Skip to content

feat(contracts): canonical Credential Access Contract - #104

Draft
chitcommit wants to merge 1 commit into
mainfrom
nick/credential-access-contract
Draft

feat(contracts): canonical Credential Access Contract#104
chitcommit wants to merge 1 commit into
mainfrom
nick/credential-access-contract

Conversation

@chitcommit

Copy link
Copy Markdown
Contributor

Summary

Adds the single canonical Credential Access Contract (chittycanon://core/contracts/credential-access) that templates and services cite rather than restate — the root cause of the recurring "1Password" drift is per-template restatement.
Also adds the ChittyGuardian conformance check check-credential-contract.sh.
Draft: opened for review; not for merge without operator go-ahead.

In this PR

  • canonical/contracts/credential-access.md — v1 invariants, role table, conformance checklist, enforcement pointer.
  • plugins/chittyagent-dispatch/scripts/check-credential-contract.sh — validated: passes clean, fails a surface that names 1Password / holds CF_ACCESS_CLIENT_* / lacks the citation.

Not in this PR (routed elsewhere)

  • Wiring the check into pre-commit-drift.sh (policy block) — follow-up on the dispatch repo.
  • Projecting the conformance block via chittyagent-dispatch into templates + chittyos-compliance SECURITY.md scaffold.
  • Drift fixes to chittyagent-template/SECURITY.md, mcp-auth, mcp-deploy-register (separate repos).
  • Registering ChittySecrets (L0) in ChittyRegistry — sensitive intent, routes through /chico.
    Tracked in Linear CFDXN-160 (+161–165).
    🤖 Generated with Claude Code
    https://claude.ai/code/session_01W7JQpX31TaGMfh3EQjPaA1

@coderabbitai

coderabbitai Bot commented Sep 8, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant