Skip to content

Unknown --matchers slugs are silently ignored #34

Description

@divyamagrawal06

What happened

When deepsec scan --matchers includes an unknown matcher slug, deepsec silently ignores the unknown slug and scans with only the known matchers. This makes an invalid scan request look successful.

Reproduction

deepsec scan \
  --project-id matcher-repro \
  --root fixtures/vulnerable-app \
  --matchers xss,does-not-exist

Expected vs actual

Expected: deepsec should fail clearly and name the unknown matcher slug.
Actual: deepsec runs only the xss matcher, completes successfully, and exits 0.

Environment

  • deepsec version (pnpm deepsec --version):
  • Node version (node --version):
  • OS: Linux (Ubuntu) through WSL (Win 11)
  • Agent backend (claude-agent-sdk / codex): N/A
  • Model: N/A

Logs

xss: 2 match(es)
Scan complete
EXIT_STATUS=0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions