Fix audit tool bootstrap and add per-run preflight

audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
  under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
  since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
  and --user-only (no system package managers, no sudo).

log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.

audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).

Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
This commit is contained in:
2026-09-22 15:21:28 -05:00
parent d3258b224a
commit 37fc3fb291
30 changed files with 1045 additions and 84 deletions
@@ -0,0 +1,73 @@
#!/usr/bin/env bash
set -euo pipefail
SKILL_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")/.." && pwd)"
say() { printf '\n\033[1m▶ %s\033[0m\n' "$*"; }
warn() { printf '\033[33m! %s\033[0m\n' "$*"; }
install_python_tools() {
if ! command -v uv >/dev/null 2>&1; then
warn "uv not installed. Install: https://docs.astral.sh/uv/getting-started/installation/"
exit 1
fi
say "Installing Python dependencies into $SKILL_DIR/.venv/ via uv"
uv sync --group tools
}
# Each plugin version gets its own venv, so the check targets this skill's .venv, not whatever python is on PATH.
python_deps_present() {
[[ -x "$SKILL_DIR/.venv/bin/python" ]] &&
"$SKILL_DIR/.venv/bin/python" -c 'import hcl2, bs4, requests' >/dev/null 2>&1
}
verify_tools() {
say "Verifying tool availability"
local tool missing=()
if python_deps_present; then
printf ' %-15s %s\n' "python deps" "(.venv)"
else
missing+=("python-hcl2/beautifulsoup4/requests (.venv)")
fi
# tofu only: the plan runner has no terraform fallback.
for tool in trivy tflint tofu terragrunt gh; do
if command -v "$tool" >/dev/null 2>&1; then
printf ' %-15s %s\n' "$tool" "$(command -v "$tool")"
else
missing+=("$tool")
fi
done
[[ ${#missing[@]} -eq 0 ]] && return
printf ' %-15s \033[31mmissing\033[0m\n' "${missing[@]}"
return 1
}
main() {
case "${1:-}" in
"") ;;
--check-only) verify_tools; return ;;
*) echo "usage: install-tools.sh [--check-only]" >&2; return 2 ;;
esac
cd "$SKILL_DIR"
install_python_tools
cat <<EOF
Native tools are not installed here. Missing ones install user-scoped with:
trivy go install github.com/aquasecurity/trivy/cmd/trivy@latest
tflint go install github.com/terraform-linters/tflint@latest
tofu go install github.com/opentofu/opentofu/cmd/tofu@latest
terragrunt go install github.com/gruntwork-io/terragrunt@latest
gh go install github.com/cli/cli/v2/cmd/gh@latest
Run /audit-terraform to use the skill.
EOF
verify_tools
}
if [[ "${BASH_SOURCE[0]}" == "$0" ]]; then
main "$@"
fi