docs(skills): document programmatic-write scope cut in skills_guard module docstring

Enough1122's review on #92249 asked whether language write APIs
(Python open('w')/write_text/os.replace/shutil, Node fs.writeFileSync/
appendFile) are covered by the agent-config persistence tiers. They are
not: those tiers score shell redirection, sed -i, and imperative prose
only; language-API calls surface just the informational *_ref finding.

Static regexes cannot tie a dynamically-built path to the config-file
destination without executing the skill, so this is a documented scope
cut rather than missing coverage — runtime install gates remain the
backstop. Scoring behavior is unchanged, so SCANNER_VERSION stays at
skills-guard-v2 and cached verdicts remain valid.

Refs #92249
This commit is contained in:
ClintonEmok
2026-08-23 19:44:16 +02:00
committed by Teknium
parent faf8730779
commit 4ade4450bf
+14
View File
@@ -20,6 +20,20 @@ Usage:
allowed, reason = should_allow_install(result)
if not allowed:
print(format_scan_report(result))
Known limitation — programmatic writes (out of scope for this static pass):
the agent-config persistence tiers score shell write mechanics
(">>" redirection, "sed -i") and imperative modification prose only.
Language write APIs in bundled scripts — Python open(..., 'w'/'a'),
pathlib.Path.write_text(), os.replace(), shutil.copy*, and Node
fs.writeFileSync()/appendFile() — aimed at agent-config files surface
only the low-severity *_ref finding, never a scored persistence tier.
Static regexes cannot reliably tie such a call to the config-file
destination (paths may be built dynamically) without executing the
skill, so language-API persistence is left to runtime gates (install
confirmation, sandboxing). If coverage is added later, it belongs as a
fourth "mechanical" tier next to agent_config_mod_shell, requiring the
config-file name as a literal argument at the call site.
"""
import re