Ferrule

Private, on-device Terraform security review for Chrome

View the Project on GitHub Erya-Labs/Ferrule

M2 results — GitHub integration verified live

Date: 2026-07-30 How: npm run verify-m2 (spike/m2-verify/) against a real private repository, using a fine-grained personal access token scoped to that repo with Contents: Read-only. Verdict: PASS — the zero-egress claim holds under observation.

Exit criterion (from ROADMAP.md)

Lists a private repo’s .tf files and runs the scanner on them end-to-end; no request leaves the allowlist (verified in the DevTools network log).

What was verified

Caveats, recorded honestly

Conclusion

M2 is complete. The GitHub client works against real private repositories and the extension’s central privacy promise survives direct observation. Proceed to M3 (wiring the pipeline together — Queue 2, T15–T22).