docs: add the CTO belt for status and proof - #204
Conversation
The belt names trustshell status and trustshell proof --verify. It tells the reader not to print a secret.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Strix Security ReviewNo security issues found. Review summaryThe PR adds a single Markdown documentation file ( Updated for Reviewed by Strix |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
The PR adds a single Markdown documentation file (skills/belts/CTO.md) describing two CLI commands and cautioning against printing secrets, plus a corresponding test (tests/cto-belt.test.ts) that reads the static documentation file and asserts on its allowed content. Both added files contain no runtime code, no hardcoded secrets, no user-controlled input, and no dangerous sinks. The changes are documentation and test-only additions with no security-relevant impact.
Reviewed by Strix
Configure security review settings
CTO belt is a now-list:
trustshell statusandtrustshell proof <agentIdOrSlug> --verify. It says to read the CLI lines and not to print a secret, a key, or an env value.No HeyGen. No live stake. No secret values in the file.
Related to #191.