Fix audit tool bootstrap and add per-run preflight
audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
and --user-only (no system package managers, no sudo).
log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.
audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).
Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
This commit is contained in:
@@ -43,6 +43,27 @@ other command so the bundled scripts resolve wherever the plugin is installed:
|
||||
export SKILL_DIR=<absolute path to the directory holding this SKILL.md>
|
||||
```
|
||||
|
||||
### 0.5 Preflight — every run
|
||||
|
||||
```
|
||||
bash ${SKILL_DIR}/scripts/install-tools.sh --check-only
|
||||
```
|
||||
|
||||
It installs nothing and returns in milliseconds when everything is present,
|
||||
so run it every time. Each plugin version runs from its own directory with a
|
||||
fresh, empty `.venv`, so expect it to fail on the first run after an update.
|
||||
|
||||
- **Exit 0:** continue.
|
||||
- **Non-zero:** it lists what is missing. Run
|
||||
`bash ${SKILL_DIR}/scripts/install-tools.sh` (only `uv sync` into
|
||||
`${SKILL_DIR}/.venv`; never sudo), then re-run `--check-only`.
|
||||
- **Still missing** (`trivy`, `tflint`, `tofu`, `terragrunt`, `gh` are native
|
||||
binaries the script does not install): show the user the install commands
|
||||
the script printed and ask before running any. If they decline, continue:
|
||||
the collection script records each missing tool in `tools_unavailable` with
|
||||
its install command, and stops with an error if a plan needs a missing
|
||||
`tofu` / `terragrunt`.
|
||||
|
||||
### 1. Resolve mode, repo identity, and worktree
|
||||
|
||||
First resolve `NWO` (owner/repo) so every `gh` call works regardless of
|
||||
@@ -110,7 +131,7 @@ Create the directory.
|
||||
### 3. Run the collection script
|
||||
|
||||
```
|
||||
python ${SKILL_DIR}/scripts/collect-changes.py \
|
||||
uv run --project ${SKILL_DIR} python ${SKILL_DIR}/scripts/collect-changes.py \
|
||||
--repo <REPO> --base <base-or-detect> --head <head-ref-or-HEAD> \
|
||||
--output-dir <OUTPUT> --mode <local|ref>
|
||||
```
|
||||
@@ -183,7 +204,7 @@ echo '{
|
||||
"aws-bp-reviewer": {"model":"sonnet","input_tokens":N,"output_tokens":N,"duration_ms":N},
|
||||
"consistency-reviewer": {"model":"sonnet","input_tokens":N,"output_tokens":N,"duration_ms":N},
|
||||
"tf-hygiene-reviewer": {"model":"haiku","input_tokens":N,"output_tokens":N,"duration_ms":N}
|
||||
}' | python ${SKILL_DIR}/scripts/log-run.py \
|
||||
}' | uv run --project ${SKILL_DIR} python ${SKILL_DIR}/scripts/log-run.py \
|
||||
--output-dir <OUTPUT> --run-id $RUN_ID --repo <REPO> \
|
||||
--mode <local|ref> --usage-json -
|
||||
```
|
||||
@@ -286,6 +307,9 @@ In ref mode, end with: "Worktree left at `<REPO>` for follow-up review."
|
||||
- **Plan failed in some dir:** Manifest's `errors[]` populated, script exited
|
||||
non-zero. Show the errors. Do NOT run agents. Tell user to fix and re-run.
|
||||
- **No `gh`:** see step 1.
|
||||
- **Scanner or plan tool missing:** `tools_unavailable` maps each missing tool
|
||||
to its install command. A missing `trivy` / `tflint` only skips that scan;
|
||||
say so in the output. A missing `tofu` / `terragrunt` fails collection.
|
||||
- **Module with no callsites:** Manifest has a warning in `errors[]`; report
|
||||
it but still run the subagents (they handle diff-only entries fine).
|
||||
- **One agent fails:** Report what the surviving agents found and note the
|
||||
|
||||
Reference in New Issue
Block a user