Skip to content

docs: describe the payment check first and its trust boundary - #50

Merged
gabchess merged 1 commit into
mainfrom
docs/v030-pass
Sep 22, 2026
Merged

gabchess merged 1 commit into
mainfrom
docs/v030-pass

Conversation

@gabchess

@gabchess gabchess commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

What changed

The root README describes the payment check first, runs it first, and links the changelog. THREAT-MODEL.md gains a section on the payment check's boundary: what the caller controls, what the owner controls, what consult() reads. CONTRIBUTING.md and SECURITY.md name the consult/, mcp/ and augment/ surfaces. The agent skill, the catalog reference and the server README name the authorization window and policyFields.

How it is tested

yarn public:check, yarn evals:offline, yarn evals:test, yarn augment:verify and yarn lint pass.

Summary by CodeRabbit

  • Documentation
    • Updated repository documentation to describe Hedwig’s payment-check service, MCP server, and onchain role program.
    • Added setup and verification commands for Consult, MCP, and Augment.
    • Clarified security scope, deployment authority, and Consult’s caller responsibilities.
    • Expanded Augment documentation with an additional evaluation scenario.
    • Documented required payment policy fields, including Solana role selection and authorization windows.
    • Clarified policy validation and outcomes for incomplete payment policies.

The README leads with the payment check and links the changelog. THREAT-MODEL.md gains the payment check's boundary and drops a plan. CONTRIBUTING and SECURITY name the consult and mcp surfaces. The skill, the catalog reference and the server README name the authorization window and policyFields.
@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3a2aabee-1beb-4687-9885-c7006e507d3a

📥 Commits

Reviewing files that changed from the base of the PR and between 7d569c3 and aa53800.

📒 Files selected for processing (8)
  • CONTRIBUTING.md
  • README.md
  • SECURITY.md
  • THREAT-MODEL.md
  • augment/README.md
  • augment/skills/hedwig/SKILL.md
  • augment/skills/hedwig/references/conditions.md
  • mcp/README.md
 _____________________________________________________________
< Oompa Loompa doompadee doo, I've got a code review for you. >
 -------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@gabchess
gabchess merged commit 36e4474 into main Sep 22, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant