docs: align scan write-up filenames with the findings schema - #357
docs: align scan write-up filenames with the findings schema#357mldangelo-oai wants to merge 4 commits into
Conversation
The findings schema requires a write-up's file name to equal its
directory slug:
"pattern": "^findings/([a-z0-9][a-z0-9._-]*)/\\1\\.md$"
The orchestrating skills state that convention, but the write-up skill
that actually creates the file asked for an "appropriately-named" report
with two differing example file names, neither of which satisfies the
pattern. The sub-agent prompt template passed only an output directory,
so the constraint never reached the worker.
State the `findings/<slug>/<slug>.md` rule in the skill, the report
format reference, and the sub-agent prompt, while keeping the original
intent that the slug stay descriptive rather than `report`.
Fixes #47
Co-authored-by: Mario Hercules <mariohercules@hotmail.com>
|
Codex Review: Didn't find any major issues. Already looking forward to the next diff. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Security review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
zcrab-oai
left a comment
There was a problem hiding this comment.
Looks good. The scan write-up guidance matches the findings schema, and the previously failing Windows checks are now green.
Summary
8afc257019a311a58709c15c6a3dff9c9f001e86and explicit co-author attribution.findings/<slug>/<slug>.mdonly during Codex Security final reporting sowriteup.reportPathsatisfies the findings schema.main.Fixes #47. Supersedes #204.
Verification
10/10deterministic Promptfoo artifact-policy evaluations: four scan-finalization cases and six standalone disclosure cases.finalize_scan_contract.validate_against_schemaproduction validator.git diff --check origin/main...HEADpassed, and both files remain declared inplugin-files.json.Attribution
The branch is based directly on #204, keeps @mariohercules's original commit, and contains an explicit
Co-authored-bytrailer so the contribution remains attributed when this squash-only repository merges the change.