Fix audit tool bootstrap and add per-run preflight

audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
  under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
  since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
  and --user-only (no system package managers, no sudo).

log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.

audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).

Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
This commit is contained in:
2026-09-22 15:21:28 -05:00
parent d3258b224a
commit 37fc3fb291
30 changed files with 1045 additions and 84 deletions
+25 -3
View File
@@ -43,6 +43,27 @@ other command so the bundled scripts resolve wherever the plugin is installed:
export SKILL_DIR=<absolute path to the directory holding this SKILL.md>
```
### 0.5 Preflight — every run
```
bash ${SKILL_DIR}/scripts/install-tools.sh --check-only
```
It installs nothing and returns in milliseconds when everything is present,
so run it every time. Each plugin version runs from its own directory with a
fresh, empty `.venv`, so expect it to fail on the first run after an update.
- **Exit 0:** continue.
- **Non-zero:** it lists what is missing. Run
`bash ${SKILL_DIR}/scripts/install-tools.sh --user-only` (Python tools into
`${SKILL_DIR}/.venv`, opengrep, user-scope PowerShell modules; never sudo),
then re-run `--check-only`.
- **Still missing** (`gitleaks`, `osv-scanner`, `gh` are system packages):
ask the user before running `bash ${SKILL_DIR}/scripts/install-tools.sh`
without `--user-only` — it installs through brew/paru/yay/pacman and may
call sudo. If they decline, continue: the collection script records each
missing tool in `tools_unavailable` with its install command.
### 1. Resolve mode, repo identity, and worktree
First resolve `NWO` (owner/repo) so every `gh` call works regardless of
@@ -103,7 +124,7 @@ Create the directory.
### 3. Run the collection script
```
python ${SKILL_DIR}/scripts/collect-findings.py \
uv run --project ${SKILL_DIR} python ${SKILL_DIR}/scripts/collect-findings.py \
--repo <REPO> --head <head-or-HEAD> \
--output-dir <OUTPUT> --mode <local|ref>
```
@@ -170,7 +191,7 @@ echo '{
"secrets-reviewer": {"model":"sonnet","input_tokens":N,"output_tokens":N,"duration_ms":N},
"maintainability-reviewer": {"model":"haiku","input_tokens":N,"output_tokens":N,"duration_ms":N},
"gha-reviewer": {"model":"sonnet","input_tokens":N,"output_tokens":N,"duration_ms":N}
}' | python ${SKILL_DIR}/scripts/log-run.py \
}' | uv run --project ${SKILL_DIR} python ${SKILL_DIR}/scripts/log-run.py \
--output-dir <OUTPUT> --run-id $RUN_ID --repo <REPO> \
--mode <local|ref> --usage-json -
```
@@ -287,7 +308,8 @@ In ref mode, end with: "Worktree left at `<REPO>` for follow-up review."
coverage was partial. Example: `⚠️ Go file changed but not reviewed:
cmd/server.go (Go support not in this skill yet).`
- **No `gh`:** see step 1.
- **Tools missing on PATH:** non-fatal; `tools_unavailable` lists them.
- **Tools missing on PATH:** non-fatal; `tools_unavailable` maps each to
its install command.
Agents acknowledge degraded coverage.
- **PowerShell files changed but no `pwsh`:** `psscriptanalyzer` and
`injectionhunter` report `not on PATH` / `<module> not installed`. Both