Register whitehat-security and align operating boundaries

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a0260c-4067-7052-9647-ad000d576e38
This commit is contained in:
tegwick 2026-08-21 22:52:37 +02:00
parent 0ce9f44ff9
commit 348738ba73
9 changed files with 474 additions and 16 deletions

View file

@ -11,12 +11,16 @@ true.
It exists because a repo testing its own boundary grades its own homework. The
probes most worth having are the ones an author would not think to write.
- **Independent by construction.** It does not take a declared posture as true,
and it is not owned by the repo whose canon it verifies.
- **Independent in operation.** It does not take a declared posture as true.
NetKingdom owns both the security canon and this facility, so findings leave
through `risk-nexus` under separate ownership rather than being resolved here.
- **It finds; it does not fix.** Findings route to `risk-nexus`, which owns
severity and disclosure. The repo that owns the defect owns the repair.
- **A pass means the attacks we tried did not work** — not that the boundary
holds. Reports say so.
- Intent: `INTENT.md`
- Workplans: `workplans/`
- Intent: [`INTENT.md`](INTENT.md)
- Scope: [`SCOPE.md`](SCOPE.md)
- Workplans: [`workplans/`](workplans/)
- Rules of engagement (pending operator approval):
[`docs/rules-of-engagement.md`](docs/rules-of-engagement.md)