Skip to content

audit-dead-code: when coverage is incomplete, offer to file an issue or research and install a detector #4524

Description

@kyle-sexton

Summary

When a language has no lane, or a lane's tool is not installed, code-tidying:audit-dead-code
0.23.2 reports the lane as skipped and stops there. The owner's intent is that the skill covers
all source code accurately. So when it cannot cover some code, it should close the gap instead of
only labeling it.

Current limits, from the skill itself:

  • "Never fetch": a lane with no local binary is skipped, and no package runner is invoked
    (SKILL.md "Hard rules").
  • Rust and .NET are permanently out of scope because their detectors build or execute project code.
    The same reason covers clangd and jdtls (context/lanes.md:124-130).
  • Languages with no lane at all get no mention (see the sibling coverage-accounting issue).

Fix

When coverage is incomplete, the skill offers a path per gap. The default stays read-only, and
every action needs the user's consent:

  1. Name the gap: which files, which language, and why (no lane, tool not installed, excluded by
    policy).
  2. Offer to file an issue against this plugin for a language or tool the skill does not
    support, pre-filled with the file count and language.
  3. Offer to research and install: run /discovery:research to pick a detector for the language,
    show the choice and its install command, and install and run it only after the user approves.
    Record the detector's precision as unmeasured until the trap fixtures cover it.
  4. Revisit the build-free rule as an opt-in, not a default. For Rust, .NET, C/C++, and Java,
    offer a consent-gated lane that may build the project. The consent prompt states plainly that
    this executes repo code (build.rs, proc macros, MSBuild targets). Keep it off for untrusted
    repos.

This changes the "Never fetch" hard rule. The rule's safety property (no silent network or code
execution) is kept by the consent gate, not by refusing.

Verification

  • Done when a run over a fixture with a language that has no lane prints the gap and offers both
    paths, and no install or build happens without an explicit yes.
  • The research-and-install path is exercised once end to end, for example on a repo with Java and
    no detector, and the chosen tool's output is parsed into the existing record schema.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions