diff --git a/README.md b/README.md index dcf95e6..33597c3 100644 --- a/README.md +++ b/README.md @@ -6,6 +6,7 @@ CI tests license + npm dependencies

@@ -41,9 +42,8 @@ Objective -> Trust Route -> Consequence Preview -> Execution Authority -> | **3. Authority** | Is this exact execution allowed right now? | `pctr protect ` | ```bash -npm link ./packages/pctr # not on npm yet; link it from a clone -pctr init # discover agents and tools, write pctr.json -pctr scan # what consequences can they reach? +npx @blocksifr/pctr init # discover agents and tools, write pctr.json +npx @blocksifr/pctr scan # what consequences can they reach? ```

diff --git a/assets/pctr-scan.svg b/assets/pctr-scan.svg index e828d70..c8515e2 100644 --- a/assets/pctr-scan.svg +++ b/assets/pctr-scan.svg @@ -3,7 +3,7 @@ - pctr scan + npx @blocksifr/pctr scan PCTR diff --git a/packages/pctr/README.md b/packages/pctr/README.md index ab9671c..f774f4f 100644 --- a/packages/pctr/README.md +++ b/packages/pctr/README.md @@ -12,14 +12,13 @@ Objective -> Trust Route -> Consequence Preview -> Execution Authority -> pctr scan finds five agents, three tools and four potential actions, and reports one critical protected consequence: customers.delete can be reached through support-agent and admin-agent without independent execution authority -Not on npm yet — from a clone of this repo: - ```bash -npm link ./packages/pctr # then the bare `pctr` command works anywhere -pctr init # discover agents and tools, write pctr.json -pctr scan # what consequences can they reach? +npx @blocksifr/pctr init # discover agents and tools, write pctr.json +npx @blocksifr/pctr scan # what consequences can they reach? ``` +Or install it: `npm i -g @blocksifr/pctr`, then just `pctr init` and `pctr scan`. + No account. No network. Everything stays in `./pctr.json` and `./.pctr`. ## Share what you find diff --git a/packages/pctr/action.yml b/packages/pctr/action.yml index dcffc03..e4f50c2 100644 --- a/packages/pctr/action.yml +++ b/packages/pctr/action.yml @@ -21,7 +21,7 @@ inputs: version: description: 'Version of @blocksifr/pctr to run.' required: false - default: 'latest' + default: 'latest' # published on npm: https://www.npmjs.com/package/@blocksifr/pctr outputs: critical: diff --git a/packages/pctr/scripts/render-terminal-svg.mjs b/packages/pctr/scripts/render-terminal-svg.mjs index 596b434..8abe9cd 100644 --- a/packages/pctr/scripts/render-terminal-svg.mjs +++ b/packages/pctr/scripts/render-terminal-svg.mjs @@ -97,7 +97,7 @@ const svg = ` - pctr scan + npx @blocksifr/pctr scan ${body} diff --git a/packages/pctr/src/report.mjs b/packages/pctr/src/report.mjs index 3cbe35e..404e588 100644 --- a/packages/pctr/src/report.mjs +++ b/packages/pctr/src/report.mjs @@ -85,4 +85,4 @@ export function renderReport(graph, { title = 'PCTR consequence scan', includeBa } const footer = () => - `---\nScanned with [PCTR](${HOMEPAGE}) — \`pctr scan\`. Nothing left this machine.\n`; + `---\nScanned with [PCTR](${HOMEPAGE}) — \`npx @blocksifr/pctr scan\`. Nothing left this machine.\n`;