threadctx-dev
Summary
2 repositories give instructions to AI coding agents (AGENTS.md (2), Claude Code (2), Cursor (2), GitHub Copilot (2)); 2 have none.
| Control | Status | Result |
|---|---|---|
| TC-01 AI coding agents and their tools are inventoried | Evidenced | 4 repositories scanned; 6 agent instruction or configuration files and 2 MCP servers inventoried across 2 repositories (see the inventory). |
| TC-02 Secrets are kept out of agent instructions and tool configuration | Met | Tested on 2 repositories with agent context; no open findings. |
| TC-03 Agent instructions are free of hidden or injected content | Met | Tested on 2 repositories with agent context; no open findings. |
| TC-04 Agents are not told to bypass quality and security checks | Met | Tested on 2 repositories with agent context; no open findings. |
| TC-05 Third-party agent tools are pinned and authenticated | Needs attention | Tested on 2 repositories; 2 open findings in 1 repository. |
| TC-06 Agent instructions have owners and reviewed changes | Met | Tested on 2 repositories with agent context; no open findings. |
| TC-07 Agent instructions are accurate and consistent | Gap | Tested on 2 repositories; 3 open findings (1 blocking) in 1 repository. |
| TC-08 Agent context is monitored over time | Not evidenced | This is the first audit in this folder, so there is no earlier run to compare with. Run the audit on a schedule (Team plan) to evidence ongoing monitoring. |
Method
The repositories of threadctx-dev were listed through the GitHub API with the operator's own token. For each repository, the files that AI coding agents read (AGENTS.md, CLAUDE.md, Cursor rules, GitHub Copilot instructions, Gemini files, MCP configuration) and the manifests they refer to were fetched and analysed on the operator's machine. No repository content was sent to threadctx or any third party. Each control is tested against the deterministic rules listed under it; a rule's false-positive rate is published at threadctx.dev/rules. Findings that the repository owners suppressed in configuration are excluded and remain visible in audit.json.
Status meanings. Met: tested, no open findings. Evidenced: the audit itself provides the evidence. Needs attention: non-blocking findings, or not yet evidenced. Gap: at least one blocking finding.
Controls
TC-01 AI coding agents and their tools are inventoried Evidenced
4 repositories scanned; 6 agent instruction or configuration files and 2 MCP servers inventoried across 2 repositories (see the inventory).
TC-02 Secrets are kept out of agent instructions and tool configuration Met
Tested on 2 repositories with agent context; no open findings.
TC-03 Agent instructions are free of hidden or injected content Met
Tested on 2 repositories with agent context; no open findings.
TC-04 Agents are not told to bypass quality and security checks Met
Tested on 2 repositories with agent context; no open findings.
TC-05 Third-party agent tools are pinned and authenticated Needs attention
Tested on 2 repositories; 2 open findings in 1 repository.
Repositories with findings: threadctx-dev/threadctx-mcp
TC-06 Agent instructions have owners and reviewed changes Met
Tested on 2 repositories with agent context; no open findings.
TC-07 Agent instructions are accurate and consistent Gap
Tested on 2 repositories; 3 open findings (1 blocking) in 1 repository.
Repositories with findings: threadctx-dev/agent-context-demo
TC-08 Agent context is monitored over time Not evidenced
This is the first audit in this folder, so there is no earlier run to compare with. Run the audit on a schedule (Team plan) to evidence ongoing monitoring.
Framework cross-reference
| Framework | Reference | Name | Control | Status |
|---|---|---|---|---|
| SOC 2 | CC6.1 | Logical access: inventory of information assets | TC-01 | Evidenced |
| SOC 2 | CC6.1 | Logical access: protection of credentials | TC-02 | Met |
| SOC 2 | CC6.8 | Prevent or detect unauthorised or malicious software | TC-03 | Met |
| SOC 2 | CC8.1 | Change management: changes are tested before implementation | TC-04 | Met |
| SOC 2 | CC9.2 | Risks from vendors and business partners are assessed and managed | TC-05 | Needs attention |
| SOC 2 | CC8.1 | Change management: changes are authorised and approved | TC-06 | Met |
| SOC 2 | CC2.1 | Relevant, quality information supports internal control | TC-07 | Gap |
| SOC 2 | CC4.1 | Ongoing and separate evaluations | TC-08 | Not evidenced |
| SOC 2 | CC7.1 | Detection of configuration changes and vulnerabilities | TC-08 | Not evidenced |
| ISO/IEC 27001:2022 | A.5.9 | Inventory of information and other associated assets | TC-01 | Evidenced |
| ISO/IEC 27001:2022 | A.5.17 | Authentication information | TC-02 | Met |
| ISO/IEC 27001:2022 | A.8.12 | Data leakage prevention | TC-02 | Met |
| ISO/IEC 27001:2022 | A.8.7 | Protection against malware | TC-03 | Met |
| ISO/IEC 27001:2022 | A.8.28 | Secure coding | TC-03 | Met |
| ISO/IEC 27001:2022 | A.8.29 | Security testing in development and acceptance | TC-04 | Met |
| ISO/IEC 27001:2022 | A.5.21 | Managing information security in the ICT supply chain | TC-05 | Needs attention |
| ISO/IEC 27001:2022 | A.8.32 | Change management | TC-06 | Met |
| ISO/IEC 27001:2022 | A.8.4 | Access to source code | TC-06 | Met |
| ISO/IEC 27001:2022 | A.8.9 | Configuration management | TC-07 | Gap |
| ISO/IEC 27001:2022 | A.8.16 | Monitoring activities | TC-08 | Not evidenced |
| ISO/IEC 42001:2023 | A.4.4 | Tooling resources | TC-01 | Evidenced |
| ISO/IEC 42001:2023 | A.6.2.4 | AI system verification and validation | TC-04 | Met |
| ISO/IEC 42001:2023 | A.10.3 | Suppliers | TC-05 | Needs attention |
| ISO/IEC 42001:2023 | A.6.2.7 | AI system technical documentation | TC-07 | Gap |
| NIST AI RMF 1.0 | GOVERN 1.6 | Mechanisms are in place to inventory AI systems | TC-01 | Evidenced |
| NIST AI RMF 1.0 | MEASURE 2.7 | AI system security and resilience are evaluated | TC-02 | Met |
| NIST AI RMF 1.0 | MEASURE 2.7 | AI system security and resilience are evaluated | TC-03 | Met |
| NIST AI RMF 1.0 | GOVERN 6.1 | Policies address risks from third-party entities | TC-05 | Needs attention |
| NIST AI RMF 1.0 | GOVERN 2.1 | Roles and responsibilities are documented | TC-06 | Met |
| NIST AI RMF 1.0 | MAP 2.2 | Knowledge limits and how outputs are used are documented | TC-07 | Gap |
| NIST AI RMF 1.0 | MANAGE 4.1 | Post-deployment monitoring plans are implemented | TC-08 | Not evidenced |
Inventory
Every agent instruction or configuration file and MCP server found. The same data is in inventory.csv.
| Repository | Agents | Files | MCP servers |
|---|---|---|---|
| threadctx-dev/agent-context-demo | AGENTS.md, Claude Code, Cursor, GitHub Copilot | .cursor/rules/style.mdc AGENTS.md CLAUDE.md | — |
| threadctx-dev/threadctx-mcp | AGENTS.md, Claude Code, Cursor, GitHub Copilot | .cursor/rules/threadctx.mdc AGENTS.md CLAUDE.md | threadctx (stdio), threadctx (stdio) |
Review and sign-off
For the control owner's records.