Move the code and terraform audits into the reviews plugin

Copy the standalone code-review and terraform-review skills into
plugins/reviews as audit-code and audit-terraform. The rename separates the
automated, linter-driven audits from the guided review-pr walkthrough that
already lived here.

Resolve bundled script paths through ${SKILL_DIR}, exported in a new step 0.
CLAUDE_PLUGIN_ROOT is not set in the Bash tool environment, so the obvious
substitution would have expanded to nothing and broken every collection
script invocation.

Replace the PLAN and DESIGN docs with READMEs written from the current
SKILL.md and scripts. The old docs had drifted badly: they named semgrep
where the code calls opengrep, scoped five review agents where there are
now eight, and predated Lua, PowerShell, and GitHub Actions support.

Add CONSISTENCY_NORMS to the audit-terraform agent inputs. The collection
script writes consistency_norms.json and the agent prompt declares it, but
SKILL.md never listed it, leaving the variable unsubstituted.

Drop the --ingest-verdicts instruction from both skills. review_stats.py
parses no arguments, so the ref-mode verdict template it told users to feed
back could never be read.

Point audit-terraform's smoke test at README.md and resolve its fixture
paths relative to the test file rather than an absolute home directory.

Tests: 197 passing (audit-code), 106 passing (audit-terraform).
This commit is contained in:
2026-07-21 11:11:05 -05:00
parent 600c1fef86
commit f5934181ec
179 changed files with 20779 additions and 3 deletions
@@ -0,0 +1,28 @@
"""Adapter: actionlint -format '{{json .}}' normalized to Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_actionlint_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, list):
return []
out: list[Finding] = []
for item in payload:
line = item.get("line", 0)
out.append(Finding(
tool="actionlint",
rule_id=item.get("kind", "unknown"),
severity="high",
file=item.get("filepath", ""),
line=line,
end_line=line,
message=item.get("message", ""),
))
return out
@@ -0,0 +1,29 @@
"""Adapter: bandit -f json normalized to Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
_SEVERITY = {"HIGH": "high", "MEDIUM": "medium", "LOW": "low"}
def parse_bandit_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
out: list[Finding] = []
for result in payload.get("results", []):
line_range = result.get("line_range") or [result.get("line_number"), result.get("line_number")]
out.append(Finding(
tool="bandit",
rule_id=result.get("test_id", ""),
severity=_SEVERITY.get(result.get("issue_severity", ""), "medium"),
file=result.get("filename", ""),
line=line_range[0],
end_line=line_range[-1],
message=result.get("issue_text", ""),
))
return out
@@ -0,0 +1,51 @@
"""Adapter: dotnet build text output normalized to Finding[]."""
from __future__ import annotations
import os
import re
from scripts.manifest import Finding
_LINE_RE = re.compile(
r"^(?P<file>[^(]+)\((?P<line>\d+),\d+\):\s*"
r"(?P<severity>error|warning)\s+"
r"(?P<code>[A-Z]+\d+):\s*"
r"(?P<message>.+?)\s*"
r"(?:\[[^\]]+\])?\s*$"
)
def _severity(code: str, severity_word: str) -> str:
if code.startswith("SCS"):
return "high"
if severity_word == "error":
return "medium"
return "low"
def parse_dotnet_build_output(stdout: str, repo_root: str) -> list[Finding]:
out: list[Finding] = []
seen: set[tuple[str, int, str]] = set()
for raw in stdout.splitlines():
m = _LINE_RE.match(raw)
if not m:
continue
file_abs = m.group("file")
rel = os.path.relpath(file_abs, repo_root) if file_abs.startswith(repo_root) else file_abs
code = m.group("code")
line = int(m.group("line"))
key = (rel, line, code)
if key in seen:
continue
seen.add(key)
out.append(Finding(
tool="dotnet",
rule_id=code,
severity=_severity(code, m.group("severity")),
file=rel,
line=line,
end_line=line,
message=m.group("message"),
))
return out
@@ -0,0 +1,40 @@
"""Adapter: eslint -f json normalized to Finding[]."""
from __future__ import annotations
import json
import os
from scripts.manifest import Finding
def _severity(rule_id: str, sev_num: int) -> str:
if rule_id and "security" in rule_id:
return "high"
if sev_num == 2:
return "medium"
return "low"
def parse_eslint_output(stdout: str, repo_root: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, list):
return []
out: list[Finding] = []
for entry in payload:
file_path = entry.get("filePath", "")
rel = os.path.relpath(file_path, repo_root) if file_path.startswith(repo_root) else file_path
for msg in entry.get("messages", []):
rule_id = msg.get("ruleId") or ""
out.append(Finding(
tool="eslint",
rule_id=rule_id,
severity=_severity(rule_id, msg.get("severity", 1)),
file=rel,
line=msg.get("line", 0),
end_line=msg.get("endLine", msg.get("line", 0)),
message=msg.get("message", ""),
))
return out
@@ -0,0 +1,27 @@
"""Adapter: gitleaks --report-format json normalized to Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_gitleaks_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, list):
return []
out: list[Finding] = []
for r in payload:
out.append(Finding(
tool="gitleaks",
rule_id=r.get("RuleID", ""),
severity="critical",
file=r.get("File", ""),
line=r.get("StartLine", 0),
end_line=r.get("EndLine", r.get("StartLine", 0)),
message=r.get("Description", ""),
))
return out
@@ -0,0 +1,41 @@
"""Adapter: interrogate --quiet --output-format=json output → Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_interrogate_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, dict):
return []
files = payload.get("files")
if not isinstance(files, dict):
return []
out: list[Finding] = []
for file_path, file_data in files.items():
if not isinstance(file_data, dict):
continue
for entry in file_data.get("missing", []):
if entry.get("private"):
continue
full_name = entry.get("name", "")
symbol = full_name.split(":", 1)[-1] if ":" in full_name else full_name
if symbol.startswith("_"):
continue
kind = entry.get("type", "symbol")
line = entry.get("lineno", 0)
out.append(Finding(
tool="interrogate",
rule_id="interrogate:missing-docstring",
severity="low",
file=file_path,
line=line,
end_line=line,
message=f"missing docstring for public {kind} {symbol}",
))
return out
@@ -0,0 +1,34 @@
"""Adapter: jscpd JSON output → Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_jscpd_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, dict):
return []
out: list[Finding] = []
for dup in payload.get("duplicates", []):
first = dup.get("firstFile", {})
second = dup.get("secondFile", {})
lines = dup.get("lines", 0)
severity = "medium" if lines >= 30 else "low"
out.append(Finding(
tool="jscpd",
rule_id=f"jscpd:clone-{lines}lines",
severity=severity,
file=first.get("name", ""),
line=first.get("start", 0),
end_line=first.get("end", 0),
message=(
f"duplicate of {second.get('name', '')}:"
f"{second.get('start', 0)}-{second.get('end', 0)} ({lines} lines)"
),
))
return out
@@ -0,0 +1,31 @@
"""Adapter: knip --reporter json output → Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_knip_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, dict):
return []
out: list[Finding] = []
for issue in payload.get("issues", []):
file_path = issue.get("file", "")
for export in issue.get("exports", []):
name = export.get("name", "")
line = export.get("line", 0)
out.append(Finding(
tool="knip",
rule_id="knip:dead-export",
severity="medium",
file=file_path,
line=line,
end_line=line,
message=f"unused export '{name}'",
))
return out
@@ -0,0 +1,46 @@
"""Adapter: lizard --csv output → Finding[]."""
from __future__ import annotations
from scripts.manifest import Finding
def _severity_for_ccn(ccn: int) -> str | None:
if ccn >= 20:
return "high"
if ccn >= 10:
return "medium"
return None
def parse_lizard_output(stdout: str) -> list[Finding]:
out: list[Finding] = []
for raw in stdout.splitlines():
parts = raw.strip().split(",")
if len(parts) < 6:
continue
try:
ccn = int(parts[1])
except ValueError:
continue
severity = _severity_for_ccn(ccn)
if severity is None:
continue
location = parts[5]
loc_parts = location.split("@")
if len(loc_parts) < 3:
continue
name, line_str, file_path = loc_parts[0], loc_parts[1], loc_parts[2]
try:
line = int(line_str)
except ValueError:
continue
out.append(Finding(
tool="lizard",
rule_id=f"lizard:ccn={ccn}",
severity=severity,
file=file_path,
line=line,
end_line=line,
message=f"function {name} has CCN {ccn}",
))
return out
@@ -0,0 +1,32 @@
"""Adapter: luac -p stderr normalized to Finding[]."""
from __future__ import annotations
import re
from scripts.manifest import Finding
_PATTERN = re.compile(r"^luac:\s+(.+?):(\d+):\s+(.+)$")
def parse_luac_output(stderr: str, repo_root: str = "") -> list[Finding]:
out: list[Finding] = []
prefix = repo_root.rstrip("/") + "/" if repo_root else ""
for line in stderr.splitlines():
m = _PATTERN.match(line.strip())
if not m:
continue
filepath, lineno_str, message = m.group(1), m.group(2), m.group(3)
if prefix and filepath.startswith(prefix):
filepath = filepath[len(prefix):]
lineno = int(lineno_str)
out.append(Finding(
tool="luac",
rule_id="syntax-error",
severity="critical",
file=filepath,
line=lineno,
end_line=lineno,
message=message,
))
return out
@@ -0,0 +1,37 @@
"""Adapter: mypy text output normalized to Finding[]."""
from __future__ import annotations
import re
from scripts.manifest import Finding
_LINE_RE = re.compile(
r"^(?P<file>[^:]+):(?P<line>\d+):\s*"
r"(?P<severity>error|warning|note):\s*"
r"(?P<message>.+?)"
r"(?:\s+\[(?P<code>[a-z\-]+)\])?\s*$"
)
_SEVERITY = {"error": "medium", "warning": "low", "note": None}
def parse_mypy_output(stdout: str) -> list[Finding]:
out: list[Finding] = []
for raw in stdout.splitlines():
m = _LINE_RE.match(raw)
if not m:
continue
sev = _SEVERITY.get(m.group("severity"))
if sev is None:
continue
out.append(Finding(
tool="mypy",
rule_id=m.group("code") or "",
severity=sev,
file=m.group("file"),
line=int(m.group("line")),
end_line=int(m.group("line")),
message=m.group("message"),
))
return out
@@ -0,0 +1,51 @@
"""Adapter: opengrep --json normalized to Finding[]. Same JSON schema as semgrep (opengrep is a semgrep fork)."""
from __future__ import annotations
import json
import re
from scripts.manifest import Finding
_SEVERITY = {"ERROR": "high", "WARNING": "medium", "INFO": "low"}
_CWE_RE = re.compile(r"(CWE-\d+)")
_LOCAL_RULES_MARKER = "scripts.rules."
def _clean_rule_id(check_id: str) -> str:
if _LOCAL_RULES_MARKER in check_id:
return check_id.rsplit(_LOCAL_RULES_MARKER, 1)[-1]
return check_id
def _cwe(meta: dict) -> str | None:
raw = meta.get("cwe")
if isinstance(raw, list) and raw:
m = _CWE_RE.search(str(raw[0]))
return m.group(1) if m else None
if isinstance(raw, str):
m = _CWE_RE.search(raw)
return m.group(1) if m else None
return None
def parse_opengrep_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
out: list[Finding] = []
for r in payload.get("results", []):
extra = r.get("extra", {})
metadata = extra.get("metadata", {})
out.append(Finding(
tool="opengrep",
rule_id=_clean_rule_id(r.get("check_id", "")),
severity=_SEVERITY.get(extra.get("severity", ""), "medium"),
file=r.get("path", ""),
line=r.get("start", {}).get("line", 0),
end_line=r.get("end", {}).get("line", r.get("start", {}).get("line", 0)),
message=extra.get("message", ""),
cwe=_cwe(metadata),
))
return out
@@ -0,0 +1,31 @@
"""Adapter: osv-scanner --format json normalized to Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_osv_scanner_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
out: list[Finding] = []
for r in payload.get("results", []):
manifest_path = r.get("source", {}).get("path", "")
for pkg in r.get("packages", []):
p = pkg.get("package", {})
name = p.get("name", "")
version = p.get("version", "")
for v in pkg.get("vulnerabilities", []):
out.append(Finding(
tool="osv-scanner",
rule_id=v.get("id", ""),
severity="high",
file=manifest_path,
line=1,
end_line=1,
message=f"{name} {version}: {v.get('summary', '')}",
))
return out
@@ -0,0 +1,35 @@
"""Adapter: pip-audit -f json normalized to Finding[].
Findings are attached to the dependency manifest file rather than a source
file, since the vulnerability is in a pinned dep, not in code.
"""
from __future__ import annotations
import json
from scripts.manifest import Finding
def parse_pip_audit_output(stdout: str, manifest_path: str = "requirements.txt") -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
out: list[Finding] = []
for dep in payload.get("dependencies", []):
name = dep.get("name", "")
version = dep.get("version", "")
for v in dep.get("vulns", []):
fix = v.get("fix_versions") or []
fix_str = ", ".join(fix) if fix else None
out.append(Finding(
tool="pip-audit",
rule_id=v.get("id", ""),
severity="high",
file=manifest_path,
line=1,
end_line=1,
message=f"{name} {version}: {v.get('description', '')}",
fix_suggestion=f"upgrade to {fix_str}" if fix_str else None,
))
return out
@@ -0,0 +1,56 @@
"""Adapter: Invoke-ScriptAnalyzer JSON normalized to Finding[].
Shared by both PowerShell tools — PSScriptAnalyzer's built-in rules and the
InjectionHunter custom rule pack — because both are Invoke-ScriptAnalyzer runs
and emit the same DiagnosticRecord shape.
"""
from __future__ import annotations
import json
import os
from scripts.manifest import Finding
_SEVERITY = {
"ParseError": "critical",
"Error": "high",
"Warning": "medium",
"Information": "low",
}
_INJECTION_FLOOR = "high"
def parse_psscriptanalyzer_output(
stdout: str, repo_root: str, tool: str = "psscriptanalyzer",
) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if isinstance(payload, dict):
payload = [payload]
if not isinstance(payload, list):
return []
out: list[Finding] = []
for item in payload:
if not isinstance(item, dict):
continue
path = item.get("ScriptPath") or item.get("ScriptName") or ""
rel = os.path.relpath(path, repo_root) if path.startswith(repo_root) else path
line = item.get("Line") or 0
severity = _SEVERITY.get(item.get("Severity", ""), "medium")
if tool == "injectionhunter":
severity = _INJECTION_FLOOR
out.append(Finding(
tool=tool,
rule_id=item.get("RuleName", "unknown"),
severity=severity,
file=rel,
line=line,
end_line=item.get("EndLine") or line,
message=item.get("Message", ""),
))
return out
@@ -0,0 +1,46 @@
"""Adapter: radon cc -j JSON output → Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def _severity_for_complexity(cc: int) -> str | None:
if cc >= 20:
return "high"
if cc >= 10:
return "medium"
return None
def parse_radon_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, dict):
return []
out: list[Finding] = []
for file_path, items in payload.items():
if not isinstance(items, list):
continue
for item in items:
cc = item.get("complexity", 0)
severity = _severity_for_complexity(cc)
if severity is None:
continue
line = item.get("lineno", 0)
end_line = item.get("endline", line)
name = item.get("name", "?")
kind = item.get("type", "function")
out.append(Finding(
tool="radon",
rule_id=f"radon:cc={cc}",
severity=severity,
file=file_path,
line=line,
end_line=end_line,
message=f"high cyclomatic complexity (CCN={cc}) in {kind} {name}",
))
return out
@@ -0,0 +1,40 @@
"""Adapter: ruff check --output-format=json normalized to Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def _severity_for_rule(code: str) -> str:
if not code:
return "low"
if code.startswith("S"):
return "high"
if code.startswith("B"):
return "medium"
return "low"
def parse_ruff_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, list):
return []
out: list[Finding] = []
for item in payload:
loc = item.get("location") or {}
end = item.get("end_location") or loc
code = item.get("code", "")
out.append(Finding(
tool="ruff",
rule_id=code,
severity=_severity_for_rule(code),
file=item.get("filename", ""),
line=loc.get("row", 0),
end_line=end.get("row", loc.get("row", 0)),
message=item.get("message", ""),
))
return out
@@ -0,0 +1,38 @@
"""Adapter: ruff check with idiom/simplification selectors → Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
def _severity_for_idiom_rule(code: str) -> str:
if not code:
return "low"
if code.startswith(("PLR", "C90", "B")):
return "medium"
return "low"
def parse_ruff_idiom_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, list):
return []
out: list[Finding] = []
for item in payload:
loc = item.get("location") or {}
end = item.get("end_location") or loc
code = item.get("code", "")
out.append(Finding(
tool="ruff-idiom",
rule_id=code,
severity=_severity_for_idiom_rule(code),
file=item.get("filename", ""),
line=loc.get("row", 0),
end_line=end.get("row", loc.get("row", 0)),
message=item.get("message", ""),
))
return out
@@ -0,0 +1,34 @@
"""Adapter: selene --display-style=json normalized to Finding[]."""
from __future__ import annotations
import json
from scripts.manifest import Finding
_SEVERITY = {"Error": "high", "Warning": "medium", "Note": "low"}
def parse_selene_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
if not isinstance(payload, list):
return []
out: list[Finding] = []
for item in payload:
code = item.get("code", {})
span = item.get("span", {})
start = span.get("start", {})
end_span = span.get("end", {})
out.append(Finding(
tool="selene",
rule_id=code.get("name", "unknown"),
severity=_SEVERITY.get(code.get("severity", ""), "medium"),
file=item.get("filename", ""),
line=start.get("line", 0),
end_line=end_span.get("line", start.get("line", 0)),
message=item.get("primary_label", ""),
))
return out
@@ -0,0 +1,33 @@
"""Adapter: tsc --noEmit text output normalized to Finding[]."""
from __future__ import annotations
import re
from scripts.manifest import Finding
_LINE_RE = re.compile(
r"^(?P<file>[^(]+)\((?P<line>\d+),\d+\):\s*"
r"(?P<severity>error|warning)\s+"
r"(?P<code>TS\d+):\s*"
r"(?P<message>.+?)\s*$"
)
def parse_tsc_output(stdout: str) -> list[Finding]:
out: list[Finding] = []
for raw in stdout.splitlines():
m = _LINE_RE.match(raw)
if not m:
continue
sev = "medium" if m.group("severity") == "error" else "low"
out.append(Finding(
tool="tsc",
rule_id=m.group("code"),
severity=sev,
file=m.group("file"),
line=int(m.group("line")),
end_line=int(m.group("line")),
message=m.group("message"),
))
return out
@@ -0,0 +1,31 @@
"""Adapter: vulture text output → Finding[]."""
from __future__ import annotations
import re
from scripts.manifest import Finding
_LINE_RE = re.compile(
r"^(?P<file>[^:]+):(?P<line>\d+):\s*(?P<msg>.+?)\s*\((?P<conf>\d+)%\s*confidence\)$"
)
def parse_vulture_output(stdout: str) -> list[Finding]:
out: list[Finding] = []
for raw in stdout.splitlines():
m = _LINE_RE.match(raw.strip())
if not m:
continue
conf = int(m.group("conf"))
severity = "medium" if conf >= 80 else "low"
out.append(Finding(
tool="vulture",
rule_id=f"vulture:{conf}pct",
severity=severity,
file=m.group("file"),
line=int(m.group("line")),
end_line=int(m.group("line")),
message=m.group("msg"),
))
return out
@@ -0,0 +1,48 @@
"""Adapter: zizmor --format sarif normalized to Finding[]."""
from __future__ import annotations
import json
import re
from scripts.manifest import Finding
_LEVEL = {"error": "high", "warning": "medium", "note": "low"}
_CWE_RE = re.compile(r"(CWE-\d+)")
def parse_zizmor_output(stdout: str) -> list[Finding]:
try:
payload = json.loads(stdout)
except json.JSONDecodeError:
return []
out: list[Finding] = []
for run in payload.get("runs", []):
cwe_by_rule: dict[str, str] = {}
for rule in run.get("tool", {}).get("driver", {}).get("rules", []):
for tag in rule.get("properties", {}).get("tags", []):
m = _CWE_RE.match(tag)
if m:
cwe_by_rule[rule["id"]] = m.group(1)
break
for result in run.get("results", []):
rule_id = result.get("ruleId", "unknown")
locations = result.get("locations", [])
if not locations:
continue
phys = locations[0].get("physicalLocation", {})
uri = phys.get("artifactLocation", {}).get("uri", "")
region = phys.get("region", {})
start_line = region.get("startLine", 0)
end_line = region.get("endLine", start_line)
out.append(Finding(
tool="zizmor",
rule_id=rule_id,
severity=_LEVEL.get(result.get("level", "warning"), "medium"),
file=uri,
line=start_line,
end_line=end_line,
message=result.get("message", {}).get("text", ""),
cwe=cwe_by_rule.get(rule_id),
))
return out