docs: update project documentation for v1.72.0.0

docs/skills.md: Third-Party Web Actions subsection under /ship (Aside
recommended driver, consent rules, credential boundaries). BROWSER.md:
"Aside and third-party drives" subsection under Real-browser mode + ToC
entry, including the no-gstack-side-audit-trail caveat (ship adversarial
finding 12). TODOS.md: mark the finding-12 doc note done.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-08-28 04:58:28 +00:00
co-authored by Claude Fable 5
parent d40f98660c
commit 99714e2a15
3 changed files with 26 additions and 4 deletions
+4 -3
View File
@@ -471,9 +471,10 @@ directory path got.
**Why:** The symlink-swap class fixed for directories on this branch remains
open for the files inside them (ship adversarial review, finding 5).
Also note for docs: drives through Aside leave no gstack-side audit trail
(no egress receipts, no browse-daemon logs) — the audit trail lives in Aside;
worth a line in BROWSER.md when this area is next touched (finding 12).
Docs note (finding 12) — done in the v1.72.0.0 doc pass: BROWSER.md
§ "Aside and third-party drives" now records that Aside drives leave no
gstack-side audit trail (no egress receipts, no browse-daemon logs); the
audit trail lives in Aside.
**Effort:** S (human ~half day / CC+gstack ~20 min)
**Priority:** P3