feat: add Proof Before Action evidence workflow - #169
Conversation
Agent Permission Diff
Gate DecisionNo findings were produced. FindingsNo agent-facing permission findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fb94dbab0f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6a920e2271
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ab64774ba0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review superseding exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: df52cf45f8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please perform a fresh independent review of exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1a5696b571
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please perform a fresh independent review of exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 752bd4c8c6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please perform a fresh independent review of exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cd6ec4bde3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please perform a fresh independent review of the exact current head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1a41b18eda
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 74dbc3bad4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please perform a fresh independent merge-relevant review of exact head 93aefce. Re-review the complete Proof Before Action change, especially privacy-preserving full remote identity, npm package-selection/call handling, strict config/JSON types, command/semantic bindings, trust authority/freshness, cleanup, and fail-closed observation claims. Treat aliased, normalized, coerced, forged, noncanonical, self-consistently rehashed, contradictory, malformed, incomplete, unknown, stale, masked, unmatched, dirty, unbound, or unobservable evidence as non-authoritative. Report any remaining actionable correctness, security, provenance, cleanup, schema, packaging, CLI, or user-flow defect. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 93aefcecb4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please perform a fresh independent merge-relevant review of exact head 62aece8. Re-review the complete Proof Before Action change, especially exact remote path identity, Boolean-resistant trust schemas, npm selector handling, strict config/JSON types, command/semantic bindings, trust authority/freshness, cleanup, and fail-closed observation claims. Treat aliased, normalized, coerced, forged, noncanonical, self-consistently rehashed, contradictory, malformed, incomplete, unknown, stale, masked, unmatched, dirty, unbound, or unobservable evidence as non-authoritative. Report any remaining actionable correctness, security, provenance, cleanup, schema, packaging, CLI, or user-flow defect. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 62aece81bf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. Delightful! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Correction: the exact local/remote/PR head is |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 38fb470d09
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c527240be0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 95e53cfc99
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 29c74750c0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c7b39c7d1c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. Delightful! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Re-requesting now that exact-head CI is fully green. Please review commit |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
Adds Proof Before Action as a local-first MCPAudit product surface. It runs a caller-supplied command as an unprivileged, capability-free user inside a disposable Docker observer, compares observed effects with a strict declaration, joins repository-local MCP dependencies to a read-only mcp-trust snapshot, and exports a portable JSON/offline-HTML evidence capsule.
This is evidence before action, not a general sandbox or release authority. The v1 final-state observer intentionally reports a clean final snapshot as
unknown, notpass, because transient filesystem and database attempts are not traced. Persisted undeclared effects still block. No result proves container-escape resistance, macOS-native effects, exact-version applicability for unresolved dependencies, or authorization unless the capsule-index root is anchored independently.Changes
proof-before-actionconsole script withinspect,verify, and versionedschemacommands.--network=none, read-only image root,no-new-privileges, and resource/output limits;KILL,SETGID,SETPCAP, andSETUID, with exact Docker configuration readback;65534:65534, with empty supplementary groups and all five Linux capability masks verified as zero from a root-protected runtime profile;server.jsontransport entries asunknownwith partial-discovery diagnostics instead of raising an unstructured exception.inspection_blockedresults, checks Docker cleanup exit codes and local temporary-root removal, and blocks otherwise-successful inspection when cleanup cannot be confirmed.unverifiableevidence, preventing modified grades from appearing current.authority: unverified, reservinganchoredfor an actual digest match.dockerprovider while retaining the legacydocker-in-colimavalue only for v1 input compatibility; limitations describe the Docker engine and any optional VM/hypervisor as unobserved rather than asserting a runtime that was not detected.inspection_blockedresult with exit code 2 instead of leaking a parser traceback.current.complete: truesurfaces with any unknown attempted/decision/outcome/persisted state as non-passing, including legacy or alternate producer input.complete: true.mcpServersorserverswhen emitting exact JSON Pointers and pointer-bound dependency IDs.Checklist
Security implications
noneprevents ordinary external interfaces but does not prove resistance to container, VM, or hypervisor escape.--expect-root-sha256is required for externally anchored authority.Test plan
uv sync --dev --lockeduv run pytest -q→ 1008 passeduv run pytest -q tests/test_proof_before_action.py→ 124 passeduv run ruff check .→ passeduv run ruff format --check→ 109 files formatteduv run mypy src→ no issues in 51 source filesuv lock --checkandgit diff --check→ passedproof-before-action = mcp_audit.proof_cli:main; installed help and schema emission succeed;unverifiable;capsule-index.json;inspection_blockedresult before image-provided observer tools run;unknownverdict, records providerdocker, matched image IDsha256:6f7b03f7c2c8e2e784dcf9295400527b9b1270fd37b7e9a7285cf83b6951452d,provenance_source: build-metadata, producer commit18dcf649a19437ef49f7f525cea911a720244a4d, anddirty: false; filesystem, database, and network coverage are explicitly incomplete, IPv4/IPv6 counters are present, and observation/manifest share the staged-subject binding;77ad9d5a1ec5967635e78aaf584bfd3390cf232b, producer commit18dcf649a19437ef49f7f525cea911a720244a4d, schemaproof-before-action.capsule.v1, and independently supplied root7e42ec501c1b9bf126523a8561ce7d5ba95db76efe1d4a632179d1320c8f228b→ valid, authorityanchored;authority_root_mismatch,valid: false, andauthority: unverified.artifact_tamperedandreport_projection_mismatch.unknown; exit 0 remains reserved for a complete observation mechanism;block;inspection_blockedJSON result and no traceback.Limitations and rollback
Related issues
None.