Files
jhonny-editor/code/docs/recommendations/2026-08-18-round-2/30-host-capability-attestation.md
T
João Henrique b541f502ba feat: initial commit - Jhonny Editor
- Adicionado estrutura completa do projeto
- Configurado MCP server para Premiere Pro
- Adicionado documentação e skills
- Configurado Gitignore para o projeto
2026-09-08 09:59:31 -04:00

22 lines
1.1 KiB
Markdown
Executable File

# Recommendation 30: signed host capability attestation
## Evidence
Adobe documents host and UXP runtime version inspection, while Premiere APIs declare minimum versions per method. Static package declarations can therefore differ from the connected runtime.
- [Understanding UXP APIs](https://developer.adobe.com/premiere-pro/uxp/resources/fundamentals/apis)
- [Adobe UXP changelog](https://developer.adobe.com/premiere-pro/uxp/changelog)
## Proposed improvement
Have the authenticated panel produce a nonce-bound capability attestation containing host version, UXP version, plugin build hash, probed stable methods, and timestamp. Bind it to the current WebSocket connection and expire it quickly.
## Acceptance criteria
- Replayed, expired, cross-connection, and mismatched-build attestations are rejected.
- Probes are read-only and bounded.
- Tool discovery uses the attested intersection, not package-version assumptions.
- Diagnostics distinguish declared, probed, and live-verified capability.
Attestation proves what the panel observed, not that a later host operation succeeded.