feat: add HMAC-SHA256 report authenticity envelopes (Phase 20 JSON slice) - #10
Open
mattpartida wants to merge 1 commit into
Open
mattpartida wants to merge 1 commit into
mattpartida wants to merge 1 commit into
Conversation
…ice) - Add --envelope-secret-file to config_risk_summary.py: optional additive report_envelope (algorithm, payload_sha256, signature, covered_fields) over the JSON report payload; output unchanged without the flag - Fail closed on unreadable/empty secrets with structured invalid_envelope_secret error findings; require --format json - Add dependency-light verify_report_envelope.py verifier with --secret-file/--secret-env (mutually exclusive), constant-time compare, exit codes 0/1/2, and machine-readable failure codes - Add docs/report-envelopes.md plus README, SKILL.md, ci-integration, changelog, and roadmap sync - Add tests/test_phase20_report_envelopes.py (17 tests: compatibility, determinism, tamper detection, secret handling, docs sync)
This was referenced Sep 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements the roadmap's Phase 20 (first slice): an optional, non-executable integrity envelope for exported JSON reports so downstream consumers can detect accidental or malicious report mutation between scan time and review time.
Scanner (
skills/agent-security/scripts/config_risk_summary.py):--envelope-secret-file <path>flag adds an additivereport_envelopeobject to JSON output:algorithm(hmac-sha256),payload_sha256,signature, and sortedcovered_fields.invalid_envelope_secreterror findings (ok: false, strict exit 1) instead of silently unsigned output.--format json(default); combining with markdown/SARIF is a usage error (exit 2) rather than silently unsigned output.New verifier (
skills/agent-security/scripts/verify_report_envelope.py):--secret-file <path>/--secret-env <VAR>.missing_envelope,unsupported_algorithm,malformed_envelope,payload_digest_mismatch,signature_mismatch,invalid_secret,invalid_report), 2 = usage error.hmac.compare_digest).Docs: new
docs/report-envelopes.md(envelope fields, verifier usage, exit-code table, secret generation/storage/rotation, integrity-not-encryption scoping); README quick start + key-files list;SKILL.mdhelper scripts + example commands;docs/ci-integration.mdsigned-artifact workflow section; CHANGELOG; roadmap Phase 20 marked Shipped (JSON report slice) with explicit remaining follow-ups (SARIF/Markdown coverage,kidmulti-secret rotation support).Test Plan
tests/test_phase20_report_envelopes.pywritten first (17 tests, all red before implementation)report_envelope; existing JSON fields unchangedpython -m compileall -q skills tests scripts— OKpython -m pytest -q— 146 passed (129 baseline + 17 new)ruff check .— All checks passed./package-skills.sh+python3 scripts/package_skills.py --check— artifacts current and reproducible (new verifier script is packaged intoagent-security.skill)git diff --check— cleanFollow-ups deliberately deferred: SARIF/Markdown envelope coverage and key-identifier (
kid) rotation support — recorded in the roadmap as remaining Phase 20 scope.