Skip to content

fix(identity): bind candidate_name to fictional profile, off MCP surface - #21

Merged
David-BS merged 1 commit into
mainfrom
fix/c1-identity-binding
Jun 28, 2026
Merged

fix(identity): bind candidate_name to fictional profile, off MCP surface#21
David-BS merged 1 commit into
mainfrom
fix/c1-identity-binding

Conversation

@David-BS

Copy link
Copy Markdown
Owner

The four md-generator tools (strategic_playbook, application_summary, interview_prep, quick_reference) exposed candidate_name as a free MCP input, letting the agent compose the candidate identity from its own memory -- a PII risk: real identities instead of the fictional Robin Mercier.

Remove the channel on all four: candidate_name leaves the input surface (JSON schema properties + required AND the tool-description prose) and is injected from CANDIDATE_PROFILE at payload composition, where the profile wins over any caller value. Single binding location, destined to become the deployment MCP resource like sender_*. cover_letter was already bound; unchanged.

Add falsify-first structural floor guards and an observed end-to-end test rendering all five deliverables.

The four md-generator tools (strategic_playbook, application_summary, interview_prep, quick_reference) exposed candidate_name as a free MCP input, letting the agent compose the candidate identity from its own memory -- a PII risk: real identities instead of the fictional Robin Mercier.

Remove the channel on all four: candidate_name leaves the input surface (JSON schema properties + required AND the tool-description prose) and is injected from CANDIDATE_PROFILE at payload composition, where the profile wins over any caller value. Single binding location, destined to become the deployment MCP resource like sender_*. cover_letter was already bound; unchanged.

Add falsify-first structural floor guards and an observed end-to-end test rendering all five deliverables.
@David-BS
David-BS merged commit e7ea9cc into main Jun 28, 2026
6 checks passed
@David-BS
David-BS deleted the fix/c1-identity-binding branch June 28, 2026 11:21
David-BS added a commit that referenced this pull request Jun 28, 2026
Couples manifest.version and chain_core.SERVER_VERSION so the frozen-server T0 parity assert (serverInfo.version == manifest) stays green. Carries the c1 identity-binding fix (PR #21) under a distinct version, separating this build from the pre-c1 public 0.2.1.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant