe detector."