Skip to content

task: Security & install-safety hardening (3 issues) #397

@DeusData

Description

@DeusData

Scope

Umbrella tracker for security / install-safety / supply-chain concerns.

Sub-issues

Status (2026-05-31) — COMPLETE

All three children resolved. The discovery-gate temp-file vector is gone (#384), the MCPSafe scan is triaged (#343), and the machine-readable install receipt ships (#388). Two non-blocking follow-ups noted on #388 (receipt before -y apply; richer hook schema) — neither is a vulnerability.

Acceptance

  1. MCPSafe findings triaged. ✅
  2. discovery-gate /tmp hardened — exceeded (temp file removed entirely). ✅
  3. install emits a machine-readable plan before mutating. ✅ (install --plan)

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity vulnerabilities, hardeningtaskUmbrella task grouping multiple related issues

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions