Repository navigation
Trust: a family is what a command does and where; production and SQL writes cost more; families nest - #43
Merged
Conversation
packages/trust/experiments/families: a labelled set of made-up command pairs (must stay separate: dev vs prod, read vs write; fine together: another file, row or id — some held out until the end), the candidate rules, and a runner that scores them there and, as counts only, on the Trust ledgers on the machine it runs on. Nothing from a ledger is printed or kept. Not part of the package. Today's rule merges 23 of 32 must-separate pairs (`mcpx db-local` with `mcpx db-prod`, `compose -p dev` with `-p prod`). Rule G — the plain words and target flags read in order, plus environments named in env vars and hosts — merges none, splitting 6 of 29 pairs that could share a family. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… production and SQL writes cost more
A family is what `w` ("trust any …") covers. It was a program and, for tools in a table, its
subcommand — so `mcpx db-local` and `mcpx db-prod` were one family, and so were `docker compose -p dev up`
and `-p prod up`: widening either trusted production along with dev. Measured on labelled pairs
(packages/trust/experiments/families), the old rule merged 23 of 32 that must stay apart.
Now, for any CLI: the program and the plain words after it (up to three, until the first argument),
any flag that names a target with its value (`--context`, `--profile`, `-p`, `-n`, `--host`…), and any
env var, host or name that names an environment. Standard utilities (`ls`, `cat`, `grep`…) take no
subcommand, so their family stays the program. On the same pairs: none merged, one split (a
service name), kept as test/families.test.ts.
- `mcpx db-prod execute_sql …` → `mcpx db-prod execute_sql`; `docker compose -p dev up -d` →
`docker compose -p dev up`; `kubectl get pods -o wide -n prod` → `kubectl get pods -n prod`.
- Anything that names production (`prod`, `production`, `prd`, `live`, as a word or part of one) is
dangerous: the higher count, and its family is never widened.
- SQL that writes, in any program's argument (`--sql "delete from …"`), is dangerous, so a widened
`mcpx db-local execute_sql` answers reads and still asks about writes.
A family widened under the old rule matches nothing now: Trust asks again, never more.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Families sharing their first words sit in a folder (mcpx › db-local › execute_sql); a folder is for reading, w widens one family. A folder holding danger shows prod or ! while closed. A widening nothing falls in any more is marked old, out of any folder, and x removes it. The storefront sample adds mcpx, compose and kubectl, and an old widening. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
mcpx db-local …andmcpx db-prod …were one Trust family, sowon one trusted the other. Same fordocker compose -p dev/-p prod,kubectl --context a/b.-p,--context,--profile,-n,--site…) with their values, and env vars and hosts that name an environment.ls,cat,grepand the like stay one family.prod/production/prd/livein a flag, host, name orNODE_ENV=→ 8 approvals, never widened.update … set,delete from,insert into,drop,alter,create,truncate,grant. A widened family never answers them.mcpx›db-local›execute_sql. Folders are read-only:wwidens one family only. A closed folder showsprod/!when anything inside is dangerous.old, andxremoves it.Why this rule
packages/trust/experiments/familiesscores 10 candidate rules on 61 made-up labelled pairs:docker compose -p dev logs webvsapi).test/families.test.tskeeps it there.Checks
bun test --conditions browser(2285 pass);🤖 Generated with Claude Code