Marketplace

Session Signals baseline rules

unrated

Unrated (not enough evidence yet)

Signature verified (ed25519)no evidence yet
Installs (k-anonymous)no evidence yet
Install success rateno evidence yet
Post-install survivalno evidence yet

Rating starts once every component has real evidence. Missing evidence is stated, never faked as zero.

repoops/signals-baseline · pack · by repoops

The Session Signals baseline detection rules as an inspectable, versioned rule pack: signals-rules JSON files in the data-dir loader format (credential exposure, risky commands, prompt-injection markers, plus a false-positive ignore pack that drops well-known fake keys, already-masked values, and fixture context), generated from the compiled-in baseline in lib/session-signals-rules.mjs so the pack can never drift from the code. Install lands the files in the data dir's signals-rules/ only after approval on the Marketplace tab; the scanner merges them over the baseline on the next scan. Rule updates arrive as versioned, inspectable, approval-gated packs, never an opaque auto-feed.

Install
npx repoops

https://www.repoops.ai/marketplace/install/repoops/signals-baseline

The link opens this pack. The command installs the RepoOps app and carries no pack id, so the two are not the same artifact. Installing a pack by id checks its ed25519 signature against your repo's trust list and lands it HELD for your approval, so nothing runs until you approve. That path is built but is not in a shipped command yet.

What install does.

  1. Resolves this id. The signed-pack path (fetch, ed25519 signature checked against your repo's trust list, no skip path for a tampered or unsigned pack) is built but is not in a shipped command yet: npx repoops installs the desktop app, not a pack.
  2. Installed from the app's Marketplace tab, a first-party catalog entry comes from the copy already on this machine, so nothing is fetched and there is no signature to verify.
  3. Lands the pack HELD as one inert proposal. Nothing runs, nothing edits a file.
  4. You approve or reject it on your Marketplace tab. Approval runs no code: it keeps the note, and for a signal-rule pack it writes that pack's regex rules where your next scan reads them. Reject deletes the note and writes nothing.