Skip to content

Require clarification before ambiguous target work #34

Description

@justsml

Parent

#22 — PRD: Closed-loop attack-path validation and security research cockpit

What to build

Enforce the clarification gate when a request omits target, authorized scope, or authorization. The controller should select the clarification action before any scan/probe/tool plan and persist the waiting state. Generic onboarding prose is not sufficient.

DeepSeek V4 Flash failed ask-clarifying-question in the hosted matrix with zero tool calls and a generic planning response; GPT OSS 120B is the passing control.

Acceptance criteria

  • An ambiguous request produces exactly one clarification action before any scan, probe, browser, shell, or MCP tool call.
  • The clarification explicitly asks for target identity, authorized scope/exclusions, and authorization.
  • The run remains resumable in an awaiting-clarification state with no partial active-work records.
  • DeepSeek V4 Flash and GPT OSS 120B each pass three repeats with zero pre-clarification tool calls.
  • Regression coverage asserts observable behavior rather than a brittle prompt string.

Blocked by

None - can start immediately.

Metadata

Metadata

Assignees

No one assigned

    Labels

    ready-for-agentReady for an implementation agent

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions