-
Notifications
You must be signed in to change notification settings - Fork 7
claude-code: adversarially harden the privacy boundary #59
Copy link
Copy link
Open
Labels
claude-codeClaude Code integrationClaude Code integrationenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededintegrationAgent/runtime integration workAgent/runtime integration workprivacyPrivacy boundary or telemetry workPrivacy boundary or telemetry work
Description
Activity
Metadata
Metadata
Assignees
Labels
claude-codeClaude Code integrationClaude Code integrationenhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededintegrationAgent/runtime integration workAgent/runtime integration workprivacyPrivacy boundary or telemetry workPrivacy boundary or telemetry work
Goal
Treat Claude Code integration input as hostile and prove that sensitive local context cannot accidentally cross MARGINAL privacy boundaries.
Contribution wanted
Build adversarial privacy tests using synthetic canaries and harden any boundary that fails.
Synthetic canaries
Include synthetic examples resembling:
Required guarantee
Privacy-safe or exportable evidence must not contain raw:
Pseudonymization must not be presented as anonymity.
Acceptance criteria
Security posture
If a field cannot be proven safe for a strict privacy boundary, reject or keep it local rather than attempting heuristic sanitization.