Skip to content

Latest commit

 

History

History
39 lines (27 loc) · 1.65 KB

File metadata and controls

39 lines (27 loc) · 1.65 KB

PF-Core Bridge

SCOPE grants export to PF-Core runtime obligations that specify permitted and blocked tools.

Contract version: pf-core-v0.5. Full field mapping: external_integration_contracts.md.

Export

scope export pf --grant grant.json --out pf_obligation.json --validate

Optional live validation when a PF-Core checkout is configured:

export PF_CORE_REPO_PATH=/path/to/pf-core
scope export pf --grant grant.json --out pf_obligation.json --validate --live

Sample output shape: adapters/pf_core/examples/pf_obligation.json (regenerate with a live grant for current contract fields).

Obligation fields

  • obligation_version — pf-core-v0.5
  • permitted_tools — tools runtime may invoke
  • blocked_tools — tools that must remain blocked
  • approved_scope — SCOPE approval scope
  • constraints — protocol version, single-use flags
  • expiration — invalidation triggers
  • Signature fields — copied when present on signed grant
  • action_chain_id / pf_trace_id / pf_trace_hash — round-tripped for runtime evidence reconstruction (SCOPE-AS-05)

PF-Core verifies that runtime traces respect these obligations. SCOPE defines permission; PF-Core verifies compliance. OVK remains out-of-repo for this release (see ADR-0007).

Related documentation