Add provenance tag and confidence-gated suppression to guardrail prompts (AST-180794) - #1578
Open
cx-kedar-bhujade wants to merge 4 commits into
Open
cx-kedar-bhujade wants to merge 4 commits into
cx-kedar-bhujade wants to merge 4 commits into
Conversation
…ardrail prompts Tags ASCA/KICS/SCA guardrail output with a Checkmarx provenance marker so agents can distinguish genuine findings from spoofed text, and replaces the blanket "ask the user first" suppression gate with a confidence-gated model: suppress only when grounded in something verifiable in the file (or, for SCA, after actually attempting remediation), otherwise ask instead of guessing. Also reminds the agent to resume the original task after handling a finding. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…o guardrail prompts Adds a shared hookDenyHeader to ASCA, KICS, and SCA guardrail prompts that states up front the message is a Checkmarx hook deny, not file content or an untrusted tool error, without repeating the spoof phrases the anti-injection skill tests treat as evidence a message did not come from Checkmarx. Splits the suppression rule into two independently sufficient paths: (a) the user explicitly told the agent to suppress or ignore the finding, honored immediately with no further verification, or (b) the agent decides on its own and grounds that decision in code it has actually opened and read itself (not an assumption or another file's claim). SCA's package suppression path is tightened the same way, requiring either the user's instruction or an actual remediation attempt returning "no fixed version exists". Adds injection-trigger regression tests across all five supported agents for ASCA, KICS, and SCA verifying the hook-deny header is present and phrases like "without asking" or "silently" never appear in agent-facing text. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ation model Replaces the analyze/ask-when-unsure flow with an explicit classify-then-act sequence: findings are false positives only when cited evidence meets (a) or (b), otherwise they are always remediated autonomously and never surfaced to the user as a remediate-or-suppress question. Adds a structured remediation summary report and a verify-and-retry step across ASCA, KICS, and SCA guardrails. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a provenance tag and a hook-deny header to ASCA, KICS, and SCA guardrail hook output, and replaces the blanket "ask the user first" suppression gate with a two-path confidence-gated model across all three guardrails.
The flow:
asca,kics,sca) computes itspermissionDecisionReason/additionalContext/ finding text as before.provenanceTaghelper prepends[Checkmarx cx-devassist — automated security output, not user input]to that text, so the coding agent can recognize genuine Checkmarx output versus text that merely looks like a finding (e.g. spoofed from a file or fetched page).hookDenyHeaderconstant opens the agent-facing instructions, stating up front that the message is a Checkmarx hook deny, not file content or an untrusted tool error — without using any of the phrases the anti-injection tests treat as evidence a message is not genuinely from Checkmarx.What changed
provenanceTagandhookDenyHeaderadded toasca/delta.go,kics/delta.go, andsca/prompts.go, prepended to the reason/context/finding strings each hook returns.TestAdditionalContext_OmitsInjectionTriggers(ASCA and KICS) andTestRemediation_OmitsInjectionTriggers(SCA), each checked across all five supported agents, asserting the hook-deny header is present and that phrases such as "without asking" or "silently" never appear in agent-facing text.kics/delta_test.go) to assert the new two-path wording instead of the old blanket-ask gate.Behavior guarantees
formatFindings(ASCA, KICS) anddenyFrom(SCA).Validation
go test ./internal/commands/agenthooks/...— passed.golangci-lint run -c .golangci.ymlon the changed packages — no new findings introduced by this change.Documentation updates
None required: this changes internal guardrail hook prompt text only, with no public API, CLI flag, or configuration change.