Skip to content

ShadowClaw 1.2.0

ShadowClaw now reports the four Kinetic Trust Protocol v2.0.0 Risk Factor inputs it can honestly observe, on the paths its telemetry already takes. It reports; it does not decide. No trust score is computed on the endpoint, no oracle is contacted, and nothing in shadowclaw/ktp/ is consulted by detection — which keeps "detect, don't enforce" a property of the architecture rather than a promise in the documentation.

Unobserved is maximum stress, never zero

The rule that shapes the implementation: every value is a stress term where 1 is maximum stress, and anything unobserved resolves to 1.0, never 0. A term reading zero when unmeasured would make silence and calm the same number, and a deployment could raise its own trust score by switching sensors off. An unknown signal therefore contributes the substitute rather than dropping out of the aggregation, so losing a feed always moves a factor toward stress.

That is ShadowClaw's own claim arriving from KTP's direction: the detector already refuses to let a dark plane look like a clean one. The same reasoning fixes a defect in _reap(), which had dropped silent processes outright and made a host ShadowClaw stopped watching indistinguishable from one that reported calm.

Attribution reworked alongside it

MAX_ANCESTRY_DEPTH is retired for depth-decayed attribution authority, and observed topology is reported as attributed/orphaned/ boot_persistent under attribution_state — deliberately not KTP's sponsored/independent/guarantor, which denote earned generation phase and would invert the meaning here.

The oracle is a separate, optional sidecar

The optional oracle sidecar lives in integrations/ktp-oracle/ with its own version, Python floor, and dependency set. The arrow between them points one way and is enforced rather than intended: a test fails the build if anything under shadowclaw/ imports a third-party module, checked both by walking the source and by importing the sensor in a fresh interpreter.

Read the coverage before the value

Dashboards must read ktp.degraded alongside any Risk Factor value: an unprivileged sensor floors adversarial_pressure at 0.714 because Endpoint Security needs root, and a panel alerting on the bare number fires forever. The DefenseClaw integration documents this.

Detection behavior is unchanged by this release: --verify passes all 31 scenarios.

Next