feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

feat(skills): add security scanning to cicd - #23

Merged
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation
Aug 30, 2026
Merged

feat(skills): add security scanning to cicd#23
harrymove-ctrl merged 2 commits into
mainfrom
feat/cicd-security-validation

Conversation

@Abdol164

@Abdol164Abdol164 commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

What's missing today

cmk:cicd frames itself as "three concerns that stay separated: what validates every change, what
ships a specific commit somewhere, and what gates or authenticates either one."
The pipeline it
composes validates build, test and docs — and never scans. No SAST, no dependency advisories, no
secret detection, no IaC scanning. "Security" appears in the skill only as where secrets are stored
and OIDC federation. Supply-chain coverage exists only inside cmk:rust; secrets are addressed as
storage, never as detection.

So a design can declare a control — cmk:design already requires a security section with
assumptions, gaps, and controls — and the pipeline has nowhere to enforce it.

The idea

Adds references/security-scanning.md: four classes (code, dependencies, secrets, infrastructure),
each a question rather than a product, satisfied by a scanner of that category or equivalent in
the cargo-deny style cmk:rust already uses.

Classes are scoped to the effort rather than run wholesale — running everything on every change
trains people to ignore the result. Selection reuses cmk:delivery-review's existing triad, applied
to classes rather than lenses:

  • Adaptive when unstated — select from what the diff touches; a docs-only diff implicates none.
  • Binding when stated — an explicit list honored exactly, in both directions.
  • Disclosed unconditionally — state which classes ran and which did not, each absence with its
    reason.

Deliberately not coupled to Quick/Targeted/Full. Depth measures how expensive a wrong answer is;
class selection follows which artifacts changed. Coupling them is wrong in both directions — a
Quick review of a lockfile bump still needs a full dependency scan, and a Full review of a
docs-only diff needs no SAST.

Secrets is the one class that always runs: a committed credential is not proportional to the size of
the change that carried it.

The load-bearing distinction

A findings list renders these identically, and they must not be reported the same way:

  • Not applicable — the diff touched no manifest, so the dependency class did not run. Coverage
    intact.
  • Could not run — the scanner was missing, unauthenticated, timed out, or loaded zero rules.
    Coverage has a hole.

Collapsing the second into the first is how a gate stops gating with nobody noticing. This is the
scanner-level form of a trap this skill already names: under skipped-job-reports-success the job
never ran; here it ran and checked nothing. Added to the traps list as
empty-scan-reads-as-clean, and separated by exit code — 3 for incomplete coverage, distinct
from 0.

Two smaller pieces

ci-structure.md gains the one place security departs from the surrounding convention: area
gating assumes blast radius matches file paths, which breaks here. A lockfile bump touches one file
and can alter the whole dependency graph; a credential lands in fixtures a src/** filter never
sees. Gate dependencies on manifests and lockfiles; run secrets unconditionally.

delivery-review lens 6 is "think like a bad actor with the diff in hand" — pure reasoning —
in a skill whose bar two sections later is "commands executed with output" and "a review with
zero findings and a thin evidence section is a failed review."
The lens now names the scans that
backed it and the classes that did not run, so it can meet the standard that file already sets.

That file sits at exactly 150 lines, so the two added lines are paid for by reflowing the
Boundary review paragraph, which left lens. alone on a line. No words changed — the diff
there is pure rewrap.

Suppressions

cmk:design requires stating security gaps. A suppression is that same accepted gap expressed where
it is enforced, so it carries the same obligation: a reason and an expiry, with an expired one
failing the gate. Accepted must not decay into forgotten.

Checks

  • bash scripts/skill-lint.sh — OK
  • Versions bumped: cmk:cicd 0.3.3 → 0.4.0 (new guidance), cmk:delivery-review 0.1.3 → 0.1.4;
    conventions.md roster updated
  • Companion docs updated for both skills
  • No tool mandated anywhere — every scanner reference reads "or equivalent"

Abdol164and others added 2 commits August 28, 2026 22:20
The pipeline this skill composes validates build, test and docs and never
scans. Adds the four classes, scoped to what the diff touches and disclosed
either way, so a scan that could not run is not read as one that found
nothing — the scanner-level form of skipped-job-reports-success.
delivery-review's security lens now names the scans that backed it, so it
can meet the evidence bar that skill already sets.
Resolves the overlap with #22, which landed first:
- cicd/SKILL.md — keep main's "Use when…" description house form, carry this
branch's "add security scanning" / "scan for vulnerabilities" triggers, and
take 0.4.0 (a new guidance facet, not the 0.3.4 wording bump).
- delivery-review/SKILL.md — main moved the seven lenses out to
references/lenses.md, so this branch's inline lens-6 edit had no target
left. Re-applied it there instead: the security lens still has to name the
scans that backed it and the classes that did not run. Taking either side
of that conflict verbatim would have dropped the change silently.
- conventions.md — main's rewritten version roster, with cmk:cicd moved from
the 0.3.x band to 0.4.x so it stays named exactly once.
- docs/ai/skills/delivery-review.md — record references/lenses.md and the new
Red Flags / Rationalizations sections, which the lens extraction left out.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@harrymove-ctrl
harrymove-ctrl merged commit 645c596 into mainAug 30, 2026
2 checks passed
harrymove-ctrl added a commit that referenced this pull request Aug 30, 2026
…-validation"
This reverts commit 645c596, reversing
changes made to 6b6781f.
@harrymove-ctrl

Copy link
Copy Markdown
Contributor

Reverted from main in ae4ae31, together with #22 which it was merged on top of. Continues in #26 with @Abdol164's commit unchanged (identical diff: 7 files, +177/-23). Please review there.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Abdol164@harrymove-ctrl@tung-lee