Skip to content

feat(scanner): flag ambiguous vendored plugin code scope - #1156

Draft
seonghobae wants to merge 3 commits into
feat/claude-plugin-normalized-name-1099from
feat/claude-plugin-vendored-scope-1099
Draft

seonghobae wants to merge 3 commits into
feat/claude-plugin-normalized-name-1099from
feat/claude-plugin-vendored-scope-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Current repair boundary — 2026-09-12

Successor of #1155 / issue #1099. Does not Close those. NFC identity stays #1155. Inventory is evidence, not permission.

Unique delta

When a plugin tree contains vendored or generated third-party code that is not declared as a bounded, identity-bound dependency, fail closed as one scope finding (claude-plugin-vendored-scope-undeclared):

  • undeclared vendor/leftpad.js or node_modules/foo/index.js fails admission
  • dist/ and *.min.js bundles are the same class
  • a declared hooks/pre.sh plus LICENSE is not this finding
  • package.json plus a lockfile without node_modules/ stays inventory
  • generated files listed in plugin.json files[] are declared scope
  • vendored trees emit one scope finding, not per-file hook findings
  • admitted SHA-bound nested plugins under vendor/nested stay the submodule class
  • Hangul and NFC identity names stay feat(scanner): reject non-NFC plugin identity names #1155
  • snippets are path labels and omit secrets and raw bidi

scan_result=pass is not Noema admission.

Test plan

  • RED then GREEN (tests/test_claude_plugin_vendored_scope.py)
  • Detector statement coverage 1709/1709 with plugin suites on Python 3.13
  • Interrogate docstring coverage 110/110 on the detector
  • Exact-head Checks on this head
  • Keep Draft until current-head gates are GREEN

Relates to #1099. Relates to #1155.

RED contract for vendor/, node_modules/, dist/, and min.js copies
that are not declared in plugin.json files[]. Relates to #1099.
Fail closed on undeclared vendor/, node_modules/, dist/, and min.js
copies as one scope finding. files[] and admitted nested plugins stay
identity-bound. Relates to #1099.
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 17:18 UTC records Draft #1156 `a6f6a74` stacked on #1155.
- Undeclared vendor/node_modules/dist copies fail as one scope finding.
- Hook walks skip those trees so admission is not a per-file flood.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- #1099 remaining surfaces stay on stacked successors, not Close.

Tests:
- documentation-only; detector evidence lives on #1156 (1709/1709)
seonghobae added a commit that referenced this pull request Sep 7, 2026
Refresh the single-writer gap baseline from live exact-head evidence:
Draft #1157 on #1156. Relates to #1099.
@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work labels Sep 8, 2026 — with ChatGPT Codex Connector

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium Normal-priority or P2 work

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant