fix(profiles): use Luna judges and forward scanner reasoning - #62
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 24, 2026, 12:16 AM ET / 04:16 UTC (Revision 2). ClawSweeper reviewWhat this changesThe branch switches two bundled ClawHub judges to GPT-6 Luna with high reasoning, forwards scanner model and reasoning settings through Docker environment allowlists, and updates tests and operator documentation. Merge readiness✅ Ready for maintainer review The change remains necessary: current main still selects GPT-5.5 in the bundled ClawHub judges. The prior packaged README mismatch is fixed at this head. The MEMBER-authored PR records a staged source-landing decision, with A.I.G. support and production credential verification reserved for rollout; no introduced merge blocker was found. Priority: P2 Review scores
Verification
How this fits togetherClawScan’s built-in ClawHub profiles choose scanners and an external judge for a skill or plugin target. Scanner reports feed the judge, and the run produces evidence and a verdict artifact. flowchart LR
A[Skill or plugin target] --> B[ClawHub profile]
B --> C[Scanner sandbox]
A --> C
C --> D[Raw scanner reports]
D --> E[Codex judge]
B --> E
E --> F[Verdict artifact]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Land the scoped profile preparation, then gate publication and ClawHub adoption on A.I.G. support, updated runtime pins, and a credentialed Luna scan. Do we have a high-confidence way to reproduce the issue? Not applicable as a profile-default and setting-forwarding change. Current-main source shows the older model and missing reasoning allowlist entries. Is this the best way to solve the issue? Yes. The branch uses the existing profile and environment-name allowlist mechanisms, while the documented staged rollout keeps unsupported A.I.G. reasoning separate. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against 6d4573ee6187. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
|
@clawsweeper re-review Please review exact head 4e7db96. The packaged README model/environment catalog mismatch is fixed. The PR body records the accepted staged source-landing decision and explicitly preserves A.I.G. runtime/release and production-equivalent credential proof as rollout gates. Runtime and tests are unchanged from 200ac10; this follow-up changes only README documentation. |
|
🦞👀 Re-review progress:
|
Summary
Both bundled ClawHub judges still selected GPT-5.5, and Docker could drop SkillSpector's configured reasoning effort. Use GPT-6 Luna with high reasoning in
clawhubandclawhub-aig, and preserve scanner model/reasoning settings across the existing environment allowlists.SKILLSPECTOR_MODELandSKILLSPECTOR_REASONING_EFFORTin both profile environments, and add the missing reasoning setting to the scanner registry.REASONING_EFFORTalongsideDEFAULT_MODEL.Scope
This is a maintainer-authorized default update to the official bundled profiles, not a vulnerability profile proposal.
Security / Trust Impact
The requested model selection changes the ClawHub judge. Environment passthrough remains a variable-name allowlist; values are not added to Docker arguments or artifact metadata. No credentials, scanning permissions, gate rules, prompts, or output schemas change. Production/config delta is +8 lines; tests +49; docs/changelog +18.
Verification
go test -count=1 ./..., including fullinternal/profilesandinternal/runnersuites.go test -count=1 ./...: stopped after the unchangedTestRunCommandPrintsHelphung incaptureStdout. Its helper writes to an OS pipe before reading; the captured Go stack was blocked insyscall.writeviamain.go:36andmain_test.go:1468. The help test, its output-capture helper, and help text are unchanged. Follow-up: make CLI test output capture drain concurrently on macOS.go vet ./...go run ./cmd/clawscan --helpmake docs-sitegit diff --checkandgofmtDependency contracts checked: SkillSpector model resolution, SkillSpector reasoning forwarding, and Codex CLI model override / reasoning request construction. The campaign's separate local Codex Luna/high availability canary succeeded; it does not prove production API-key access.
Rollout dependency
A.I.G. high reasoning is not active in the pinned runtime. The current
aig-skill-scan==0.2.2dependency does not supportREASONING_EFFORT. Its upstream support is being prepared separately; this change only forwards the optional setting and documents that limitation. An upstream release and a verified runtime dependency update are required before claiming all ClawHub scanners use high reasoning.ClawScan publication/runtime rollout and ClawHub package adoption are separate steps. No release tags, package publication, production scans, runtime deployment, or live variables were changed.
` after updating its expected optional-environment list.
Dependency contracts checked: SkillSpector model resolution, SkillSpector reasoning forwarding, and Codex CLI model override / reasoning request construction. The campaign's separate local Codex Luna/high availability canary succeeded; it does not prove production API-key access.
Rollout dependency
A.I.G. high reasoning is not active in the pinned runtime. The current
aig-skill-scan==0.2.2dependency does not supportREASONING_EFFORT. Its upstream support is being prepared separately; this change only forwards the optional setting and documents that limitation. An upstream release and a verified runtime dependency update are required before claiming all ClawHub scanners use high reasoning.ClawScan publication/runtime rollout and ClawHub package adoption are separate steps. No release tags, package publication, production scans, runtime deployment, or live variables were changed.
Maintainer landing decision
Accept this as staged source preparation. Both bundled judges select Luna/high independently of A.I.G.; the optional A.I.G. environment allowlist does not set or enable reasoning effort. Existing A.I.G. 0.2.2 behavior remains unchanged. The full all-scanners-high rollout remains blocked on upstream support, a verified runtime dependency update, ClawScan publication, and downstream adoption.
The packaged README now matches the profile model and scanner environment settings, including the A.I.G. limitation. The final README-only delta leaves runtime and tests byte-identical to the validated 200ac10 head; docs generation passed again.
ClawSweeper rank-up move: a representative scan with the deployed credential is deferred to runtime rollout, because this PR publishes no package/image and activates no production scanner. The existing local Luna/high canary demonstrates local account availability, not production access. Production-equivalent Luna access remains a rollout gate.