diff --git a/DISCLOSURE.md b/DISCLOSURE.md index e54a73c..997e356 100644 --- a/DISCLOSURE.md +++ b/DISCLOSURE.md @@ -4,8 +4,8 @@ tier: T2 status: active owner: jp source: generated -last_reviewed: 2026-05-24 -review_by: 2026-08-22 +last_reviewed: 2026-05-25 +review_by: 2026-08-23 depends_on: - disclosure-schema - profile-distribution-protocol @@ -15,7 +15,7 @@ auto_regen_cmd: "yq '.disclosure' manifest.yaml | " # `steev` — Disclosure -> Live as of `2026-05-24`. Source: `steev/manifest.yaml → disclosure:` block. Pre-push hook check 6 (curator/lib/pre-push.sh) enforces this == live `hermes -p steev` runtime. +> Live as of `2026-05-25`. Disclosure schema v2 (manifest `disclosure.schema_version: 2` — adds `external_orchestrators` per DISCLOSURE-SCHEMA §4.6). Source: `steev/manifest.yaml → disclosure:` block. Pre-push hook check 6 (curator/lib/pre-push.sh) enforces this == live `hermes -p steev` runtime. ## §1 Identity @@ -43,6 +43,7 @@ auto_regen_cmd: "yq '.disclosure' manifest.yaml | " | `inherit_mcp_toolsets` | `false` | **CLAUDE.md hard-rule fix.** Closes Wave-1 finding: `bte` MCP silently leaked from host. `bte` = Plan B marketing platform — forbidden to steev per `steev/CLAUDE.md:14` ("No access to Plan B marketing platform credentials (CMO-only)") | | `inherit_dirs` | none | No external-dir skill bundles narrowed in | | `sovereign_only` | `false` | steev intentionally calls Perplexity (hosted) for lightweight WebSearch per `manifest.yaml:90` — disclosed honestly | +| `external_orchestrators` | `[]` | Schema v2 field (DISCLOSURE-SCHEMA §4.6). steev has no exec'd orchestrators (no sandcastle equiv) — empty list. | ## §3 Skills (6) diff --git a/manifest.yaml b/manifest.yaml index 8bea183..074fa06 100644 --- a/manifest.yaml +++ b/manifest.yaml @@ -99,13 +99,14 @@ sovereignty: # Pre-push hook check 6 enforces this == live `hermes -p steev …` runtime. disclosure: scope: personal - schema_version: 1 + schema_version: 2 chat_facing: true # sole JP chat touchpoint per CLAUDE.md L7-L8 delegates_to: [ceo-planb] # business work routed to CEO via kanban inherit_builtins: false # deny Hermes 84-builtin default; allowlist below inherit_mcp_toolsets: false # deny host MCP propagation (closes bte leak) sovereign_only: false # perplexity (hosted) intentionally called for WebSearch inherit_dirs: [] + external_orchestrators: [] # steev has no exec'd orchestrators (no sandcastle equiv) skills: - id: steev-agent