Skip to content

security: fix attestation HMAC pattern before any MCP exposure #59

Description

@hyperpolymath

Threat-model (2026-04-19) flags the SHA256(key||data) pattern; the hardened Trustfile's no-homerolled-hmac + metadata-only key types both block MCP exposure until fixed. Source: .machine_readable/threat-model.a2ml + contractiles/Trustfile.a2ml.

https://claude.ai/code/session_01GJatEm2TVFSTBEkKXmserJ

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions