Fix audit tool bootstrap and add per-run preflight

audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
  under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
  since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
  and --user-only (no system package managers, no sudo).

log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.

audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).

Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
This commit is contained in:
2026-09-22 15:21:28 -05:00
parent d3258b224a
commit 37fc3fb291
30 changed files with 1045 additions and 84 deletions
@@ -3,6 +3,9 @@ from __future__ import annotations
import importlib.util
import json
import os
import subprocess
import sys
from pathlib import Path
_SPEC = importlib.util.spec_from_file_location(
@@ -136,3 +139,17 @@ def test_log_path_parent_is_created(tmp_path: Path) -> None:
])
assert rc == 0
assert log.exists()
def test_runs_as_a_script_from_another_cwd(tmp_path: Path) -> None:
log = tmp_path / "runs.jsonl"
env = {k: v for k, v in os.environ.items() if k != "PYTHONPATH"}
r = subprocess.run(
[sys.executable, str(_SPEC.origin),
"--output-dir", str(tmp_path), "--run-id", "x", "--repo", "/r",
"--mode", "local", "--log-path", str(log), "--usage-json", "-"],
input=json.dumps({"x-reviewer": {"model": "sonnet"}}),
capture_output=True, text=True, cwd=tmp_path, env=env, check=False,
)
assert r.returncode == 0, r.stderr
assert _read_log(log)[0]["agent"] == "x-reviewer"