Add Bastion, a security engineer persona #77

Merged
robert merged 1 commit from process/security-persona into main 2026-09-03 23:38:09 +02:00
Owner

NFR-S1–S8 in REQUIREMENTS.md §2.5 have existed since the original planning round with no persona actively holding them — nobody's job was "does this leak, does this trust the wrong thing." This adds Bastion, an eighth persona, modeled on the existing seven in .claude/agents/.

Bastion owns four concrete surfaces, not a generic checklist:

  • The transport — PebbleKit 2's bound-service guarantee (D37, NFR-S8) vs. the PKJS pairing-token fallback (#16)
  • Untrusted input — GPX files arriving via the Android share sheet (#24): malformed XML, XXE, resource exhaustion
  • Permissions — ACCESS_BACKGROUND_LOCATION, BLUETOOTH_SCAN/CONNECT, requested only when needed with a plain-language rationale (NFR-S6)
  • Secrets and supply chain — NFR-S3/S7 (public repo, no committed keys), Gradle/pip/pebble-tool dependencies, the act_runner images

Uses the built-in security-review skill on diffs rather than re-deriving a checklist by hand, and is deliberately scoped down: most findings are tracked issues, not merge blockers — this is a hobby project, not a bank.

docs/TEAM.md roster and "why these eight" rationale updated to match.

https://claude.ai/code/session_01DAoXbRmJUf2uxNYBfdAXPt

NFR-S1–S8 in REQUIREMENTS.md §2.5 have existed since the original planning round with no persona actively holding them — nobody's job was "does this leak, does this trust the wrong thing." This adds **Bastion**, an eighth persona, modeled on the existing seven in `.claude/agents/`. Bastion owns four concrete surfaces, not a generic checklist: - **The transport** — PebbleKit 2's bound-service guarantee (D37, NFR-S8) vs. the PKJS pairing-token fallback (#16) - **Untrusted input** — GPX files arriving via the Android share sheet (#24): malformed XML, XXE, resource exhaustion - **Permissions** — `ACCESS_BACKGROUND_LOCATION`, `BLUETOOTH_SCAN`/`CONNECT`, requested only when needed with a plain-language rationale (NFR-S6) - **Secrets and supply chain** — NFR-S3/S7 (public repo, no committed keys), Gradle/pip/pebble-tool dependencies, the `act_runner` images Uses the built-in `security-review` skill on diffs rather than re-deriving a checklist by hand, and is deliberately scoped down: most findings are tracked issues, not merge blockers — this is a hobby project, not a bank. `docs/TEAM.md` roster and "why these eight" rationale updated to match. https://claude.ai/code/session_01DAoXbRmJUf2uxNYBfdAXPt
NFR-S1-S8 in REQUIREMENTS.md have existed since the original planning round
with no persona actively holding them. Bastion closes that gap: the
transport surface (PebbleKit bound services vs. the PKJS token fallback),
untrusted GPX/route input from the share sheet, the Android permission
model, and secrets/supply chain.

Modeled on the existing seven personas in .claude/agents/. Update
docs/TEAM.md's roster and rationale accordingly.

Claude-Session: https://claude.ai/code/session_01DAoXbRmJUf2uxNYBfdAXPt
robert merged commit a13f6e80f8 into main 2026-09-03 23:38:09 +02:00
Sign in to join this conversation.
No description provided.