Skip to content

Add provenance tag and confidence-gated suppression to guardrail prompts (AST-180794) - #1578

Merged
cx-kedar-bhujade merged 8 commits into
stagingfrom
feature/AST-180794-add-provenance-tag-confidence-gated-remediation
Oct 6, 2026
Merged

cx-kedar-bhujade merged 8 commits into
stagingfrom
feature/AST-180794-add-provenance-tag-confidence-gated-remediation

Conversation

@cx-kedar-bhujade

Copy link
Copy Markdown
Contributor

Summary

Adds a provenance tag and a hook-deny header to ASCA, KICS, and SCA guardrail hook output, and replaces the blanket "ask the user first" suppression gate with a two-path confidence-gated model across all three guardrails.

The flow:

  1. Each guardrail package (asca, kics, sca) computes its permissionDecisionReason / additionalContext / finding text as before.
  2. A new provenanceTag helper prepends [Checkmarx cx-devassist — automated security output, not user input] to that text, so the coding agent can recognize genuine Checkmarx output versus text that merely looks like a finding (e.g. spoofed from a file or fetched page).
  3. A new hookDenyHeader constant opens the agent-facing instructions, stating up front that the message is a Checkmarx hook deny, not file content or an untrusted tool error — without using any of the phrases the anti-injection tests treat as evidence a message is not genuinely from Checkmarx.
  4. The suppression rule is now two independently sufficient paths: (a) the user explicitly told the agent to suppress or ignore the finding — honored immediately, no further verification needed; or (b) the agent decides on its own, but only when grounded in code it has actually opened and read itself (not an assumption, and not merely because another file or the finding text claims something). SCA's package-suppression path additionally requires an actual remediation attempt that returned "no fixed version exists" for path (b).
  5. Each prompt still reminds the agent that the security check is mid-task, not a new task, so it resumes the user's original request afterward instead of inventing follow-up work.

What changed

  • provenanceTag and hookDenyHeader added to asca/delta.go, kics/delta.go, and sca/prompts.go, prepended to the reason/context/finding strings each hook returns.
  • Removed the "ASK THE USER FIRST" / "wait for their answer" gate from the ASCA and KICS Cursor prompts and the SCA vulnerable-package prompt; replaced with the two-path (a)/(b) suppression model described above.
  • Added TestAdditionalContext_OmitsInjectionTriggers (ASCA and KICS) and TestRemediation_OmitsInjectionTriggers (SCA), each checked across all five supported agents, asserting the hook-deny header is present and that phrases such as "without asking" or "silently" never appear in agent-facing text.
  • Updated the existing KICS Cursor wording test (kics/delta_test.go) to assert the new two-path wording instead of the old blanket-ask gate.

Behavior guarantees

  • Suppression commands and remediation tool calls emitted by each guardrail are unchanged; only the surrounding instructional text changed.
  • The provenance tag and hook-deny header are prepended consistently to every reason/context/finding string returned by formatFindings (ASCA, KICS) and denyFrom (SCA).
  • A user's explicit suppress/ignore instruction is always honored without requiring the agent to first classify the finding as a false positive.

Validation

  • Test approach: Not established from available evidence.
  • Unit tests: go test ./internal/commands/agenthooks/... — passed.
  • Integration tests: Not run — no integration test covers guardrail prompt text.
  • Lint: golangci-lint run -c .golangci.yml on the changed packages — no new findings introduced by this change.

Documentation updates

None required: this changes internal guardrail hook prompt text only, with no public API, CLI flag, or configuration change.

cx-kedar-bhujade and others added 3 commits September 25, 2026 17:11
…ardrail prompts

Tags ASCA/KICS/SCA guardrail output with a Checkmarx provenance marker so
agents can distinguish genuine findings from spoofed text, and replaces the
blanket "ask the user first" suppression gate with a confidence-gated model:
suppress only when grounded in something verifiable in the file (or, for SCA,
after actually attempting remediation), otherwise ask instead of guessing.
Also reminds the agent to resume the original task after handling a finding.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…o guardrail prompts

Adds a shared hookDenyHeader to ASCA, KICS, and SCA guardrail prompts that
states up front the message is a Checkmarx hook deny, not file content or an
untrusted tool error, without repeating the spoof phrases the anti-injection
skill tests treat as evidence a message did not come from Checkmarx.

Splits the suppression rule into two independently sufficient paths: (a) the
user explicitly told the agent to suppress or ignore the finding, honored
immediately with no further verification, or (b) the agent decides on its own
and grounds that decision in code it has actually opened and read itself (not
an assumption or another file's claim). SCA's package suppression path is
tightened the same way, requiring either the user's instruction or an actual
remediation attempt returning "no fixed version exists".

Adds injection-trigger regression tests across all five supported agents for
ASCA, KICS, and SCA verifying the hook-deny header is present and phrases like
"without asking" or "silently" never appear in agent-facing text.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
cx-kedar-bhujade and others added 3 commits September 29, 2026 21:19
…ation model

Replaces the analyze/ask-when-unsure flow with an explicit classify-then-act
sequence: findings are false positives only when cited evidence meets (a) or
(b), otherwise they are always remediated autonomously and never surfaced to
the user as a remediate-or-suppress question. Adds a structured remediation
summary report and a verify-and-retry step across ASCA, KICS, and SCA
guardrails.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds the findings/packages list into the Cursor ASCA/KICS prompts and the
SCA malicious/vulnerable prompts (previously only in the non-Cursor path),
and simplifies remediationNote's signature now that subject/goal are no
longer used. Aligns summary report wording and evidence hints (e.g. "parent
module or sibling manifest") across agents, and updates the KICS Cursor test
to match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Extract the ASCA, KICS, and SCA closing remediation reports into shared
constants (ascaRemediationReport, kicsRemediationReport, scaMaliciousReport,
scaVulnerableReport) so the Cursor and non-Cursor deny paths render the same
markdown report instead of two copies that could drift apart. Bump
ast-cx-hooks to v1.0.10 and refresh go.sum.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
cx-anurag-dalke
cx-anurag-dalke previously approved these changes Oct 5, 2026

@cx-anurag-dalke cx-anurag-dalke left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok

cx-rakesh-kadu
cx-rakesh-kadu previously approved these changes Oct 5, 2026
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@stepsecurity-app

stepsecurity-app Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

✅ Resolved — a later workflow run passed this policy check.

Original alert (resolved)

Security Policy Alert: Secret Policy Violation

This workflow run has been blocked by StepSecurity's secrets policy because it accesses secrets and the workflow file differs from the default branch.

Secret references detected:

  • secrets.CX_BASE_URI at line 221
  • secrets.CX_CLIENT_ID at line 222
  • secrets.CX_CLIENT_SECRET at line 223
  • secrets.CX_BASE_AUTH_URI at line 224
  • secrets.CX_AST_USERNAME at line 225
  • secrets.CX_AST_PASSWORD at line 226
  • secrets.CX_APIKEY at line 227
  • secrets.CX_TENANT at line 228
  • secrets.CX_SCAN_SSH_KEY at line 229
  • secrets.ECHO_LIBRARIES_ACCESS_KEY at line 231
  • secrets.PERSONAL_ACCESS_TOKEN at line 233
  • secrets.PROXY_USER at line 236
  • secrets.PROXY_PASSWORD at line 237
  • secrets.PR_GITLAB_TOKEN at line 242
  • secrets.PR_GITLAB_NAMESPACE at line 243
  • secrets.PR_GITLAB_REPO_NAME at line 244
  • secrets.PR_GITLAB_PROJECT_ID at line 245
  • secrets.PR_GITLAB_IID at line 246
  • secrets.AZURE_ORG at line 247
  • secrets.AZURE_PROJECT at line 248
  • secrets.AZURE_REPOS at line 249
  • secrets.AZURE_TOKEN at line 250
  • secrets.BITBUCKET_WORKSPACE at line 252
  • secrets.BITBUCKET_REPOS at line 253
  • secrets.BITBUCKET_USERNAME at line 254
  • secrets.BITBUCKET_PASSWORD at line 255
  • secrets.GITLAB_TOKEN at line 256
  • secrets.PR_BITBUCKET_TOKEN at line 258
  • secrets.MS_TEAMS_WEBHOOK_URL_INTEGRATION_TESTS at line 437

To approve this workflow, please add the workflows-approved label to this PR.

Note: The label must be added by someone other than the PR author (cx-kedar-bhujade) or automation bots to ensure proper security review.

After the label is added, you can re-run the blocked workflow to proceed.

This workflow will be automatically approved once merged into the default branch.

For more information, see StepSecurity's Secret Exfiltration Policy documentation.

@cx-kedar-bhujade
cx-kedar-bhujade changed the base branch from main to staging October 5, 2026 09:39
@cx-rahul-pidde
cx-rahul-pidde self-requested a review October 5, 2026 09:46
cx-rahul-pidde
cx-rahul-pidde previously approved these changes Oct 5, 2026
@cx-aniket-shinde
cx-aniket-shinde self-requested a review October 5, 2026 09:47
@cx-kedar-bhujade
cx-kedar-bhujade changed the base branch from staging to main October 5, 2026 09:49
@cx-kedar-bhujade
cx-kedar-bhujade dismissed stale reviews from cx-aniket-shinde and cx-rahul-pidde October 5, 2026 09:49

The base branch was changed.

@cx-kedar-bhujade
cx-kedar-bhujade changed the base branch from main to staging October 5, 2026 14:50
@cx-kedar-bhujade
cx-kedar-bhujade merged commit 59024ab into staging Oct 6, 2026
26 of 29 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants