Authorship¶
ShadowClaw is the work of Mike Storm, Distinguished Engineer, CCIE Security 13847. Its source headers, runtime metadata, CLI banner, and telemetry record the provenance of official ShadowClaw builds.
The threat this exists for¶
The author statements in every source file and the SHA-256 checksum in shadowclaw/authorship.py are a deliberate, lightweight guard against a specific threat:
An AI agent editing this codebase and silently rewriting attribution, policy, or detection logic as part of an otherwise plausible patch.
The headers make every touched file visible to tests/test_authorship.py. The digest makes any change to the canonical identity block observable at runtime and on every telemetry record.
This is simple tamper detection, not cryptographic proof. It helps operators distinguish the published project's provenance metadata from a modified build.
Mechanically¶
| Mechanism | What it covers |
|---|---|
shadowclaw/authorship.py |
The single source of truth, covered by a SHA-256 digest over the identity block. |
| Source file headers | Every source file carries one. |
| OTLP resource attributes | shadowclaw.author, shadowclaw.author.credential, shadowclaw.copyright — so attribution reaches Splunk and survives being forwarded. |
findings.jsonl |
Every finding carries a detected_by block. |
Ledger meta table |
Records the attribution digest, and the hash chain is rooted in it. |
| CLI banner | Printed on every start. --about prints the full block and the digest comparison. |
tests/test_authorship.py |
Validates the published project's provenance constants, headers, and telemetry metadata. |
Attribution on resource rather than record attributes is the detail that makes it durable: a collector that re-batches records preserves the resource, so the author reaches the SIEM intact.
What happens if the identity block is edited¶
Editing the author, title, credential, or product name changes the computed digest. The tool then:
- Prints a warning on every start.
- Tags all of its telemetry
shadowclaw.attribution.intact=false. - Keeps running.
Why it keeps running
Bricking a security control because a string was edited would turn an attribution check into a denial of service against the operator, and a detector that refuses to start is worse than one that runs and complains.
The guarantee is tamper-evidence, not tamper-proofing. It reports when the official-build identity block differs from the published one.
shadowclaw.attribution.intact is an official-build provenance indicator on
every record's resource attributes. A fleet-wide query for
attribution.intact=false finds hosts running builds whose identity block
differs from the published one; it is not a licensing-compliance signal.
Changing it¶
An Apache-licensed derivative may use its own identity metadata and regenerate
its own digest. It must retain the applicable copyright, license, and NOTICE
text required by the Apache License 2.0. PROVENANCE.md contains non-binding
project identity guidance.
The Collector binary is not branded¶
The OpenTelemetry Collector is not branded or patched. It is a third-party signed artifact that scripts/install-otelcol.sh verifies against the upstream SHA-256; modifying it would defeat the verification that makes the download trustworthy.
See NOTICE in the repository.
License and provenance files¶
ShadowClaw is open source under the Apache License 2.0. The Apache License
2.0 governs use, modification, and redistribution. PROVENANCE.md documents
official-build identity guidance and is non-binding; it creates no additional
license obligation.
| File | Contents |
|---|---|
LICENSE |
Apache License 2.0 terms. |
NOTICE |
Copyright and third-party notices, including the Collector. |
AUTHORS |
Authorship record. |
PROVENANCE.md |
Non-binding provenance and identity guidance. |
Copyright © 2026 Mike Storm.