Skip to content

Add scanner production safety gates#1646

Open
yanziwei wants to merge 1 commit into
UnitOneAI:mainfrom
yanziwei:improve/scanner-production-safety
Open

Add scanner production safety gates#1646
yanziwei wants to merge 1 commit into
UnitOneAI:mainfrom
yanziwei:improve/scanner-production-safety

Conversation

@yanziwei
Copy link
Copy Markdown

@yanziwei yanziwei commented Jun 7, 2026

Summary

Implements the production scan safety gaps documented in #1645 for scanner-tuning.

Changes:

  • Adds a Production Scan Safety Gate covering canary scans, lockout-safe authentication, state-changing web/API controls, target health monitoring, abort thresholds, scanner allowlist governance, fragile system handling, and cloud/API quota budgets.
  • Adds SCAN-SAFE-* finding identifiers for common scanner safety failures.
  • Extends the authentication record with lockout guardrails.
  • Adds a Production Scan Safety section to the output report template.
  • Adds a common pitfall warning that non-DoS credentialed scans can still cause outages.
  • Bumps the skill version to 1.1.0.

Validation

  • git diff --check
  • Markdown fence-balance check for skills/vuln-management/scanner-tuning/SKILL.md
  • ASCII check for skills/vuln-management/scanner-tuning/SKILL.md
  • Required marker checks for SCAN-SAFE-01, Production Scan Safety, Abort thresholds, and Lockout Guardrails

Bounty

Requested as an Improver bounty submission for #1645. Payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant