Skip to content

fix(leads): honour scan_prospects on the discovery path too - #136

Merged
ralyodio merged 1 commit into
masterfrom
fix/runner-skipscan-topup
Jul 28, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/runner-skipscan-topup

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

scan_prospects was threaded into the runner's stage-3 research call and nowhere else. The discovery top-up — the path that sees every newly discovered domain — kept queueing a scan per candidate regardless of the setting.

So a campaign with scanning off still scanned everything it found, which is exactly what the setting exists to prevent. #135 fixed the one-shot finder; this is the same bug on the campaign path, and I missed it when adding the setting in #129.

Observable in the audits table — a tick on a scan_prospects=false campaign produced fresh audits of artstation.com, adobe.com, elevify.com and friends.

Guard

Asserts every researchProspect call in the runner passes skipScan, and derives it from the campaign rather than hardcoding it. It also asserts there's more than one call site, so the test can't quietly stop proving anything if the code is refactored.

Source-level, because the alternative is standing up the runner against a live database and a scan worker to watch for a call that shouldn't happen. Verified it bites: reverting the fix fails 2 of 3.

Checks

  • tsc --noEmit clean
  • 751/751 tests pass, 3 new
  • production build compiles

🤖 Generated with Claude Code

The setting was threaded into the runner's stage-3 research call and
nowhere else, so the discovery top-up — the path that sees every newly
discovered domain — kept queueing a scan per candidate no matter what
the campaign asked for. A campaign with scanning off still scanned
everything it found, which is exactly the behaviour the setting exists
to prevent.

Observable in the audits table: a tick on a scan_prospects=false
campaign produced fresh audits of artstation.com, adobe.com and every
other domain discovery turned up.

The guard asserts every researchProspect call in the runner passes
skipScan, and derives it from the campaign rather than hardcoding it.
Source-level, because the alternative is standing up the runner with a
live database and a scan worker to watch for a call that should not
happen. Reverting the fix fails it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

vu1nz Security Review

0 finding(s) in PR #?

No security issues found.

@ralyodio
ralyodio merged commit 9fc0f3f into master Jul 28, 2026
8 checks passed
@ralyodio
ralyodio deleted the fix/runner-skipscan-topup branch July 28, 2026 03:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant