Skip to content

Lead with the task, ship a runnable walkthrough, fix the version drift - #2

Merged
GChief117 merged 1 commit into
mainfrom
first-use-walkthrough
Sep 16, 2026
Merged

GChief117 merged 1 commit into
mainfrom
first-use-walkthrough

Conversation

@GChief117

Copy link
Copy Markdown
Contributor

Acts on the cycle-8 distribution directive: turn the Glama discovery foothold into a
task-specific entry point with one copyable, tested walkthrough through a substantive
result.

Three problems, all on the only surface with verified external discovery

  1. The README led with what the server is, not what it does. It now opens with
    "Verify a signed agent mandate through MCP" and the first command runs a real
    verification.

  2. It advertised a command that does not resolve. npm serves 0.1.0, the version
    with the first-use defect; the README told people to run @0.1.1. There is now an
    explicit installation notice and a tested install from the release tarball with a
    checksum.

  3. The server misreported its own version. createServer advertised 0.1.0 while
    package.json said 0.1.1, so the MCP initialize handshake was wrong. A test now
    pins the two together.

The walkthrough

examples/verify-mandate.mjs, run against production before this PR:

decision: requires_approval
  violation: Actions above 25000 minor units need a human approval token.
  digest: c90fd0bc104dce63…

=== 4. Tamper with one signed field, keep the signature ===
rejected: Agent Mandate error 400/invalid_request.
The tampered mandate did not buy an allow. The signature is doing its job.

The tamper step is the part that matters. A happy-path walkthrough cannot show whether
the signature is checked at all. Raising approvalRequiredAboveMinor from 25,000 to
999,999 while keeping the original signature would turn requires_approval into
allow, so the script exits non-zero if it ever succeeds.

It starts the released artifact, not the working tree, so it exercises what a
developer actually installs. The key is read from the environment or prompted for
without echo, and is never printed or written to disk.

Verification

  • 29/29 tests pass, build clean
  • walkthrough run end to end against production: positive PASS, tamper PASS

🤖 Generated with Claude Code

…e version

Three problems on the only surface with verified external discovery.

1. The README opened with what the server IS, not what it DOES. A developer
   arriving from a listing had to read past an architecture description to find
   out whether it solved their problem. It now opens with the task, and the
   first command runs a real verification.

2. It told people to run `npx ...@0.1.1`, which does not resolve: npm serves
   0.1.0, the version with the first-use defect. Telling people a broken command
   works is worse than saying nothing. There is now an explicit notice and a
   tested install from the release tarball, with a checksum to compare.

3. createServer advertised version 0.1.0 while package.json said 0.1.1. A
   developer who checks the handshake found the artifact misreporting itself,
   which is corrosive for a product whose entire claim is that it tells you the
   truth about authority. A test now pins the two together.

examples/verify-mandate.mjs is the canonical walkthrough. It creates a mandate,
verifies an action through the MCP tool, then raises approvalRequiredAboveMinor
from 25000 to 999999 while keeping the original signature and verifies again.

That second call is the point. A walkthrough that only shows the happy path
cannot tell you whether the signature is checked at all. The tampered envelope
would turn a requires_approval into an allow, so if it succeeds the guarantee is
worthless and the script exits non-zero.

It starts the RELEASED artifact, not the working tree, so it tests what a
developer actually installs. The key is read from the environment or prompted
for without echo, and is never printed or written to disk.

Verified against production: untampered returns requires_approval with the
correct violation and a digest; tampered is rejected 400. 29/29 tests pass.
@GChief117
GChief117 merged commit 2439302 into main Sep 16, 2026
1 check passed
@GChief117
GChief117 deleted the first-use-walkthrough branch September 16, 2026 03:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants