audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
and --user-only (no system package managers, no sudo).
log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.
audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).
Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
112 lines
4.0 KiB
Python
112 lines
4.0 KiB
Python
"""Per-agent manifest slicing."""
|
|
from __future__ import annotations
|
|
|
|
|
|
_TYPE_TOOLS = {"mypy", "tsc"}
|
|
_DEP_TOOLS = {"pip-audit", "osv-scanner"}
|
|
_SECRET_TOOLS = {"gitleaks"}
|
|
_MAINTAINABILITY_TOOLS = {"vulture", "radon", "interrogate", "lizard", "knip", "jscpd", "selene"}
|
|
_GHA_TOOLS = {"actionlint", "zizmor"}
|
|
|
|
_PSSA_SECURITY_RULES = {
|
|
"PSAvoidUsingPlainTextForPassword",
|
|
"PSAvoidUsingConvertToSecureStringWithPlainText",
|
|
"PSAvoidUsingUsernameAndPasswordParams",
|
|
"PSUsePSCredentialType",
|
|
"PSAvoidUsingInvokeExpression",
|
|
"PSAvoidUsingComputerNameHardcoded",
|
|
"PSAvoidUsingBrokenHashAlgorithms",
|
|
}
|
|
|
|
|
|
def slice_for_agent(manifest: dict, agent: str) -> dict:
|
|
"""Return a subset of the manifest scoped to a specific reviewer."""
|
|
base = {
|
|
"mode": manifest["mode"],
|
|
"base_ref": manifest["base_ref"],
|
|
"head_ref": manifest["head_ref"],
|
|
"default_branch": manifest["default_branch"],
|
|
"language_breakdown": manifest["language_breakdown"],
|
|
"changed_files": list(manifest["changed_files"]),
|
|
"tool_stats": dict(manifest["tool_stats"]),
|
|
"tools_unavailable": dict(manifest["tools_unavailable"]),
|
|
"errors": list(manifest["errors"]),
|
|
}
|
|
findings = manifest["findings"]
|
|
|
|
if agent == "security-triage":
|
|
kept: list[dict] = []
|
|
for f in findings:
|
|
tool = f["tool"]
|
|
if tool in {"bandit", "ruff", "opengrep", "luac", "injectionhunter"}:
|
|
kept.append(f)
|
|
elif tool == "psscriptanalyzer" and f.get("rule_id", "") in _PSSA_SECURITY_RULES:
|
|
kept.append(f)
|
|
elif tool == "eslint" and "security" in f.get("rule_id", ""):
|
|
kept.append(f)
|
|
elif tool == "dotnet" and f.get("rule_id", "").startswith("SCS"):
|
|
kept.append(f)
|
|
return {**base, "findings": kept}
|
|
|
|
if agent == "type-safety":
|
|
kept = []
|
|
for f in findings:
|
|
tool = f["tool"]
|
|
if tool in _TYPE_TOOLS:
|
|
kept.append(f)
|
|
elif tool == "eslint" and "security" not in f.get("rule_id", ""):
|
|
kept.append(f)
|
|
elif tool == "dotnet" and not f.get("rule_id", "").startswith("SCS"):
|
|
kept.append(f)
|
|
return {**base, "findings": kept}
|
|
|
|
if agent == "dependency":
|
|
return {
|
|
**base,
|
|
"findings": [f for f in findings if f["tool"] in _DEP_TOOLS],
|
|
"package_diffs": dict(manifest["package_diffs"]),
|
|
}
|
|
|
|
if agent == "secrets":
|
|
return {**base, "findings": [f for f in findings if f["tool"] in _SECRET_TOOLS]}
|
|
|
|
if agent == "consistency":
|
|
kept: list[dict] = []
|
|
for f in findings:
|
|
if f["tool"] != "ruff-idiom":
|
|
continue
|
|
rid = f.get("rule_id", "")
|
|
if rid.startswith(("C901", "PLR0915")):
|
|
continue
|
|
kept.append(f)
|
|
return {**base, "findings": kept}
|
|
|
|
if agent == "walkthrough":
|
|
return {
|
|
"mode": manifest["mode"],
|
|
"base_ref": manifest["base_ref"],
|
|
"head_ref": manifest["head_ref"],
|
|
"default_branch": manifest["default_branch"],
|
|
"language_breakdown": manifest["language_breakdown"],
|
|
"changed_files": list(manifest["changed_files"]),
|
|
"errors": list(manifest["errors"]),
|
|
}
|
|
|
|
if agent == "maintainability":
|
|
kept = []
|
|
for f in findings:
|
|
if f["tool"] in _MAINTAINABILITY_TOOLS:
|
|
kept.append(f)
|
|
elif f["tool"] == "luac":
|
|
kept.append(f)
|
|
elif f["tool"] == "psscriptanalyzer" and f.get("rule_id", "") not in _PSSA_SECURITY_RULES:
|
|
kept.append(f)
|
|
elif f["tool"] == "ruff-idiom" and f.get("rule_id", "").startswith(("C901", "PLR0915")):
|
|
kept.append(f)
|
|
return {**base, "findings": kept}
|
|
|
|
if agent == "gha-reviewer":
|
|
return {**base, "findings": [f for f in findings if f["tool"] in _GHA_TOOLS]}
|
|
|
|
return manifest
|