[3.6.0] - 2026-08-20
Gate G4 (Dependency Honesty) gets its mechanical half: hallucinated-
package detection. LLMs invent package names and attackers register them
("slopsquatting"), so an import that does not exist on its registry is
both an incompleteness defect and a supply-chain attack surface - and it
is now detected, not just judged.
Added
verify_dependenciesMCP tool (persona_constitution/dependencies.py):
extracts imports from source (Python via AST including literal-argument
importlib.import_module/__import__; JS/TS via import/export/require
specifiers) or from a unified diff's added lines with new-file line
numbers, classifies the cheap-and-private tiers locally (caller-excluded
globs, Python stdlib incl. a frozen 3.9-floor fallback, Node built-ins,
modules the diff itself provides), and verifies the remainder against
PyPI (PEP 503 simple index) and the npm registry. A curated alias table
resolves the well-known import-name/distribution mismatches
(yaml -> PyYAML, cv2 -> opencv-python, ...) asexists-as.- Network honesty as a contract. This is the package's only
network-touching tool besides the GitHub client, and its advertised
description says so: package names and nothing else leave the machine,
bounded (50 packages/call, 10s timeout, 3 attempts, backoff). A 404 is
missing-> FAIL; timeouts/5xx/429/offline areunverifiable-> REVIEW,
never a silent PASS.scan_codeandreview_patchremain fully
offline. - The reviewing agent's protocol now calls
verify_dependenciesfor
G4's existence half; pinning and intent remain judgement. - 29 hermetic tests: extraction forms, tier ordering (local tiers
provably never query), alias resolution, verdict precedence, retry
behaviour at the single network egress, diff line mapping, and the
tool's boundary validation. The module joins the nightly mutation run.
Scanner accuracy measured by this release build
Adversarial corpus: 24 violations, 13 legitimate samples, 37 total
prose rules only 24/37 (64%)
union (shipped) 37/37 (100%)
Union at or above baseline (37/37 >= 37).