Skip to content

fix(guardrail): --no-verify bypass (#171) + remove unwired scaffolder agent (#170) - #177

Merged
Chachamaru127 merged 3 commits into
mainfrom
claude/recent-issues-prs-review-NFoQ3
May 29, 2026
Merged

Chachamaru127 merged 3 commits into
mainfrom
claude/recent-issues-prs-review-NFoQ3

Conversation

@Chachamaru127

@Chachamaru127 Chachamaru127 commented May 29, 2026 •

Copy link
Copy Markdown
Owner

This branch bundles two related cleanups from the recent-issues review.


1. fix(guardrail): detect --no-verify / --no-gpg-sign bypass via shell metacharacters (#171)

The R10 guardrail (go/internal/guardrail/helpers.go) used (?:^|\s)...(?:\s|$) — only whitespace counted as a token boundary. Because bash also treats &&, ;, | as separators, the flag stayed effective while slipping past detection:

git commit -m x --no-verify&&echo done   => not detected (bypass)
git commit --no-verify -m x               => detected (normal)

Fix: broaden the boundary class to [\s;&|()<>] for leading/trailing anchors. Detection direction is safe (broader → more likely to deny); trailing non-separators (--no-verify-mode, --no-verifyx) still don't match.

Tests: TestR10_ShellMetacharBypass (8 bypass forms now deny) + TestR10_NoFalsePositive (substring forms stay non-deny). Existing R10 tests unchanged.

Fixes #171


2. refactor(agents): remove unwired scaffolder agent (#170)

agents/scaffolder.md defined analyze/scaffold/update-state modes but had no spawn path — no skill or hook ever called subagent_type="claude-code-harness:scaffolder" (worker/reviewer do). Scaffolding is done inline by harness-setup, state sync by harness-plan; both are interactive Lead flows where worktree isolation is counterproductive. The agent provided no benefit and only misled readers as a registered-but-dead stub.

Removed the agent and cleaned all active references:

  • hooks SubagentStart/SubagentStop matchers (hooks/ + .claude-plugin/, dual-synced)
  • docs: team-composition / agent-frontmatter-policy / distribution-scope / go/DESIGN
  • skills harness-setup / harness-plan / harness-loop + codex/ & opencode/ mirrors
  • tests that asserted scaffolder.md (spec-ssot, upstream-integration, agent-permission-mode, validate-plugin-v3) updated for the removal
  • generic agent_type examples in go comments/test + detect-test-framework.sh

Result: 3-agent topology (worker / reviewer / advisor). History (CHANGELOG / memory archive / v3-architecture) intentionally retained.

Closes #170


Verification

  • go test ./internal/guardrail/ ./internal/lifecycle/ ./internal/state/ — pass
  • scripts/ci/check-consistency.sh — pass (mirror parity OK)
  • scaffolder-referencing tests (spec-ssot, upstream-integration, agent-permission-mode, validate-plugin-v3) — pass
  • Version files left untouched per repo rules; changes recorded under CHANGELOG.md [Unreleased].

Note (pre-existing, out of scope): harness.toml is 4.13.0 while VERSION/plugin.json are 4.13.1 — the v4.13.1 release missed the harness.toml bump, so running sync-plugin-cache.sh reverts plugin.json to 4.13.0. Flagged separately; not addressed here.

https://claude.ai/code/session_01MNT1hAQw9AzGapXdEA3BFp

Summary by CodeRabbit

  • Bug Fixes

    • コミット時フラグ(--no-verify / --no-gpg-sign)の検出を強化し、シェルのメタ文字列を挟んだケースでも回避や誤検出を防ぐよう修正しました。
  • Tests

    • 上記境界条件を検証する回帰テストを追加しました。
  • Documentation

    • エージェント一覧・手順・ポリシー類を現行の役割構成(worker/reviewer/advisor)へ整合させました。
  • Removed

    • scaffolder に関連するドキュメントと検証対象を削除しました。
  • Chores

    • 実行フック/設定の対象絞り込みを反映しました。

Review Change Stack

…acharacters

R10 only treated whitespace as a flag-token boundary, so forms like
`git commit --no-verify&&echo` slipped past the guardrail and could
bypass pre-commit hooks / signature verification. Broaden the boundary
to include shell token separators ([\s;&|()<>]) and add regression
tests for the bypass forms plus false-positive guards.

Fixes #171

https://claude.ai/code/session_01MNT1hAQw9AzGapXdEA3BFp
@coderabbitai

coderabbitai Bot commented May 29, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 6c494b6f-5bc6-4019-b8d7-36d530dea520

📥 Commits

Reviewing files that changed from the base of the PR and between cf2747a and dff1e2e.

📒 Files selected for processing (1)
  • CHANGELOG.md
✅ Files skipped from review due to trivial changes (1)
  • CHANGELOG.md

Walkthrough

--no-verify / --no-gpg-sign の検出をシェルトークン境界に拡張(正規表現更新)し、境界条件をカバーする回帰テストと CHANGELOG 追記を追加。未配線の scaffolder サブエージェントを削除し、関連フック、ドキュメント、スキル記述、テスト・スクリプトを整理。

Changes

ガードレール検出ロジック修正

Layer / File(s) Summary
シェルトークン境界判定の強化
go/internal/guardrail/helpers.go
--no-verify と --no-gpg-sign の正規表現を、空白だけでなくシェルメタキャラクタ(;, &, `
バイパス検出と誤検知防止のテスト
go/internal/guardrail/rules_test.go
TestR10_ShellMetacharBypass でメタキャラクタ直後のフラグ連結(例: --no-verify&&echo)が拒否されること、TestR10_NoFalsePositive でフラグ名を含む長いトークンが誤検知されないことを検証するテストを追加。
変更履歴の記録
CHANGELOG.md
[Unreleased] の ### Fixed に、シェルメタキャラクタ直後の検出漏れ修正、回帰テスト追加、及びバージョン同期修正を記載。

scaffolder サブエージェント削除と関連整理

Layer / File(s) Summary
フック matcher の絞り込み
.claude-plugin/hooks.json, hooks/hooks.json, go/DESIGN.md
SubagentStart / SubagentStop の matcher から scaffolder を除外し、対象を `worker
ドキュメントとポリシー更新
*.md (.claude/rules/opus-4-7-prompt-audit.md, docs/*, agents/* 等)
agent 関連ドキュメントや監査表から scaffolder を削除し、対象一覧を worker/reviewer/advisor に整理。opus-4-7-prompt-audit.md の globs と rg 対象も更新。
コードコメント・内部例示の更新
go/internal/lifecycle/tracker.go, go/internal/lifecycle/tracker_test.go, go/internal/state/schema.go, agents/worker.md
TrackedAgent の例示やテストケース、スキーマのコメントで scaffolder を advisor 等へ差し替え。
スキル記述とテンプレート修正
codex/.codex/..., opencode/skills/..., skills/...
tdd_required 推論や agents 構成説明から scaffolder を除外し、文言を「TDD 推論」等に更新。
テスト・検証スクリプトの調整
tests/*, scripts/*
tests/test-agent-permission-mode.sh, tests/test-claude-upstream-integration.sh, tests/test-spec-ssot-workflow.sh, tests/validate-plugin-v3.sh 等で scaffolder を対象一覧から削除、関連変数を更新。

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Poem

🐰 メタキャラの穴ふさぎに飛び込んで
正規表現で線を引いたよ
古い足場はそっと消え
ドキュメントは整えられた
テストが守る この小さな庭園

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed プルリクエストのタイトルは、2つの主要な変更(ガードレール修正とscaffolderエージェント削除)の両方を明確に示しており、変更内容を正確に要約している。
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/recent-issues-prs-review-NFoQ3

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

Per issue #170 evaluation: agents/scaffolder.md defined analyze/scaffold/
update-state modes but had no spawn path (no skill or hook ever called
subagent_type="claude-code-harness:scaffolder"). Scaffolding is done
inline by harness-setup and state sync by harness-plan; setup/plan are
interactive Lead flows where worktree isolation is counterproductive, so
the agent provided no benefit and only misled readers as a registered-but-
dead stub.

Remove the agent definition and clean up all active references:
- hooks SubagentStart/Stop matchers (hooks/ + .claude-plugin/, dual-synced)
- docs: team-composition, agent-frontmatter-policy, distribution-scope, go/DESIGN
- skills harness-setup/harness-plan/harness-loop + codex/opencode mirrors
- tests that asserted scaffolder.md (spec-ssot, upstream-integration,
  agent-permission-mode, validate-plugin-v3) updated for the removal
- generic agent_type examples in go comments/test + detect-test-framework.sh

Result: 3-agent topology (worker / reviewer / advisor). check-consistency
green, scaffolder-referencing tests pass, go tests pass. History
(CHANGELOG / memory archive / v3-architecture) intentionally retained.

Closes #170

https://claude.ai/code/session_01MNT1hAQw9AzGapXdEA3BFp
@Chachamaru127 Chachamaru127 changed the title fix(guardrail): detect --no-verify/--no-gpg-sign bypass via shell metacharacters fix(guardrail): --no-verify bypass (#171) + remove unwired scaffolder agent (#170) May 29, 2026
…prs-review-NFoQ3

# Conflicts:
#	CHANGELOG.md
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: --no-verify and --no-gpg-sign detection bypassed by shell metacharacters Scaffolder Agent is defined but never spawned by any skill or hook

2 participants