Skip to content

Make skill scan gate deterministic - #1048

Draft
danbarr wants to merge 1 commit into
mainfrom
skill-scan-deterministic-gate
Draft

danbarr wants to merge 1 commit into
mainfrom
skill-scan-deterministic-gate

Conversation

@danbarr

@danbarr danbarr commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Implements the scan-config half of #1047.

The blocking skill scan flipped between pass and fail on identical content because the LLM meta-analyzer was deciding which of thousands of ATR regex hits to keep. This switches to skill-scanner 2.2.0's recommended gating setup:

  • Drop --enable-meta. Upstream measured it costing 16.4 points of recall, and it's now off by default.
  • Drop the ATR rule pack. It produced ~98% of HIGH+ hits across our catalog, and upstream ATR marks all its skill-targeted rules as maturity: test.
  • Add --policy quiet. It lowers noisy rules and caps low-confidence and contextual-risk judge findings at LOW.

The LLM judge, consensus runs, and the HIGH block threshold are unchanged. The docs' allowlist examples used an ATR rule and now use a PromptGuard one.

Merge before the companion allowlist PR, which adds entries for the 33 findings that block under the new settings. The smoke job doesn't scan skills, so this PR's CI doesn't exercise the new flags. I verified them locally against scanner 2.2.0, with and without the judge.

🤖 Generated with Claude Code

The LLM meta-analyzer adjudicated thousands of ATR regex hits, so the
blocking decision flipped between runs on identical content. Follow
skill-scanner 2.2.0's recommended gating setup instead:

- Drop --enable-meta. Upstream measured it costing 16.4 points of
  recall and now disables it by default.
- Drop the ATR rule pack. It produced ~98% of HIGH+ hits across the
  catalog, and upstream ATR marks all of its skill-targeted rules as
  maturity "test", not for enforcement.
- Add --policy quiet, which demotes noisy rules and caps low-confidence
  and contextual-risk LLM findings at LOW.

Update the allowlist examples in the docs, which used an ATR rule.

Refs #1047

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant