Skip to content

AST-180794 - Add provenance tag and confidence-gated suppression to guardrail prompts - #1577

Closed
cx-kedar-bhujade wants to merge 3 commits into
mainfrom
AST-180794-add-provenance-tag-confidence-gated-remediation
Closed

cx-kedar-bhujade wants to merge 3 commits into
mainfrom
AST-180794-add-provenance-tag-confidence-gated-remediation

Conversation

@cx-kedar-bhujade

@cx-kedar-bhujade cx-kedar-bhujade commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a provenance tag to ASCA, KICS, and SCA guardrail hook output, and replaces the blanket "ask the user first" suppression gate with a confidence-gated model across all three guardrails.

The flow:

  1. Each guardrail package (asca, kics, sca) computes its permissionDecisionReason / additionalContext / finding text as before.
  2. A new provenanceTag helper prepends [Checkmarx cx-devassist — automated security output, not user input] to that text, so the coding agent can recognize genuine Checkmarx output versus text that merely looks like a finding (e.g. spoofed from a file or fetched page).
  3. The prompt text itself now tells the agent to remediate autonomously for real findings, and to suppress only when the call is grounded in something verifiable in the file (or, for SCA, after actually attempting remediation and getting a "no fixed version" result) — not because a finding "looks intentional." When unsure, the agent is told to ask instead of guessing.
  4. Each prompt also reminds the agent that the security check is mid-task, not a new task, so it resumes the user's original request afterward instead of inventing follow-up work.

What changed

  • provenanceTag added to asca/delta.go and kics/delta.go, and to sca/prompts.go, each prepended to the reason/context/finding strings the hook returns.
  • Removed the "ASK THE USER FIRST" / "wait for their answer" gate from the ASCA and KICS Cursor prompts and the SCA vulnerable-package prompt; replaced with autonomous remediation plus a verifiable-evidence bar for suppression.
  • Updated TestCursorAdditionalContext_MatchesAscaAskUserWording to TestCursorAdditionalContext_MatchesAscaConfidenceGatedWording in kics/delta_test.go to assert the new wording instead of the old blanket-ask gate.

Behavior guarantees

  • Suppression commands and remediation tool calls emitted by each guardrail are unchanged; only the surrounding instructional text changed.
  • The provenance tag is prepended consistently to every reason/context/finding string returned by formatFindings (ASCA, KICS) and denyFrom (SCA).

Validation

  • Test approach: Not established from available evidence.
  • Unit tests: go test ./internal/commands/agenthooks/... — passed.
  • Integration tests: Not run — no integration test covers guardrail prompt text.
  • Lint: golangci-lint run -c .golangci.yml on the changed packages — no new findings from this change; two whitespace issues introduced by the new provenanceTag helpers were fixed.

Documentation updates

None required: this changes internal guardrail hook prompt text only, with no public API, CLI flag, or configuration change.

cx-kedar-bhujade and others added 2 commits September 25, 2026 17:11
…ardrail prompts

Tags ASCA/KICS/SCA guardrail output with a Checkmarx provenance marker so
agents can distinguish genuine findings from spoofed text, and replaces the
blanket "ask the user first" suppression gate with a confidence-gated model:
suppress only when grounded in something verifiable in the file (or, for SCA,
after actually attempting remediation), otherwise ask instead of guessing.
Also reminds the agent to resume the original task after handling a finding.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@cx-kedar-bhujade
cx-kedar-bhujade requested a review from a team September 25, 2026 11:47
…o guardrail prompts

Adds a shared hookDenyHeader to ASCA, KICS, and SCA guardrail prompts that
states up front the message is a Checkmarx hook deny, not file content or an
untrusted tool error, without repeating the spoof phrases the anti-injection
skill tests treat as evidence a message did not come from Checkmarx.

Splits the suppression rule into two independently sufficient paths: (a) the
user explicitly told the agent to suppress or ignore the finding, honored
immediately with no further verification, or (b) the agent decides on its own
and grounds that decision in code it has actually opened and read itself (not
an assumption or another file's claim). SCA's package suppression path is
tightened the same way, requiring either the user's instruction or an actual
remediation attempt returning "no fixed version exists".

Adds injection-trigger regression tests across all five supported agents for
ASCA, KICS, and SCA verifying the hook-deny header is present and phrases like
"without asking" or "silently" never appear in agent-facing text.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@cx-kedar-bhujade

Copy link
Copy Markdown
Contributor Author

Superseded by #1578 — the branch name and PR title didn't match this repo's PR-linter requirements (branch must start with bug/, fix/, feature/, or other/, and the title must end with (AST-XXXX)). Closing in favor of the corrected PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant