docs: endpoint-page competitive fact-check — correct refuted claims, fix number drift - #198
Merged
Merged
Conversation
…fix number drift Five sourced research passes (2026-07-29/30) verified every competitive claim on the MDM solution page and the sentinel spec against vendor primary sources. Full citation-complete report in docs/superpowers/research/. Corrections: - Solution page "Why endpoint-native" rewritten: the "only Harmonic and Lanai ship endpoint agents / inventory unoccupied" thesis was refuted (CrowdStrike Shadow AI Discovery 2026-03, Koi->Palo Alto ~$400M 2026-04, Cyberhaven, SentinelOne/Prompt 2025-09, Netskope endpoint scanning GA 2026-06-02, Zscaler Endpoint AI Security announced 2026-06-09, Harmonic endpoint inventory ~2026-07-26). New text claims only the verified wedge: independent OSS audit, MDM-pushed, five-surface footprint incl. Office add-ins, local PII-exposure evidence. - Spec gets a [CORRECTED 2026-07-30] banner above the refuted paragraph. - Jamf recipe: notarization only needed for PreStage/user-run installs; the PKG installs the LaunchDaemon, a Managed Login Items profile tamper-protects it. - Intune recipe: no native scheduled-task payload — script-registered task or Remediations. - Number drift: "1,200+ payloads" -> "3,900+" (measured: getAllPayloads() = 3,962 across 25 categories); "1,184+ Malicious Skill IOCs" stat tile (a ClawHavoc campaign figure, not a shipped capability) replaced with verified "18 MCP Clients Covered". - README: add missing g0 protect and g0 sentinel command rows; link protect.md, hooks.md, and the MDM solution brief from both doc indexes. All ManageEngine Endpoint Central capability claims verified accurate. Co-Authored-By: Claude Fable 5 <[email protected]>
g0 security scanScore 55/100 (F)
Findings
55 more findings
Gate: PASSED ✅ — See findings across every repo in your org → https://guard0.ai/signup?utm_source=github&utm_medium=pr_comment&utm_campaign=g0_action |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Five parallel sourced research passes (2026-07-29/30) verified every competitive claim on the MDM/endpoint solution page and the sentinel spec against vendor primary sources. The load-bearing claim — "only Harmonic and Lanai ship true endpoint agents; the inventory positioning is unoccupied" — was already false on the spec's write date, and the docs carried stale capability numbers. For a product positioned as an auditor of record, our own pages have to audit clean.
What was refuted (full citations in the new research doc)
Verified surviving wedge (now the only claims the page makes): per-machine inventory × local PII-exposure evidence, Office add-in coverage, MDM-pushed non-resident audit, independent open-source auditor positioning.
Changes
docs/solutions/mdm-ai-footprint-governance.md— "Why endpoint-native — and why independent" rewritten around the verified wedge; names the EDR/SSE endpoint entrants honestly; links the sourced fact-check. Jamf recipe corrected (notarization only for PreStage/user-run installs; PKG installs the LaunchDaemon, Managed Login Items profile tamper-protects). Intune recipe corrected (script-registered Scheduled Task or Remediations — no native payload).[CORRECTED 2026-07-30]banner above the refuted paragraph (original text preserved as historical record).docs/superpowers/research/2026-07-30-endpoint-page-competitive-fact-check.md(new) — complete claim-by-claim verdicts with every source URL, incl. verification that all 7 ManageEngine Endpoint Central capability claims are accurate.getAllPayloads()= 3,962 across 25 categories); "1,184+ Malicious Skill IOCs" stat tile (ClawHavoc campaign figure, not a shipped capability) replaced with verified "18 MCP Clients Covered". The 1,184 figure remains only indocs/openclaw-security.mdwhere it is correctly framed as campaign reporting.g0 protectandg0 sentinelcommand rows; linkprotect.md,hooks.md, and the MDM solution brief.Verification
getAllPayloads()(3,962 / 25 categories)src/mcp/well-known-paths.ts(18 entries)rgsweep confirms no stale1,200+/1,184+capability claims remain outside the campaign-reporting context🤖 Generated with Claude Code