Commit de34ca7
committed
Roadmap: declared trust-boundary / accepted-risk annotation (user-validated)
A reviewed, intentionally-accepted finding should render as acknowledged
rather than re-surface as an unreviewed medium on every scan. Motivating
evidence is real: camel-ai/camel #4155 (the eval() in hybrid-browser-
toolkit.ts we raised) was resolved by PR #4157 (merged to master
2026-07-17) as documentation only -- the eval() intact, a source comment
and tool-schema wording declaring the trust boundary, plus a test. The
gate still flags it medium/inferred despite that formal declaration
because it reads code, not declared intent. Backlog the mechanism: a
declared, attributable accepted-risk (governance.yaml or inline) the gate
renders as accepted rather than open -- never a silent suppression.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014Z2Zcqf7F1EawAx23FLwAp1 parent 25405b0 commit de34ca7
1 file changed
Lines changed: 21 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
130 | 130 | | |
131 | 131 | | |
132 | 132 | | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
133 | 154 | | |
134 | 155 | | |
135 | 156 | | |
| |||
0 commit comments