Commit Graph
6 Commits
Author SHA1 Message Date
justinandClaude Opus 5 e5f05eff6c feat(catalog): cover Windows guest-mutating tools in the starter list
The catalog is opt-in: an unlisted tool passes through unguarded. The
shipped starter list was ssh/exec and ansible/run_playbook, both Linux
shaped, so an agent changing a protected Windows guest over WinRM or
PowerShell was never guarded at all. That does not fail loudly, it
simply never inserts a checkpoint.

Adds winrm/run_command, winrm/run_ps, powershell/invoke_command and
smb/write_file. The smb entry is there because a file written into a
share changes the guest without any shell being involved.

Test asserts the example config covers both platforms and that every
entry names a vm_arg, since without one the guard cannot resolve a VM.

Still illustrative, not exhaustive: tool names vary per MCP server, so
users add their own with zerto_add_mutating_tool. That reactive model is
the real weakness here and is worth revisiting separately.

Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
Claude-Session: https://claude.ai/code/session_016yVfC5nvZowoLFnEGWhLGn
2026-09-21 14:32:52 -04:00
claude 90768f17e1 feat(flr): windows paths, recovery-site gate, stable partition reads (#4) 2026-09-21 14:11:09 -04:00
claude 59d1f71617 feat(flr): make FLR session lifecycle visible and reapable (#3) 2026-09-21 13:43:05 -04:00
claude 108e919dcb fix(flr): partition-rooted FLR paths + agent/intent in checkpoint names (#2) 2026-09-21 13:42:36 -04:00
claude 2473d22d2e fix(flr): 10.9 session list + download path (#1)
Co-authored-by: claude <[email protected]>
2026-09-21 12:18:13 -04:00
claude 38ba9c1b50 feat(poc): rewind MCP, skill, and recover-ladder docs
Initial PoC: find_protection, tagged checkpoints, FLR, mutating catalog.
Lab 10.9 status enums (0=Initializing, 1=MeetingSLA). Credentials stay in gitignored config.json.
2026-09-21 12:09:11 -04:00