Skip to content

feat: optional secrets preset and snapshot-bound review gates - #42

Merged
renezander030 merged 2 commits into
masterfrom
feat/trending-october-gates
Oct 1, 2026
Merged

renezander030 merged 2 commits into
masterfrom
feat/trending-october-gates

Conversation

@renezander030

Copy link
Copy Markdown
Owner

Adds skillgate init --preset no-secrets, an optional TruffleHog credential gate with a local infrastructure-name denylist, and an optional snapshot-bound OCR/delegated-review report gate. TruffleHog and OCR stay external; scanner output is redacted, failures block, and these gates always re-evaluate even with --cache. Prepares v0.12.0 metadata and documentation.

The delegated OCR thin slice on real PR #39 reproduced an invalid-policy bypass: opencode allowed a non-shell publish tool when it could not load the policy. The plugin now blocks unknown/MCP tools in that case while preserving built-in repair tools. The historical implementation allows the fixture; the fixed implementation blocks it.

Review reports are explicitly trusted reviewer attestations, not independent proofs that review ran. They must be complete, have no findings/warnings, and match policy, working files, and staged blob IDs. Verified-only credential detection also depends on provider reachability; static pattern gates remain useful for unsupported/unverifiable secrets.

Validation:

  • 168 tests passed; Node 22 coverage: 93.54% lines, 80.75% branches, 97.74% functions.
  • All four repository self-gates passed; npm package dry run includes both runtime modules and the regression example.
  • Pinned TruffleHog v3.97.9: clean native-gate smoke passed in 5.4s; staged public vendor canary blocked in 4.2s with a redacted receipt.
  • Added failure-path tests for scanner availability/errors/timeouts/redaction, staged infrastructure names, review freshness, preset initialization, and invalid-policy publish tools.

@renezander030
renezander030 merged commit 7721ec2 into master Oct 1, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant