Publication Sanitization Gate
skill · created
Evidence record
- What is verified
- Uses in published workflows: 2
- Revision
- Version 0.1.5
- Validation status
- Public-sanitized publication; no independent validation is claimed.
What this is and why
Turns the sanitization rules into an automatic, blocking CI check on every public publication path. Two detector layers work together: a version-pinned generic secret scanner and a project denylist of internal identifiers, mirrored into CI as patterns rather than values. The check fails closed, an allowlist entry requires an in-repo justification with an expiry, and the gate is mutation-proven: a planted forbidden token must turn CI red, because a gate that has never been red proves nothing.
Where it was applied and what it helped deliver
- Building talomnia.com with Talomnia — how this site was built by the system it describes — TALO-0003, TALO-0005, TALO-0009, TALO-0019, TALO-0024, TALO-0025, TALO-0026, TALO-0027, TALO-0028, TALO-0029, TALO-0030, TALO-0031, TALO-0032, TALO-0033, TALO-0034, TALO-0036, TALO-0037, TALO-0038, TALO-0043, TALO-0051, TALO-0052, TALO-0054, TALO-0059, TALO-0062, TALO-0063, TALO-0067, TALO-0102, TALO-0104, TALO-0117
- Workflow — how the Talomnia Workforce market research was produced — TALO-0035
Relations
- Uses: derived-from
- sanitized-projection
- Uses: part-of
- repo-provisioning-sanitized
- Used by: uses
- projection-pipelinerepo-provisioning-sanitizedstage-1-repos
- Required by: selects
- talo-0024-workflow0-evidence
Metadata and provenance
- id
- tal-skill-sanitization-gate
- type
- skill
- version
- 0.1.5
- origin
- created in Talomnia
- lifecycle
- public_sanitized
- tags
- security, tz-3-3, ci
The source is the private knowledge repository; only the sanitized public projection reaches this site.
verified · tal-skill-sanitization-gate · v0.1.5