bkd-dotcom/Umbra Admission

Govern any coding agent's PR with an admission pipeline and a signed receipt. Never merges.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
missionThe bounded task the change claims to perform (used as the agent mission / review context).noReview this pull request's change for scope, introduced secrets, and injected repository instructions.
min-authorityMinimum earned authority level required to pass (0 observe, 1 analyze, 2 branch-PR).no1
agentForce a specific executor (codex-cli | claude-code) to re-run the change. Leave blank to govern the existing PR diff without invoking an agent.no""
signing-keyBase64 Ed25519 signing key (32+ bytes) for stable receipts. Falls back to an honestly-flagged dev key if unset.no""
umbra-versionVersion of umbra-core to install from PyPI (e.g. '0.1.0'). Blank installs the latest.no""
require-sandboxIf 'true', code-executing checks (npm/pip install, go/cargo build) are refused unless a real filesystem/network sandbox is available (fail closed).nofalse
python-versionPython version to run on.no3.12
namedescription
authority-levelThe authority level the change earned (0/1/2).
receipt-hashThe canonical hash of the signed receipt.