Security coverage and capture

Understand which traffic can be governed and what recorded evidence means.

Make a device key

Run this on the computer where your agent works. It needs Node 24 or later. It runs the published @specify-work/connector package, makes the device's key in a private folder and prints only its public half.

The package's npm page lists every command and what each one needs.

@specify-work/connector on npm

Command · Terminal
npx @specify-work/connector security keygen ~/.specify/security

Coverage follows the configured route

Security applies to traffic explicitly routed through a configured governed adapter or proxy. MCP connectivity does not establish universal interception, and a configured client is not an operating-system sandbox.

Confirm the exact client, version, platform and enabled capability in the deployment’s coverage record before relying on enforcement. A device heartbeat or reported policy version alone is not independent proof of enforcement.

Metadata is not a transcript

Metadata capture hashes tool, path and destination identifiers and redacts argument values. It is not a readable transcript. Rich content evidence requires explicit authorized submission and current file grants.

An evaluation or approval records a decision. Execution and delivered outputs require their own evidence. Review the applicable failure behavior and capture policy before enabling an adapter.