Skip to content

audit-instructions: adopt (check, claim, sites) finding identity and admit I30 to I33 to --persist-findings #4116

Description

@kyle-sexton

Sub-issue of #4113 (report contract).

Problem

Findings have no identity that survives a re-run, so nothing filed from a report can be matched against the next run's output, suppressed, or carried forward. --persist-findings emits only I28 and I29 (the two scanner-seeded families), and scripts/emit-findings.sh consumes scanner rows only; the eight unemitted families are declined no-severity-crosswalk-row.

Change

Two separable items in one PR.

  1. Identity adoption. Findings adopt plugins/claude-config/skills/audit-pass/reference/finding-identity.md: identity = (check, claim, sites), sites as sorted (surface, anchor) pairs, content-derived anchor/v1 anchors with the heading-path occurrence discriminator. Each check gains a claim template (free prose in claim is a hard error). A cross-surface I15 conflict is one finding with two sites. primary_site and presentation fields stay outside the hash.
  2. Crosswalk admission. Four new rows in the detector-findings crosswalk for I30, I31, I32, I33, each arguing its tier from plugins/review/context/severity.md's tests, each Auto-applicable: No (surface-only; the skill has no fix action), with an emitting fall-through for the judgment-selected rules (I31 and I33 are behavioral and unseeded), a second emit path in emit-findings.sh fed by lane findings beside the scanner-fed one, a Confidence value the contract defines for a model-lane finding (today the contract fixes it to high because a deterministic detector fired), and a counted decline for frontmatter-located I32 rows (the relay is body-scoped; at least one measured I32 row sits on plugins/fleet/skills/reach/SKILL.md:2).

Acceptance criteria

  • Two runs over an unchanged tree yield identical finding_id values; editing an I33 opener changes that finding's id; an I15 conflict is one finding with two sites.
  • scripts/check-detector-findings-crosswalk.sh passes with the four new rows.
  • --persist-findings emits I30, I31, I32, I33 rows from lane findings; frontmatter-located I32 rows are declined and counted, never silently dropped.
  • scripts/affected-tests.sh --run passes.

Sources

  • plugins/claude-config/skills/audit-pass/reference/finding-identity.md
  • docs/conventions/finding-suppression/README.md ("How a consumer derives the id and its constituents is that consumer's own contract")
  • docs/conventions/detector-findings/README.md (admission test; "A rule set whose selection involves judgment is fail-safe toward EMITTING")
  • plugins/claude-config/skills/audit-instructions/context/persist-findings.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.priority: mediumReal value, no hard deadline; normal backlog flow.status: readyTriaged, unblocked, and fully specified; eligible to pick up.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions