Local implementation record¶
Approved scope: local audit, rename, stability fixes, MCP, Docker, plugins and release preparation. Publisher hhftechnology; version 0.6.0.
All coding remains in the existing workspace. Existing documentation/assets were preserved and updated in place. Git remote remains the existing owner/repository. No commits, staging, transfer, push, image/package uploads or marketplace submissions were performed.
Completed implementation¶
- Clean distribution/CLI/import/configuration/environment rename, including hidden
.env.example, CI, docs, branding and canonical bundled skill. - TLS, input/filter, rate-limit, retry, cache, metadata, shutdown and download fixes.
- Official SDK stdio MCP with 30 tools, scoped sessions, opaque PDF IDs/resources, optional contained export, default 50 results and maximum 100.
- Python 3.12 non-root container, hashed runtime dependencies, bundled OCR/DuckDB assets, cache/output mounts, stderr logs and Toolkit image metadata.
- Generated Claude/Codex/Grok packages and self-hosted indexes, release gates, protected trusted publishing workflows, SBOM/provenance generation and post-publication pinned submission generation.
- Fresh read-only reviewer found three edge cases; all corrected with regression tests and confirmed resolved by the reviewer.
Validation on 4 October 2026¶
| Check | Result |
|---|---|
| Original baseline | 350 tests and lint passed |
| Full Python 3.11.17 suite | 383 passed |
| Full Python 3.12.15 suite | 383 passed |
| Full Python 3.13.16 suite | 383 passed |
| Ruff lint and formatting | Passed |
| Strict MkDocs build | Passed |
| Wheel/sdist build, Twine metadata | Passed |
| Clean base wheel install and bundled skill | Passed; former import unavailable |
| Clean wheel optional extras | All extras installed; dependency check passed |
| Plugin generation consistency and three ZIPs | Passed |
| Codex local marketplace and plugin install | Passed, version 0.6.0 |
| Local Docker build, non-root UID and restart cache mount | Passed |
| Docker MCP stdio, 30 tools, errors, live SCI PDF/resource | Passed |
| Toolkit catalog and profile/gateway discovery | Passed: 30 tools and one PDF resource template |
| Python hashed dependency audit | No known vulnerabilities |
| Container HIGH/CRITICAL scan after OS upgrades | 44 HIGH findings without fixes; CI gates fixable HIGH/CRITICAL findings |
| Archive representative live checks | 7/7 passed |
| HC Services representative live checks | 8/8 passed |
| District courts representative live checks | 5/5 passed |
| SCI and judgments portal search/PDF checks | Passed |
| Calcutta portal verified TLS | Blocked: certificate chain cannot validate |
| Calcutta explicit TLS exception search/PDF | Passed |
| Known Calcutta case alternative route | Judgments portal passed; HC portal PDF unavailable/non-PDF |
| Claude/Grok application install | Pending; CLIs unavailable |
| Public publication/submission/acceptance | Pending; owner performs final stage |
The final matrix includes the judgment page default of 50 and the Calcutta-only TLS exception. No portal error was silently bypassed and no vulnerability IDs were allow-listed. CI does not fail on vulnerabilities without an available fix. SBOM is in dist/; release provenance is generated by the protected publishing workflow after publication, not fabricated locally.
See the owner release checklist.
Prompt library and Compose follow-up¶
Expanded docs/lawyers/prompts.md with a task chooser, step-by-step case research, advocate/cause-list workflows, recent judgments, focused archive searches, PDF comparisons/exports, language preferences and recovery prompts. Added compose.yaml with stdio MCP, a non-root user, persistent cache/output volumes, resource bounds and explicit Calcutta-only TLS configuration. Documented client JSON, Windows paths, local builds, post-publication pulling and optional host output mounts.
Verified Compose configuration/build, 30-tool discovery, structured errors, live SCI PDF/resource delivery, non-root volume writes and persistence across runs. Strict documentation build and smoke-script lint/formatting passed. CI now checks Compose configuration and MCP startup alongside the direct image. Existing publication blockers above remain unchanged; no publication occurred.