Skip to content

Stop security-reviewer from blocking on governing document type labels - #188

Merged
shinpr merged 1 commit into
mainfrom
fix/security-reviewer-label-gate
Sep 24, 2026
Merged

shinpr merged 1 commit into
mainfrom
fix/security-reviewer-label-gate

Conversation

@shinpr

@shinpr shinpr commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Summary

security-reviewer returned blocked when a governingDocuments entry used a type label other than design-doc or work-plan, even though every path was readable. The reviewer never uses the type value for anything, so this check only stopped reviews over a label.

The label is easy to get wrong. The build and implement recipes ask for a "typed governingDocuments list" but do not name the accepted values. document-reviewer also names the same documents differently (DesignDoc, UISpec). So a caller that has been calling document-reviewer all session can easily pass DesignDoc here.

This PR fixes it by removing the check, not by adding examples or aligning names across agents.

Changes

  • Removed: the type check from the Step 1 input gate in security-reviewer.md. The gate now blocks only when governingDocuments is empty or a path is unreadable.
  • Changed: the quality checklist item now checks that the paths are readable, not the type and path.

Also included: the patch version is bumped to 0.27.5, and the plugin copies are synced.

Verification

I ran security-reviewer with claude -p and --plugin-dir on a small fixture repository, once with the main definition and once with this branch.

Input main This branch
DesignDoc + UISpec labels, readable paths blocked (invalid type) pass after checking the Design Doc's requirements against the code
design-doc label, missing path — blocked (file does not exist)

claude plugin validate passes for the marketplace and all plugins.

🤖 Generated with Claude Code

The security-reviewer input gate rejected governingDocuments whose type
label was not exactly "design-doc" or "work-plan", even when every path
was readable. The reviewer never branches on the type value, so the
check only stopped reviews over a label. Build and implement recipes do
not spell out the accepted values, and document-reviewer uses a
different vocabulary for the same documents (DesignDoc, UISpec), so
callers can easily pass a label the gate rejects.

Remove the type check from the Step 1 gate and the quality checklist.
The gate now blocks only when governingDocuments is empty or a path is
unreadable.

Bump the patch version to 0.27.5.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@shinpr shinpr self-assigned this Sep 24, 2026
@shinpr
shinpr merged commit 0caac06 into main Sep 24, 2026
1 check passed
@shinpr
shinpr deleted the fix/security-reviewer-label-gate branch September 24, 2026 22:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant