Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions dist/detectors/claude-settings.js
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ export async function detectClaudeSettingsDrift(oldRoot, newRoot) {
for (const [permission, line] of newSettings.allow) {
if (!oldSettings.allow.has(permission) && isBroadAllow(permission)) {
findings.push({
kind: 'permission_allow_widened',
kind: 'scope_trail.permission_allow_widened',
severity: severityForAllow(permission),
file: CLAUDE_SETTINGS_FILE,
line,
Expand All @@ -21,7 +21,7 @@ export async function detectClaudeSettingsDrift(oldRoot, newRoot) {
for (const permission of oldSettings.deny.keys()) {
if (!newSettings.deny.has(permission)) {
findings.push({
kind: 'permission_deny_removed',
kind: 'scope_trail.permission_deny_removed',
severity: severityForRemovedDeny(permission),
file: CLAUDE_SETTINGS_FILE,
subject: permission,
Expand All @@ -33,7 +33,7 @@ export async function detectClaudeSettingsDrift(oldRoot, newRoot) {
for (const [hookName, oldCommands] of oldSettings.hookCommands) {
if (!newSettings.hookCommands.has(hookName)) {
findings.push({
kind: 'hook_removed',
kind: 'scope_trail.hook_removed',
severity: isHighImpactHook(hookName) ? 'high' : 'medium',
file: CLAUDE_SETTINGS_FILE,
subject: hookName,
Expand All @@ -48,7 +48,7 @@ export async function detectClaudeSettingsDrift(oldRoot, newRoot) {
const changed = [...newCommands].filter((command) => !oldCommands.has(command));
if (changed.length > 0 && newCommands.size === oldCommands.size) {
findings.push({
kind: 'hook_command_changed',
kind: 'scope_trail.hook_command_changed',
severity: isHighImpactHook(hookName) ? 'high' : 'medium',
file: CLAUDE_SETTINGS_FILE,
subject: hookName,
Expand All @@ -63,7 +63,7 @@ export async function detectClaudeSettingsDrift(oldRoot, newRoot) {
for (const hookName of newSettings.hookCommands.keys()) {
if (!oldSettings.hookCommands.has(hookName)) {
findings.push({
kind: 'hook_added',
kind: 'scope_trail.hook_added',
severity: 'low',
file: CLAUDE_SETTINGS_FILE,
subject: hookName,
Expand Down
8 changes: 4 additions & 4 deletions dist/detectors/codex-config.js
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ export async function detectCodexConfigDrift(oldRoot, newRoot) {
const newEntry = newConfig.get(key);
if (newEntry && sandboxRank(newEntry.value) > sandboxRank(oldEntry?.value)) {
findings.push({
kind: 'codex_sandbox_widened',
kind: 'scope_trail.codex_sandbox_widened',
severity: sandboxRank(newEntry.value) >= 3 ? 'critical' : 'high',
file: CODEX_CONFIG_FILE,
line: newEntry.line,
Expand All @@ -25,7 +25,7 @@ export async function detectCodexConfigDrift(oldRoot, newRoot) {
const newApproval = newConfig.get('approval_policy');
if (newApproval && approvalRank(newApproval.value) > approvalRank(oldApproval?.value)) {
findings.push({
kind: 'codex_approval_weakened',
kind: 'scope_trail.codex_approval_weakened',
severity: newApproval.value === 'never' ? 'high' : 'medium',
file: CODEX_CONFIG_FILE,
line: newApproval.line,
Expand All @@ -39,7 +39,7 @@ export async function detectCodexConfigDrift(oldRoot, newRoot) {
const newEntry = newConfig.get(key);
if (newEntry?.value === 'true' && oldEntry?.value !== 'true') {
findings.push({
kind: 'codex_network_enabled',
kind: 'scope_trail.codex_network_enabled',
severity: 'medium',
file: CODEX_CONFIG_FILE,
line: newEntry.line,
Expand All @@ -53,7 +53,7 @@ export async function detectCodexConfigDrift(oldRoot, newRoot) {
const newTrust = newConfig.get('projects.trust_level');
if (newTrust?.value === 'trusted' && oldTrust?.value !== 'trusted') {
findings.push({
kind: 'codex_project_trusted',
kind: 'scope_trail.codex_project_trusted',
severity: 'high',
file: CODEX_CONFIG_FILE,
line: newTrust.line,
Expand Down
14 changes: 7 additions & 7 deletions dist/detectors/mcp.js
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
const oldServer = oldServers[name];
if (!oldServer) {
findings.push({
kind: 'mcp_server_added',
kind: 'scope_trail.mcp_server_added',
severity: 'high',
file: config.path,
line: newServer.line,
Expand All @@ -66,7 +66,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
}
else if (serverCommand(newServer) !== serverCommand(oldServer)) {
findings.push({
kind: 'mcp_server_command_changed',
kind: 'scope_trail.mcp_server_command_changed',
severity: 'medium',
file: config.path,
line: lineForServerCommand(newServer) ?? newServer.line,
Expand All @@ -77,7 +77,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
}
if ((!oldServer || serverCommand(newServer) !== serverCommand(oldServer)) && isUnpinnedCommand(newServer)) {
findings.push({
kind: 'unpinned_mcp_command',
kind: 'scope_trail.unpinned_mcp_command',
severity: 'high',
file: config.path,
line: lineForUnpinnedCommand(newServer) ?? newServer.line,
Expand All @@ -97,7 +97,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
const changed = oldServer && serverCommand(newServer) !== serverCommand(oldServer);
if (!oldServer) {
findings.push({
kind: 'mcp_sample_server_added',
kind: 'scope_trail.mcp_sample_server_added',
severity: 'low',
file: path,
line: newServer.line,
Expand All @@ -108,7 +108,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
}
else if (changed) {
findings.push({
kind: 'mcp_sample_server_command_changed',
kind: 'scope_trail.mcp_sample_server_command_changed',
severity: 'low',
file: path,
line: lineForServerCommand(newServer) ?? newServer.line,
Expand All @@ -119,7 +119,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
}
if ((!oldServer || changed) && isUnpinnedCommand(newServer)) {
findings.push({
kind: 'mcp_sample_unpinned_command',
kind: 'scope_trail.mcp_sample_unpinned_command',
severity: severityForSampleCommandRisk(newServer),
file: path,
line: lineForUnpinnedCommand(newServer) ?? newServer.line,
Expand All @@ -131,7 +131,7 @@ export async function detectMcpDrift(oldRoot, newRoot) {
const endpoint = remoteEndpoint(newServer);
if ((!oldServer || changed) && endpoint) {
findings.push({
kind: 'mcp_sample_remote_endpoint',
kind: 'scope_trail.mcp_sample_remote_endpoint',
severity: 'medium',
file: path,
line: lineForRemoteEndpoint(newServer) ?? newServer.line,
Expand Down
2 changes: 1 addition & 1 deletion package-lock.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
{
"name": "scopetrail",
"version": "0.1.11",
Expand All @@ -11,7 +11,7 @@
"test": "node --test"
},
"dependencies": {
"agent-gov-core": "github:Conalh/agent-gov-core#v0.1.2"
"agent-gov-core": "github:Conalh/agent-gov-core#v0.2.0"

Check warning on line 14 in package.json

View workflow job for this annotation

GitHub Actions / scope-review

TaskBound low scope creep

Changed dependency agent-gov-core from github:Conalh/agent-gov-core#v0.1.2 to github:Conalh/agent-gov-core#v0.2.0. Recommendation: Review whether the version change is in scope for the task.
},
"devDependencies": {
"@types/node": "^24.0.0",
Expand Down
10 changes: 5 additions & 5 deletions src/detectors/claude-settings.ts
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ export async function detectClaudeSettingsDrift(oldRoot: string, newRoot: string
for (const [permission, line] of newSettings.allow) {
if (!oldSettings.allow.has(permission) && isBroadAllow(permission)) {
findings.push({
kind: 'permission_allow_widened',
kind: 'scope_trail.permission_allow_widened',
severity: severityForAllow(permission),
file: CLAUDE_SETTINGS_FILE,
line,
Expand All @@ -26,7 +26,7 @@ export async function detectClaudeSettingsDrift(oldRoot: string, newRoot: string
for (const permission of oldSettings.deny.keys()) {
if (!newSettings.deny.has(permission)) {
findings.push({
kind: 'permission_deny_removed',
kind: 'scope_trail.permission_deny_removed',
severity: severityForRemovedDeny(permission),
file: CLAUDE_SETTINGS_FILE,
subject: permission,
Expand All @@ -39,7 +39,7 @@ export async function detectClaudeSettingsDrift(oldRoot: string, newRoot: string
for (const [hookName, oldCommands] of oldSettings.hookCommands) {
if (!newSettings.hookCommands.has(hookName)) {
findings.push({
kind: 'hook_removed',
kind: 'scope_trail.hook_removed',
severity: isHighImpactHook(hookName) ? 'high' : 'medium',
file: CLAUDE_SETTINGS_FILE,
subject: hookName,
Expand All @@ -55,7 +55,7 @@ export async function detectClaudeSettingsDrift(oldRoot: string, newRoot: string
const changed = [...newCommands].filter((command) => !oldCommands.has(command));
if (changed.length > 0 && newCommands.size === oldCommands.size) {
findings.push({
kind: 'hook_command_changed',
kind: 'scope_trail.hook_command_changed',
severity: isHighImpactHook(hookName) ? 'high' : 'medium',
file: CLAUDE_SETTINGS_FILE,
subject: hookName,
Expand All @@ -71,7 +71,7 @@ export async function detectClaudeSettingsDrift(oldRoot: string, newRoot: string
for (const hookName of newSettings.hookCommands.keys()) {
if (!oldSettings.hookCommands.has(hookName)) {
findings.push({
kind: 'hook_added',
kind: 'scope_trail.hook_added',
severity: 'low',
file: CLAUDE_SETTINGS_FILE,
subject: hookName,
Expand Down
8 changes: 4 additions & 4 deletions src/detectors/codex-config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ export async function detectCodexConfigDrift(oldRoot: string, newRoot: string):
const newEntry = newConfig.get(key);
if (newEntry && sandboxRank(newEntry.value) > sandboxRank(oldEntry?.value)) {
findings.push({
kind: 'codex_sandbox_widened',
kind: 'scope_trail.codex_sandbox_widened',
severity: sandboxRank(newEntry.value) >= 3 ? 'critical' : 'high',
file: CODEX_CONFIG_FILE,
line: newEntry.line,
Expand All @@ -35,7 +35,7 @@ export async function detectCodexConfigDrift(oldRoot: string, newRoot: string):
const newApproval = newConfig.get('approval_policy');
if (newApproval && approvalRank(newApproval.value) > approvalRank(oldApproval?.value)) {
findings.push({
kind: 'codex_approval_weakened',
kind: 'scope_trail.codex_approval_weakened',
severity: newApproval.value === 'never' ? 'high' : 'medium',
file: CODEX_CONFIG_FILE,
line: newApproval.line,
Expand All @@ -50,7 +50,7 @@ export async function detectCodexConfigDrift(oldRoot: string, newRoot: string):
const newEntry = newConfig.get(key);
if (newEntry?.value === 'true' && oldEntry?.value !== 'true') {
findings.push({
kind: 'codex_network_enabled',
kind: 'scope_trail.codex_network_enabled',
severity: 'medium',
file: CODEX_CONFIG_FILE,
line: newEntry.line,
Expand All @@ -65,7 +65,7 @@ export async function detectCodexConfigDrift(oldRoot: string, newRoot: string):
const newTrust = newConfig.get('projects.trust_level');
if (newTrust?.value === 'trusted' && oldTrust?.value !== 'trusted') {
findings.push({
kind: 'codex_project_trusted',
kind: 'scope_trail.codex_project_trusted',
severity: 'high',
file: CODEX_CONFIG_FILE,
line: newTrust.line,
Expand Down
14 changes: 7 additions & 7 deletions src/detectors/mcp.ts
Original file line number Diff line number Diff line change
Expand Up @@ -74,7 +74,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<

if (!oldServer) {
findings.push({
kind: 'mcp_server_added',
kind: 'scope_trail.mcp_server_added',
severity: 'high',
file: config.path,
line: newServer.line,
Expand All @@ -84,7 +84,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<
});
} else if (serverCommand(newServer) !== serverCommand(oldServer)) {
findings.push({
kind: 'mcp_server_command_changed',
kind: 'scope_trail.mcp_server_command_changed',
severity: 'medium',
file: config.path,
line: lineForServerCommand(newServer) ?? newServer.line,
Expand All @@ -96,7 +96,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<

if ((!oldServer || serverCommand(newServer) !== serverCommand(oldServer)) && isUnpinnedCommand(newServer)) {
findings.push({
kind: 'unpinned_mcp_command',
kind: 'scope_trail.unpinned_mcp_command',
severity: 'high',
file: config.path,
line: lineForUnpinnedCommand(newServer) ?? newServer.line,
Expand All @@ -119,7 +119,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<

if (!oldServer) {
findings.push({
kind: 'mcp_sample_server_added',
kind: 'scope_trail.mcp_sample_server_added',
severity: 'low',
file: path,
line: newServer.line,
Expand All @@ -129,7 +129,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<
});
} else if (changed) {
findings.push({
kind: 'mcp_sample_server_command_changed',
kind: 'scope_trail.mcp_sample_server_command_changed',
severity: 'low',
file: path,
line: lineForServerCommand(newServer) ?? newServer.line,
Expand All @@ -141,7 +141,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<

if ((!oldServer || changed) && isUnpinnedCommand(newServer)) {
findings.push({
kind: 'mcp_sample_unpinned_command',
kind: 'scope_trail.mcp_sample_unpinned_command',
severity: severityForSampleCommandRisk(newServer),
file: path,
line: lineForUnpinnedCommand(newServer) ?? newServer.line,
Expand All @@ -154,7 +154,7 @@ export async function detectMcpDrift(oldRoot: string, newRoot: string): Promise<
const endpoint = remoteEndpoint(newServer);
if ((!oldServer || changed) && endpoint) {
findings.push({
kind: 'mcp_sample_remote_endpoint',
kind: 'scope_trail.mcp_sample_remote_endpoint',
severity: 'medium',
file: path,
line: lineForRemoteEndpoint(newServer) ?? newServer.line,
Expand Down
8 changes: 4 additions & 4 deletions test/claude-settings-drift.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,10 @@ test('detects Claude settings permission drift', async () => {
assert.deepEqual(
findings.map((finding) => finding.kind),
[
'permission_allow_widened',
'permission_allow_widened',
'permission_deny_removed',
'hook_removed'
'scope_trail.permission_allow_widened',
'scope_trail.permission_allow_widened',
'scope_trail.permission_deny_removed',
'scope_trail.hook_removed'
]
);
assert.equal(findings[0].subject, 'Bash(npm *)');
Expand Down
12 changes: 6 additions & 6 deletions test/cli-output.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -25,12 +25,12 @@ test('CLI emits JSON permission drift report', async () => {
assert.deepEqual(
report.findings.map((finding) => finding.kind),
[
'mcp_server_added',
'unpinned_mcp_command',
'permission_allow_widened',
'permission_allow_widened',
'permission_deny_removed',
'hook_removed'
'scope_trail.mcp_server_added',
'scope_trail.unpinned_mcp_command',
'scope_trail.permission_allow_widened',
'scope_trail.permission_allow_widened',
'scope_trail.permission_deny_removed',
'scope_trail.hook_removed'
]
);
});
Expand Down
8 changes: 4 additions & 4 deletions test/codex-config-drift.test.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,10 @@ test('detects Codex config permission drift', async () => {
assert.deepEqual(
findings.map((finding) => [finding.kind, finding.subject, finding.severity, finding.line]),
[
['codex_sandbox_widened', 'sandbox_mode', 'critical', 1],
['codex_approval_weakened', 'approval_policy', 'high', 2],
['codex_network_enabled', 'sandbox_workspace_write.network_access', 'medium', 5],
['codex_project_trusted', 'projects.trust_level', 'high', 8]
['scope_trail.codex_sandbox_widened', 'sandbox_mode', 'critical', 1],
['scope_trail.codex_approval_weakened', 'approval_policy', 'high', 2],
['scope_trail.codex_network_enabled', 'sandbox_workspace_write.network_access', 'medium', 5],
['scope_trail.codex_project_trusted', 'projects.trust_level', 'high', 8]
]
);
});
Loading