)]}'
{
  "commit": "0f4a37bc3ac940dd98c7736e4a8e32c0163b49e0",
  "tree": "9a8952e5dadfc1b48980f413f3b61d85b9967c48",
  "parents": [
    "d00df0822b0fb107eb1bfd5062b0be79c96fa3da"
  ],
  "author": {
    "name": "Michael Brown",
    "email": "mcb30@ipxe.org",
    "time": "Thu Aug 06 11:35:08 2026 +0100"
  },
  "committer": {
    "name": "Michael Brown",
    "email": "mcb30@ipxe.org",
    "time": "Thu Aug 06 12:47:53 2026 +0100"
  },
  "message": "[doc] Add agent-facing instructions\n\nAdd the instructions that Claude developed for itself over the course\nof a very interactive week-long security audit of the iPXE codebase.\nThese instructions are to be used to guide any future use of AI agents\nto search for security issues in iPXE.\n\nAgents that follow these instructions are expected to surface only\nrelevant information, write up suitably minimalistic reports (unlike\nthe typical unguided AI slop that resulted in iPXE\u0027s current \"(Ab)use\nof AI\" policy), and guide submission through the appropriate channels\nthat have been set up and documented in the security policy.  Any\nAI-authored reports are directed towards the \"ipxe/aipxe\" sandbox\nrepository, which exists to provide a clear separation between\nhuman-generated and AI-generated content.\n\nGiven that repeated passes with Claude Opus 4.8 (and a cross-check\nwith Claude Fable) have converged to a clean state, it is expected\nthat publishing these instructions will lead to at most a trickle of\nsubmissions, and that any such submissions should end up being\ngenuinely useful.\n\nThese instructions were written by Claude (with many hours of guidance\nand refinement) and have not been modified, on the basis that an AI\nagent knows best about what documentation it will itself find useful.\nUnnecessary duplication has been avoided by documenting the key points\n(e.g. bounds contracts) within the code\u0027s own Doxygen comments for\nreference by both humans and agents, and ensuring that Claude\u0027s own\ninstructions refer and defer to this authoritative documentation.\n\nClaude has not authored any code that was committed as part of this\nweek-long project.  The AI agent instructions added by this commit\nremain the only AI-authored content present in the tree.  I have set\nmyself as the commit author (with an appropriate Authored-by credit\nfor Claude), written this commit message myself, and added my own\nsignoff, to confirm that I am the human owner taking long-term\nresponsibility for this contribution, regardless of its origin.\n\nAuthored-by: Claude Opus 4.8 \u003cnoreply@anthropic.com\u003e\nSigned-off-by: Michael Brown \u003cmcb30@ipxe.org\u003e\n",
  "tree_diff": [
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "e680e45438e224c55fe5f611bd668282b8556e72",
      "new_mode": 33188,
      "new_path": ".claude/skills/ipxe-security-review/SKILL.md"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "6f7b67a7e8dbad4661e14a84268918f3cb29ba7a",
      "new_mode": 33188,
      "new_path": "AGENTS.md"
    },
    {
      "type": "add",
      "old_id": "0000000000000000000000000000000000000000",
      "old_mode": 0,
      "old_path": "/dev/null",
      "new_id": "9af606c9e1d81f5905d55dc80d0b1414a5f4fb98",
      "new_mode": 33188,
      "new_path": "CLAUDE.md"
    }
  ]
}
