Skip to content

CM-68943 Send ai-guardrails hook context with the scan so report-mode findings become violations - #504

Merged
Ilanlido merged 3 commits into
mainfrom
CM-68943-guardrails-report-violations
Jul 30, 2026
Merged

CM-68943 Send ai-guardrails hook context with the scan so report-mode findings become violations#504
Ilanlido merged 3 commits into
mainfrom
CM-68943-guardrails-report-violations

Conversation

@Ilanlido

Copy link
Copy Markdown
Collaborator

The scan now carries the hook's context inside the generic scan_parameters metadata bag under an ai_guardrails key, which lets secret-detector attribute the finding to the developer's device and, in report mode, promote it to a real violation instead of a scan-scoped detection.

  • GuardrailsMode replaces InstallMode: the same report/block pair describes both the installed mode and a single event's effective mode, which get_effective_mode now derives from the policy in one call.
  • A generation id is minted per hook event when the IDE dialect does not supply one (Copilot), since it scopes the violation's identity.
  • The device serial is cached in a temp file, keyed by username, so repeated hook invocations don't re-run the platform lookup.
  • Copilot's sessionStart hook drops its timeoutSec.

… findings become violations

The scan now carries the hook's context inside the generic scan_parameters
metadata bag under an `ai_guardrails` key, which lets secret-detector attribute
the finding to the developer's device and, in report mode, promote it to a real
violation instead of a scan-scoped detection.

- `detection_source` is sent from `SECRETS_BLOCK_REASON_BY_EVENT_TYPE`, so the
  violation and the ai-security-manager hook event describe the same event with
  the same vocabulary. The three handlers now look the reason up through that
  map instead of hardcoding it, and `_ArgScanFeature` no longer carries a
  `block_reason` alongside its event type.
- `GuardrailsMode` replaces `InstallMode`: the same report/block pair describes
  both the installed mode and a single event's effective mode, which
  `get_effective_mode` now derives from the policy in one call.
- A generation id is minted per hook event when the IDE dialect does not supply
  one (Copilot), since it scopes the violation's identity.
- The device serial is cached in a temp file, keyed by username, so repeated
  hook invocations don't re-run the platform lookup.
- Copilot's sessionStart hook drops its timeoutSec.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review for a one-time review, or @claude review always to subscribe this PR to a review on every future push.

Tip: disable this comment in your organization's Code Review settings.

Comment thread cycode/cli/utils/host_info.py Outdated
Comment thread cycode/cli/utils/host_info.py Outdated
Comment thread cycode/cli/utils/host_info.py
Comment thread cycode/cli/apps/ai_guardrails/scan/handlers.py
Comment thread cycode/cli/apps/ai_guardrails/ides/copilot.py
Comment thread cycode/cli/apps/ai_guardrails/scan/handlers.py

@omer-roth omer-roth left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

added comments, please review

…collection

The cache is now created 0600 via mkstemp and moved into place with os.replace,
so a concurrent hook can't read a half-written file and the write can't be
redirected by a symlink planted in the shared temp dir.

README gains an AI Guardrails section stating that scanning is server-side and
listing the device, user and environment data each event reports.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Ilanlido
Ilanlido enabled auto-merge (squash) July 30, 2026 12:37
@Ilanlido
Ilanlido merged commit ce8fa23 into main Jul 30, 2026
28 checks passed
@Ilanlido
Ilanlido deleted the CM-68943-guardrails-report-violations branch July 30, 2026 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants