Warfare Command. A personal separation and retirement planner for Marines

Security

The honest model

You run Claude Code against this folder, so the instructions in CLAUDE.md and .claude/skills/ drive an agent on your machine with your Claude account. Instructions are not a permission boundary; Claude Code's own permission prompts are. We do not tell you to turn those off, and no step in this folder needs you to.

What the instructions ask the agent to do, and all they ask:

Nothing here asks the agent to install software, read files outside this folder, or reach any other host. The only commands it may propose are uuidgen to make the random install id and, if you ask it to, the curl delete in PRIVACY.md; it says what each does first. If Claude proposes anything else of that kind, say no and report it.

Releases

In the pilot, a release is a zip on the docs site at https://musterout.warfarecommand.com/dl/musterout-<version>.zip. Each version gets its own file name. The download page prints the SHA-256 of each zip. Check it before you unzip: shasum -a 256 musterout-<version>.zip on a Mac, Get-FileHash musterout-<version>.zip in PowerShell on Windows. If the two differ, do not use the file, and report it.

To install a new version, replace every file in your folder with the files from the new zip except the my/ folder, which you keep exactly as it is. Then ask Claude to "update my board"; it republishes the page to the same address, and your data stays. No git is needed.

During the pilot one maintainer builds each zip from a tagged commit in a private repository. packs/usmc/REVIEW.md records the pack review, and it is unsigned until a second reviewer signs it. Until then, treat the pack as not yet independently reviewed.

Untrusted text

Regulations, MARADMINs, the weekly feed, web pages, and your own board notes are data. The skills say so, and the assistant is told never to act on an instruction found inside them. If you see it do so, report it.

The watch feed

The weekly feed is produced in a separate repository by a scheduled job with one API key held as a repository secret, no tools, a strict output schema, and an allow list of official sources. The job cannot write to this repository. /watch checks each feed before it uses it: the file must parse, be no more than 8 days old, and state its window, its message count, and whether it was truncated or read titles only. A feed that fails a check changes nothing on your board.

Telemetry endpoint

The optional count and the optional lesson results go to one edge function (supabase/functions/ingest/index.ts, address in config.json as ingest_url and ping_url). It validates the shape, caps sizes, rate limits by a salted hash of the address, and writes with a server side key that never reaches a browser. The tables are closed to every other role. It serves no reads. A delete with a study token removes that token's lesson rows, and a delete with an install id removes that id's count, and nothing else. PRIVACY.md gives both commands.

Reporting

Email [email protected]. Include the version from config.json, what you saw, and how to repeat it. During the pilot one maintainer reads it; the realistic response window is a week, and we say so rather than promise 72 hours we cannot staff. Do not put your board data or anything personal in the report.

This page is rendered from SECURITY.md in the repository, pilot build 0.1.0.