ops-warden (WARDEN-WP-0037-T01) reported the whynot-design npm lane as
platform/workloads/coulomb/whynot-design/npm-publish, field NPM_AUTH_TOKEN.
Reviewed without any OpenBao read or mutation:
- The field claim conflates the injected env var (resolved by
publication_policy) with the declared KV field (npm_token). Annotated the
catalog so the distinction is explicit at the point of confusion.
- The path claim is credible but unresolved: hardening-backlog already names
both locations, and custody is owned by railiance-platform. Catalog
mount/path left unchanged pending custody-side confirmation rather than
rewriting a proven production lane from an inbox claim.
Recorded under SECRETS-WP-0006-T06.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M65ovP3eiiPHubibvWs9mD
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 393550@bnt-lap001
Assistant-Session: 4bb359f9-1f12-4410-9e76-079cf23c82e4
Re-render admitted-lane plans as kv-mount-check plus exact-path AppRole.
Name openrouter-llm-connect as the first candidate. Document apply,
verify, and rollback without authorizing live mutation. T05 stays wait
on T04 serving and attended authority.
Assistant: grok
Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00
Write the selected field to a mode-0600 temp file, inject FIELD_FILE for
the child only, then overwrite and unlink on every exit path. The value
is not copied into the child environment.
Assistant: grok
Assistant-Session: 01a05f07-ae72-7781-9fcb-19efd61add00