Skip to content

docs: explain Community CLI canaries and detection use cases - #1

Open
andy-smith-tracebit wants to merge 1 commit into
mainfrom
codex/improve-community-cli-readme
Open

andy-smith-tracebit wants to merge 1 commit into
mainfrom
codex/improve-community-cli-readme

Conversation

@andy-smith-tracebit

Copy link
Copy Markdown

Description

The Community CLI README previously listed supported canaries and installation commands but gave little context about what triggers an alert or when to use the tool.

  • Add explanations of credential canaries, supported deployment locations, and use cases involving stolen credentials and AI agents.
  • Include approved anonymised detection examples and link to Synthesia's published experience and Tracebit's Context Bombs research. Cloud infrastructure examples are explicitly distinguished from workstation CLI capabilities.
  • Keep account creation, installation, and deployment instructions near the top. Preserve the release badge, latest-release link, API documentation, OpenAPI specification, and MIT license link.
  • Describe the actual deployment workflow: local AWS and SSH files, browser-assisted cookie placement, manual password-manager placement, canary emails, and background refresh for supported types.
  • Clarify that credential alerts require attempted use and that an absence of alerts does not prove an agent stayed within scope.

Only the README changes; CLI behavior is unchanged.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Code Coverage

Package Line Rate Branch Rate Health
tracebit 40% 33% ➖
Summary 40% (2895 / 7183) 33% (354 / 1070) ➖

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant