Skip to content

feat(harness): pre-merge threat scan (secrets/URL-allowlist/encoded blobs) (issue #94 Layer 3) #165

Description

@robercano-ghbot

Follow-up to #94Layer 3: pre-merge threat scan.

Before a PR is surfaced for owner approval, scan the diff + PR body for: secrets (regex/gitleaks-style), URLs outside an allowlist, and encoded blobs. Deterministic first. Findings block merge-ready and are visible in the cockpit.

Decision point (from #94): is an LLM "self-modification/supply-chain" threat lens worth its per-PR token cost for v1? Recommendation: deterministic-only for v1 — GitLost shows any LLM gate is probabilistic and bypassable ("Additionally,"-prefix), so the deterministic layers + token scoping carry the weight; revisit an LLM lens later as opt-in.

Acceptance (from #94): "Threat scan runs on every loop-handled PR; findings block merge-ready and are visible in the cockpit."

Metadata

Metadata

Assignees

No one assigned

    Labels

    backlogFiled, not yet approved by the owner - the loop must NOT pick it upmodule:harnessOrchestrator machinery under .claude

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions