Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .github/workflows/measure-unread-surface.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,9 @@ jobs:
measure:
name: Sample SKILL.md and extract referenced paths
runs-on: ubuntu-latest
timeout-minutes: 45
# A scan of 300 skills is ~900 registry fetches at 0.55s plus rule-engine
# time on every file, so it needs materially longer than a measure run.
timeout-minutes: 120

steps:
- uses: actions/checkout@v4
Expand Down
31 changes: 31 additions & 0 deletions scripts/scan-referenced-files.py
Original file line number Diff line number Diff line change
Expand Up @@ -151,6 +151,37 @@ def report(results: list[dict[str, Any]]) -> None:
print(f" {r['slug'][:34]:<34} {f['path'][:30]:<30} "
f"{f['verdict']:<11} risk={f['risk']:<4} [{rules}]")

# Every flagged file, divergent or not. A file whose docs already flagged
# is not concealment -- documentation and code agreeing is the honest case
# -- but a report that prints only the divergence set makes those invisible,
# and a flag you cannot see is a flag you cannot check.
flagged = [
(r, f)
for r in with_refs
for f in r["referenced"]
if f.get("status") == 200 and f.get("verdict") not in ("CLEAN", "UNKNOWN")
]
if flagged:
print(f"\nall flagged referenced files ({len(flagged)}), with their doc verdict:")
for r, f in flagged[:60]:
rules = ", ".join(x.replace("MALWAR-", "") for x in f["rules"])
print(f" {r['slug'][:30]:<30} {f['path'][:28]:<28} "
f"doc={r['doc_verdict']:<11} file={f['verdict']:<11} "
f"risk={f['risk']:<4} [{rules}]")

# Named but not retrievable. Not evidence of anything on its own; recorded
# because "we could not read it" and "there was nothing to read" are
# different facts and only one of them supports a clean claim.
if unreachable:
print(f"\nnamed but unreachable ({len(unreachable)}) -- unknown, not clean:")
by_slug: Counter[str] = Counter()
for r in with_refs:
for f in r["referenced"]:
if f.get("status") != 200:
by_slug[r["slug"]] += 1
for slug, n in by_slug.most_common(20):
print(f" {slug[:44]:<44} {n}")

print("\nThese are leads, not verdicts: the rule engine is calibrated for")
print("SKILL.md prose and its false-positive profile on code is unmeasured.")
print("Every one needs reading by hand before it is called anything.")
Expand Down
Loading