microsoft / microsoft/hve-core

feat: add EV-05 and EV-06 destination evidence

Open
#2,935 0 comments 1 reaction 1 assignee Claimed by @WilliamBerryiii View on GitHub
copilot design-thinking evals feature priority-3
Dominant language
Python
Stars
1.5k
Forks
301
Avg merge
3d 3h
Merged PRs (30d)
92

Description

## Issue Description

Add contained, executable evidence for the EV-05 Design Thinking destination and telemetry gaps and the EV-06 Mural trust-boundary gaps. Deliver both clusters in one reviewable branch while preserving their distinct runtime, validation, and evidence ceilings.

## Scoped Findings

### EV-05: Design Thinking destinations and telemetry

- `RAI-P08-G02-A077-C01`: Design Thinking telemetry decision evidence
- `RAI-P08-G03-A125-C01`: Figma export consent, sequencing, and partial-failure evidence
- `RAI-P08-G04-A185-C01`: UX artifact evidence classes and destination-intent evidence
- `RAI-P08-G04-A188-C01`: residual Copilot telemetry model and helper-verdict evidence

### EV-06: Mural boundaries

- `RAI-P08-G02-A081-C01`: readiness and bootstrap evidence
- `RAI-P08-G02-A082-C01`: destination routing evidence
- `RAI-P08-G02-A083-C01`: human-record protection evidence
- `RAI-P08-G02-A084-C01`: credential and redaction evidence
- `RAI-P08-G02-A085-C01`: seeding and recovery evidence
- `RAI-P08-G02-A086-C01`: constrained writeback evidence
- `RAI-P08-G02-A087-C01`: destination-aware hydration evidence
- `RAI-P08-G04-A191-C01`: dispatch-time scope enforcement evidence

These findings are evidence-acquisition gaps. They do not establish an observed privacy incident, successful external write, stakeholder outcome, native-service conformance, or production effectiveness.

## Ordered Work Packages

1. Correct Figma access, mutable usage-limit, tool-classification, and write-confirmation guidance.
2. Add contained EV-05 local Design Thinking, Figma MCP, and residual Copilot telemetry evidence.
3. Add an offline EV-06 finding-keyed scenario contract and deny-by-default test isolation.
4. Add a local Mural readiness doctor, central dispatch-time scope enforcement, default human-record protection, and constrained writeback.
5. Add validated destination-registry loading, explicit action-intent dispatch through injected adapters, destination-aware hydration, and deterministic recovery behavior.
6. Align Mural callers, skill documentation, security boundaries, generated references, dependencies, and validation evidence.

## Evidence Ceilings

- Do not contact live Figma, Mural, or downstream destinations.
- Do not authenticate, use credentials, access a real keyring, mutate real boards or settings, process real personal data, or execute cloud operations.
- Synthetic protocol and in-memory adapter evidence proves only local routing, authorization, containment, sequencing, state transitions, and reporting.
- Local PASS does not establish native Mural or Figma behavior, real destination loop closure, production telemetry effectiveness, privacy approval, or qualified Responsible AI acceptance.
- Treat widget, API, registry, and tool content as untrusted data. Preserve human-authored widget text while redacting credential-channel material from diagnostic and evidence sinks.

## Validation Lanes

- Focused Mural pytest and Ruff with temporary files, injected stores, fake HTTP, fake browser, and in-memory adapters
- Finding-keyed scenario-matrix validation and sanitized local evidence aggregation
- Vally schema, safety, generator-drift, instruction, and caller-behavior checks
- Documentation generation, plugin parity, Markdown, frontmatter, skill structure, public-feed, and dependency-lock checks
- Existing Copilot telemetry fast tests and focused MCP protocol tests
- Model-backed behavior and native/runtime lanes only when their separate prerequisites are available

Unavailable credentials, services, Docker, model execution, or native environments are reported as pending, blocked, or unavailable. Their absence is not a passing result.

## Reviewers

- `@microsoft/edge-ai-core-dev` through CODEOWNERS
- Mural skill, OAuth, credential-backend, transport, seeding, writeback, and destination owners
- DT Coach, Responsible AI Planner, and UX UI Designer owners
- Design Thinking telemetry, UX evidence-contract, and Figma integration owners
- Copilot telemetry package and Python runtime owners
- Privacy, security, dependency, eval, and qualified Responsible AI reviewers

No human-review checkbox or qualified-review outcome is completed by this issue.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.