Skip to content

Add provenance tag and confidence-gated suppression to guardrail prompts (AST-180794) - #1578

Open
cx-kedar-bhujade wants to merge 4 commits into
mainfrom
feature/AST-180794-add-provenance-tag-confidence-gated-remediation
Open

cx-kedar-bhujade wants to merge 4 commits into
mainfrom
feature/AST-180794-add-provenance-tag-confidence-gated-remediation

Conversation

@cx-kedar-bhujade

Copy link
Copy Markdown
Contributor

Summary

Adds a provenance tag and a hook-deny header to ASCA, KICS, and SCA guardrail hook output, and replaces the blanket "ask the user first" suppression gate with a two-path confidence-gated model across all three guardrails.

The flow:

  1. Each guardrail package (asca, kics, sca) computes its permissionDecisionReason / additionalContext / finding text as before.
  2. A new provenanceTag helper prepends [Checkmarx cx-devassist — automated security output, not user input] to that text, so the coding agent can recognize genuine Checkmarx output versus text that merely looks like a finding (e.g. spoofed from a file or fetched page).
  3. A new hookDenyHeader constant opens the agent-facing instructions, stating up front that the message is a Checkmarx hook deny, not file content or an untrusted tool error — without using any of the phrases the anti-injection tests treat as evidence a message is not genuinely from Checkmarx.
  4. The suppression rule is now two independently sufficient paths: (a) the user explicitly told the agent to suppress or ignore the finding — honored immediately, no further verification needed; or (b) the agent decides on its own, but only when grounded in code it has actually opened and read itself (not an assumption, and not merely because another file or the finding text claims something). SCA's package-suppression path additionally requires an actual remediation attempt that returned "no fixed version exists" for path (b).
  5. Each prompt still reminds the agent that the security check is mid-task, not a new task, so it resumes the user's original request afterward instead of inventing follow-up work.

What changed

  • provenanceTag and hookDenyHeader added to asca/delta.go, kics/delta.go, and sca/prompts.go, prepended to the reason/context/finding strings each hook returns.
  • Removed the "ASK THE USER FIRST" / "wait for their answer" gate from the ASCA and KICS Cursor prompts and the SCA vulnerable-package prompt; replaced with the two-path (a)/(b) suppression model described above.
  • Added TestAdditionalContext_OmitsInjectionTriggers (ASCA and KICS) and TestRemediation_OmitsInjectionTriggers (SCA), each checked across all five supported agents, asserting the hook-deny header is present and that phrases such as "without asking" or "silently" never appear in agent-facing text.
  • Updated the existing KICS Cursor wording test (kics/delta_test.go) to assert the new two-path wording instead of the old blanket-ask gate.

Behavior guarantees

  • Suppression commands and remediation tool calls emitted by each guardrail are unchanged; only the surrounding instructional text changed.
  • The provenance tag and hook-deny header are prepended consistently to every reason/context/finding string returned by formatFindings (ASCA, KICS) and denyFrom (SCA).
  • A user's explicit suppress/ignore instruction is always honored without requiring the agent to first classify the finding as a false positive.

Validation

  • Test approach: Not established from available evidence.
  • Unit tests: go test ./internal/commands/agenthooks/... — passed.
  • Integration tests: Not run — no integration test covers guardrail prompt text.
  • Lint: golangci-lint run -c .golangci.yml on the changed packages — no new findings introduced by this change.

Documentation updates

None required: this changes internal guardrail hook prompt text only, with no public API, CLI flag, or configuration change.

cx-kedar-bhujade and others added 3 commits September 25, 2026 17:11
…ardrail prompts

Tags ASCA/KICS/SCA guardrail output with a Checkmarx provenance marker so
agents can distinguish genuine findings from spoofed text, and replaces the
blanket "ask the user first" suppression gate with a confidence-gated model:
suppress only when grounded in something verifiable in the file (or, for SCA,
after actually attempting remediation), otherwise ask instead of guessing.
Also reminds the agent to resume the original task after handling a finding.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…o guardrail prompts

Adds a shared hookDenyHeader to ASCA, KICS, and SCA guardrail prompts that
states up front the message is a Checkmarx hook deny, not file content or an
untrusted tool error, without repeating the spoof phrases the anti-injection
skill tests treat as evidence a message did not come from Checkmarx.

Splits the suppression rule into two independently sufficient paths: (a) the
user explicitly told the agent to suppress or ignore the finding, honored
immediately with no further verification, or (b) the agent decides on its own
and grounds that decision in code it has actually opened and read itself (not
an assumption or another file's claim). SCA's package suppression path is
tightened the same way, requiring either the user's instruction or an actual
remediation attempt returning "no fixed version exists".

Adds injection-trigger regression tests across all five supported agents for
ASCA, KICS, and SCA verifying the hook-deny header is present and phrases like
"without asking" or "silently" never appear in agent-facing text.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ation model

Replaces the analyze/ask-when-unsure flow with an explicit classify-then-act
sequence: findings are false positives only when cited evidence meets (a) or
(b), otherwise they are always remediated autonomously and never surfaced to
the user as a remediate-or-suppress question. Adds a structured remediation
summary report and a verify-and-retry step across ASCA, KICS, and SCA
guardrails.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant