Files
claude-plugin/plugins/reviews/skills/audit-code/scripts/slicing.py
T
mroberts 37fc3fb291 Fix audit tool bootstrap and add per-run preflight
audit-code install-tools.sh:
- Buffer the opengrep release JSON before grep -m1; curl died with (23)
  under pipefail when grep quit early.
- Use ${m}: in the PowerShell block; $m: parsed as a scope-qualified var.
- On Arch, skip paru/yay when pacman -Q shows every package installed,
  since --needed still invokes sudo.
- Add --check-only (fast, installs nothing, non-zero naming missing tools)
  and --user-only (no system package managers, no sudo).

log-run.py (both skills): put the skill dir on sys.path so running it as
a script from any cwd no longer raises ModuleNotFoundError.

audit-terraform: move deps from requirements.txt into pyproject
dependency groups and add scripts/install-tools.sh (uv sync --group tools,
then check trivy, tflint, tofu, terragrunt, gh).

Both SKILL.md files gain a 0.5 Preflight step and call scripts through
uv run --project ${SKILL_DIR}. tools_unavailable is now a map of tool to
exact install command; audit-terraform skips trivy when absent and stops
with an install hint instead of crashing when tofu/terragrunt is missing.
2026-09-22 15:21:28 -05:00

112 lines
4.0 KiB
Python

"""Per-agent manifest slicing."""
from __future__ import annotations
_TYPE_TOOLS = {"mypy", "tsc"}
_DEP_TOOLS = {"pip-audit", "osv-scanner"}
_SECRET_TOOLS = {"gitleaks"}
_MAINTAINABILITY_TOOLS = {"vulture", "radon", "interrogate", "lizard", "knip", "jscpd", "selene"}
_GHA_TOOLS = {"actionlint", "zizmor"}
_PSSA_SECURITY_RULES = {
"PSAvoidUsingPlainTextForPassword",
"PSAvoidUsingConvertToSecureStringWithPlainText",
"PSAvoidUsingUsernameAndPasswordParams",
"PSUsePSCredentialType",
"PSAvoidUsingInvokeExpression",
"PSAvoidUsingComputerNameHardcoded",
"PSAvoidUsingBrokenHashAlgorithms",
}
def slice_for_agent(manifest: dict, agent: str) -> dict:
"""Return a subset of the manifest scoped to a specific reviewer."""
base = {
"mode": manifest["mode"],
"base_ref": manifest["base_ref"],
"head_ref": manifest["head_ref"],
"default_branch": manifest["default_branch"],
"language_breakdown": manifest["language_breakdown"],
"changed_files": list(manifest["changed_files"]),
"tool_stats": dict(manifest["tool_stats"]),
"tools_unavailable": dict(manifest["tools_unavailable"]),
"errors": list(manifest["errors"]),
}
findings = manifest["findings"]
if agent == "security-triage":
kept: list[dict] = []
for f in findings:
tool = f["tool"]
if tool in {"bandit", "ruff", "opengrep", "luac", "injectionhunter"}:
kept.append(f)
elif tool == "psscriptanalyzer" and f.get("rule_id", "") in _PSSA_SECURITY_RULES:
kept.append(f)
elif tool == "eslint" and "security" in f.get("rule_id", ""):
kept.append(f)
elif tool == "dotnet" and f.get("rule_id", "").startswith("SCS"):
kept.append(f)
return {**base, "findings": kept}
if agent == "type-safety":
kept = []
for f in findings:
tool = f["tool"]
if tool in _TYPE_TOOLS:
kept.append(f)
elif tool == "eslint" and "security" not in f.get("rule_id", ""):
kept.append(f)
elif tool == "dotnet" and not f.get("rule_id", "").startswith("SCS"):
kept.append(f)
return {**base, "findings": kept}
if agent == "dependency":
return {
**base,
"findings": [f for f in findings if f["tool"] in _DEP_TOOLS],
"package_diffs": dict(manifest["package_diffs"]),
}
if agent == "secrets":
return {**base, "findings": [f for f in findings if f["tool"] in _SECRET_TOOLS]}
if agent == "consistency":
kept: list[dict] = []
for f in findings:
if f["tool"] != "ruff-idiom":
continue
rid = f.get("rule_id", "")
if rid.startswith(("C901", "PLR0915")):
continue
kept.append(f)
return {**base, "findings": kept}
if agent == "walkthrough":
return {
"mode": manifest["mode"],
"base_ref": manifest["base_ref"],
"head_ref": manifest["head_ref"],
"default_branch": manifest["default_branch"],
"language_breakdown": manifest["language_breakdown"],
"changed_files": list(manifest["changed_files"]),
"errors": list(manifest["errors"]),
}
if agent == "maintainability":
kept = []
for f in findings:
if f["tool"] in _MAINTAINABILITY_TOOLS:
kept.append(f)
elif f["tool"] == "luac":
kept.append(f)
elif f["tool"] == "psscriptanalyzer" and f.get("rule_id", "") not in _PSSA_SECURITY_RULES:
kept.append(f)
elif f["tool"] == "ruff-idiom" and f.get("rule_id", "").startswith(("C901", "PLR0915")):
kept.append(f)
return {**base, "findings": kept}
if agent == "gha-reviewer":
return {**base, "findings": [f for f in findings if f["tool"] in _GHA_TOOLS]}
return manifest