forked from bchanot/claude
feat(agents): security-auditor SAST gate + onboard/audit-delta grafts (verify-loops lot 3)
agents/security-auditor.md: fresh read-only-on-code SAST gate. Pinned rulesets p/security-audit + p/secrets + p/owasp-top-ten (owasp REQUIRED — measured: the 2-ruleset baseline misses SQLi + path-traversal entirely on realistic Flask code), never --config auto, never auto login (BDR-048). Severity map: secrets ERROR → CRITICAL, other ERROR → HIGH (block), WARNING/INFO → reported. gate mode (diff, no Write) vs audit mode (Write only to REPORT, rule-locked). DEGRADED (semgrep absent) still runs the checklist and still blocks — never a vacuous pass (LRN-048). Anti-gaming: a new un-gated nosemgrep suppression is BLOCKING. PROOF mandatory, mute auditor never a PASS, blind (no iteration history), blocks HIGH/CRITICAL only (LRN-047). Grafts: onboard STEP 6 L3a dispatches it in audit mode (report .onboard-audit/semgrep.md) in BOTH gstack branches — complement to cso (cso is a gstack submodule, unmodifiable); synthesis picks it up via the existing .onboard-audit/ sweep. audit-delta security axis runs the SAST pass first, folds findings into the existing gate/fix/re-verify flow. lib/tests/security-auditor.test.sh: 28 structure locks green, shellcheck clean. Behavioral dogfood (fresh agents on a planted fixture): BLOCK(9) on the vuln commit (2 secrets→CRITICAL, semgrep+checklist complementarity — checklist caught the 6 semgrep missed off-context); BLOCK(1) on a new nosemgrep suppression (understood semgrep's 0 was the mask); DEGRADED → BLOCK(7) on grep-detectable secrets with semgrep hidden. FP measured on real repos (faunosteo, game): owasp adds only hygiene findings, contained by diff-scoping. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XpphkdTosUzokBDNG7PToS
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
ff13abfda5
commit
2b297bd44a
+26
-2
@@ -486,6 +486,29 @@ bash $HOME/.claude/lib/toggle-external.sh list 2>/dev/null | grep -E "^gstack\s+
|
||||
)
|
||||
```
|
||||
|
||||
#### Dispatch semgrep SAST — `security-auditor` (TOUJOURS, complément de cso)
|
||||
|
||||
En complément de cso (ON) OU du fallback (OFF) — un moteur SAST déterministe
|
||||
à côté de l'audit grep/raisonné. cso est un submodule gstack non modifiable ;
|
||||
semgrep vit dans cet agent local. Lancé dans les DEUX branches gstack.
|
||||
|
||||
```
|
||||
Agent(
|
||||
subagent_type="security-auditor",
|
||||
description="Onboard — semgrep SAST audit (report-only)",
|
||||
prompt="""
|
||||
MODE: audit
|
||||
SCOPE: <PROJECT_ROOT>
|
||||
REPORT: <PROJECT_ROOT>/.onboard-audit/semgrep.md
|
||||
CONTEXT: <PROJECT_ROOT>/.onboard-audit/archetype-context.md
|
||||
Follow agents/security-auditor.md exactly. Pinned rulesets only, no login.
|
||||
Write ONLY to the REPORT path. End stdout with REPORT_WRITTEN: <path>.
|
||||
"""
|
||||
)
|
||||
```
|
||||
Si semgrep absent → l'agent rend DEGRADED (checklist seule) + recommande
|
||||
`make plugin` ; NON bloquant en onboard (audit, pas gate).
|
||||
|
||||
#### Dispatch doc-syncer (si `doc` dans audit_stack)
|
||||
```
|
||||
Agent(
|
||||
@@ -511,9 +534,10 @@ Agent(
|
||||
|
||||
### Après les 3 dispatches
|
||||
|
||||
Attendre la fin des 3 subagents. Vérifier que les 3 fichiers existent et sont non vides :
|
||||
Attendre la fin des subagents. Vérifier que les fichiers existent et sont non vides
|
||||
(semgrep.md inclus — DEGRADED reste non vide : il porte le résultat checklist) :
|
||||
```bash
|
||||
for f in .onboard-audit/{code-clean,cso,doc}.md; do
|
||||
for f in .onboard-audit/{code-clean,cso,semgrep,doc}.md; do
|
||||
[ -s "$f" ] && echo "OK $f" || echo "MISSING $f"
|
||||
done
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user