driftcheck touches things people care about: it rewrites agent config files
(~/.claude.json, .mcp.json), replaces skill directories, and asks registries
and git remotes what versions exist. This policy explains the trust model and
how to report problems.
- Local trust, remote caution. Everything driftcheck reads locally is
trusted (your config, your skill dirs, your snapshots). Everything remote is
treated as data, never code: registry responses are only parsed for version
strings; GitHub tarballs are extracted with member names checked against
..traversal and only files under the recorded subpath are written. - Zero dependencies. The whole tool is Python standard library — the supply-chain surface is zero by construction. Please keep it that way.
- Nothing is sent anywhere. No telemetry, no analytics, no callbacks. The
only outbound traffic is: npm/PyPI registry metadata reads, GitHub API reads,
codeload tarball downloads, and
git fetch/pullon your own remotes. - Every mutation is reversible. One snapshot per batch before any change;
driftcheck restore latestundoes the whole batch, deleting files the batch created. A failed snapshot aborts the batch with zero mutations. - Exact-version by design. MCP servers are pinned to exact versions;
adopted skills refresh from a tarball at an exact SHA. No
@latestexecution paths are introduced by driftcheck itself.
Please use GitHub's private vulnerability reporting on this repo
(Report a vulnerability → Security tab), so details stay private until a fix
ships. Include: the command you ran, the driftcheck version (head -1 of the
output), OS and Python version, and anything unexpected the tool wrote.
Expect a reply within a few days. Fixes land in main and are released under
a patched version with a CHANGELOG entry crediting the report (unless you
prefer to stay anonymous).