AI coding agent governance · evidence pack

threadctx-dev

Configuration of AI coding agents across the organisation's GitHub repositories
Generated2026-10-06 17:22 UTC
Toolthreadctx 0.3.0 · rules 2026.10.1
Scope4 of 4 repositories
Frameworks referencedSOC 2, ISO/IEC 27001:2022, ISO/IEC 42001:2023, NIST AI RMF 1.0

Summary

5/8controls met or evidenced
2need attention
1gaps (blocking findings)
6agent files inventoried
2MCP servers inventoried

2 repositories give instructions to AI coding agents (AGENTS.md (2), Claude Code (2), Cursor (2), GitHub Copilot (2)); 2 have none.

ControlStatusResult
TC-01 AI coding agents and their tools are inventoriedEvidenced4 repositories scanned; 6 agent instruction or configuration files and 2 MCP servers inventoried across 2 repositories (see the inventory).
TC-02 Secrets are kept out of agent instructions and tool configurationMetTested on 2 repositories with agent context; no open findings.
TC-03 Agent instructions are free of hidden or injected contentMetTested on 2 repositories with agent context; no open findings.
TC-04 Agents are not told to bypass quality and security checksMetTested on 2 repositories with agent context; no open findings.
TC-05 Third-party agent tools are pinned and authenticatedNeeds attentionTested on 2 repositories; 2 open findings in 1 repository.
TC-06 Agent instructions have owners and reviewed changesMetTested on 2 repositories with agent context; no open findings.
TC-07 Agent instructions are accurate and consistentGapTested on 2 repositories; 3 open findings (1 blocking) in 1 repository.
TC-08 Agent context is monitored over timeNot evidencedThis is the first audit in this folder, so there is no earlier run to compare with. Run the audit on a schedule (Team plan) to evidence ongoing monitoring.

Method

The repositories of threadctx-dev were listed through the GitHub API with the operator's own token. For each repository, the files that AI coding agents read (AGENTS.md, CLAUDE.md, Cursor rules, GitHub Copilot instructions, Gemini files, MCP configuration) and the manifests they refer to were fetched and analysed on the operator's machine. No repository content was sent to threadctx or any third party. Each control is tested against the deterministic rules listed under it; a rule's false-positive rate is published at threadctx.dev/rules. Findings that the repository owners suppressed in configuration are excluded and remain visible in audit.json.

Status meanings. Met: tested, no open findings. Evidenced: the audit itself provides the evidence. Needs attention: non-blocking findings, or not yet evidenced. Gap: at least one blocking finding.

Controls

TC-01 AI coding agents and their tools are inventoried Evidenced

The organisation knows which repositories give instructions to which AI coding agents, and which MCP servers those agents can call.

4 repositories scanned; 6 agent instruction or configuration files and 2 MCP servers inventoried across 2 repositories (see the inventory).

SOC 2 CC6.1ISO/IEC 27001:2022 A.5.9ISO/IEC 42001:2023 A.4.4NIST AI RMF 1.0 GOVERN 1.6

TC-02 Secrets are kept out of agent instructions and tool configuration Met

No credential, token or key is written into a file that AI agents read or into an MCP server configuration.

Tested on 2 repositories with agent context; no open findings.

SOC 2 CC6.1ISO/IEC 27001:2022 A.5.17ISO/IEC 27001:2022 A.8.12NIST AI RMF 1.0 MEASURE 2.7

TC-03 Agent instructions are free of hidden or injected content Met

Instruction files contain no invisible or bidirectional characters, encoded payloads, or instructions to download and run remote code.

Tested on 2 repositories with agent context; no open findings.

SOC 2 CC6.8ISO/IEC 27001:2022 A.8.7ISO/IEC 27001:2022 A.8.28NIST AI RMF 1.0 MEASURE 2.7

TC-04 Agents are not told to bypass quality and security checks Met

No instruction tells an agent to skip tests, disable linters or checks, or hide changes from review.

Tested on 2 repositories with agent context; no open findings.

SOC 2 CC8.1ISO/IEC 27001:2022 A.8.29ISO/IEC 42001:2023 A.6.2.4

TC-05 Third-party agent tools are pinned and authenticated Needs attention

MCP servers, skills and rule packs are pinned to a version or hash, and remote servers use TLS and authentication.

Tested on 2 repositories; 2 open findings in 1 repository.

Repositories with findings: threadctx-dev/threadctx-mcp

SOC 2 CC9.2ISO/IEC 27001:2022 A.5.21ISO/IEC 42001:2023 A.10.3NIST AI RMF 1.0 GOVERN 6.1

TC-06 Agent instructions have owners and reviewed changes Met

Every instruction file is covered by CODEOWNERS, and generated files are changed only at their source.

Tested on 2 repositories with agent context; no open findings.

SOC 2 CC8.1ISO/IEC 27001:2022 A.8.32ISO/IEC 27001:2022 A.8.4NIST AI RMF 1.0 GOVERN 2.1

TC-07 Agent instructions are accurate and consistent Gap

Instructions match the repository (paths, scripts, package manager, versions) and do not contradict each other across files and tools.

Tested on 2 repositories; 3 open findings (1 blocking) in 1 repository.

Repositories with findings: threadctx-dev/agent-context-demo

SOC 2 CC2.1ISO/IEC 27001:2022 A.8.9ISO/IEC 42001:2023 A.6.2.7NIST AI RMF 1.0 MAP 2.2

TC-08 Agent context is monitored over time Not evidenced

The audit is repeated and compared with the previous run, so regressions are found and followed up.

This is the first audit in this folder, so there is no earlier run to compare with. Run the audit on a schedule (Team plan) to evidence ongoing monitoring.

SOC 2 CC4.1SOC 2 CC7.1ISO/IEC 27001:2022 A.8.16NIST AI RMF 1.0 MANAGE 4.1

Framework cross-reference

FrameworkReferenceNameControlStatus
SOC 2CC6.1Logical access: inventory of information assetsTC-01Evidenced
SOC 2CC6.1Logical access: protection of credentialsTC-02Met
SOC 2CC6.8Prevent or detect unauthorised or malicious softwareTC-03Met
SOC 2CC8.1Change management: changes are tested before implementationTC-04Met
SOC 2CC9.2Risks from vendors and business partners are assessed and managedTC-05Needs attention
SOC 2CC8.1Change management: changes are authorised and approvedTC-06Met
SOC 2CC2.1Relevant, quality information supports internal controlTC-07Gap
SOC 2CC4.1Ongoing and separate evaluationsTC-08Not evidenced
SOC 2CC7.1Detection of configuration changes and vulnerabilitiesTC-08Not evidenced
ISO/IEC 27001:2022A.5.9Inventory of information and other associated assetsTC-01Evidenced
ISO/IEC 27001:2022A.5.17Authentication informationTC-02Met
ISO/IEC 27001:2022A.8.12Data leakage preventionTC-02Met
ISO/IEC 27001:2022A.8.7Protection against malwareTC-03Met
ISO/IEC 27001:2022A.8.28Secure codingTC-03Met
ISO/IEC 27001:2022A.8.29Security testing in development and acceptanceTC-04Met
ISO/IEC 27001:2022A.5.21Managing information security in the ICT supply chainTC-05Needs attention
ISO/IEC 27001:2022A.8.32Change managementTC-06Met
ISO/IEC 27001:2022A.8.4Access to source codeTC-06Met
ISO/IEC 27001:2022A.8.9Configuration managementTC-07Gap
ISO/IEC 27001:2022A.8.16Monitoring activitiesTC-08Not evidenced
ISO/IEC 42001:2023A.4.4Tooling resourcesTC-01Evidenced
ISO/IEC 42001:2023A.6.2.4AI system verification and validationTC-04Met
ISO/IEC 42001:2023A.10.3SuppliersTC-05Needs attention
ISO/IEC 42001:2023A.6.2.7AI system technical documentationTC-07Gap
NIST AI RMF 1.0GOVERN 1.6Mechanisms are in place to inventory AI systemsTC-01Evidenced
NIST AI RMF 1.0MEASURE 2.7AI system security and resilience are evaluatedTC-02Met
NIST AI RMF 1.0MEASURE 2.7AI system security and resilience are evaluatedTC-03Met
NIST AI RMF 1.0GOVERN 6.1Policies address risks from third-party entitiesTC-05Needs attention
NIST AI RMF 1.0GOVERN 2.1Roles and responsibilities are documentedTC-06Met
NIST AI RMF 1.0MAP 2.2Knowledge limits and how outputs are used are documentedTC-07Gap
NIST AI RMF 1.0MANAGE 4.1Post-deployment monitoring plans are implementedTC-08Not evidenced

Inventory

Every agent instruction or configuration file and MCP server found. The same data is in inventory.csv.

RepositoryAgentsFilesMCP servers
threadctx-dev/agent-context-demoAGENTS.md, Claude Code, Cursor, GitHub Copilot.cursor/rules/style.mdc AGENTS.md CLAUDE.md—
threadctx-dev/threadctx-mcpAGENTS.md, Claude Code, Cursor, GitHub Copilot.cursor/rules/threadctx.mdc AGENTS.md CLAUDE.mdthreadctx (stdio), threadctx (stdio)

Review and sign-off

For the control owner's records.

Reviewed by (name, role)
Date
Follow-up ticket(s)
Next review due
Important. threadctx produces evidence about AI coding agent configuration. It is not an attestation, certification or audit opinion. Framework references show where the evidence is commonly relevant; your auditor decides whether it is sufficient for a control.