The DIS scanner collapsed Tool(param) rules to the bare tool name, so Agent(model:opus) deny + Agent(model:sonnet) allow (and the same for WebFetch(domain:...)) were flagged as dead config — a false positive now that CC 2.1.178 matches Tool(param:value) and 2.1.172 adds domain rules. The conflict-detector shared the blind spot from the other side: a wildcard deny like WebFetch(domain:*) did not cover a WebFetch(domain:good.com) allow, so a genuine cross-scope conflict was missed (false negative). New shared scanners/lib/permission-rules.mjs: - parseRule / paramMatches (glob) - dominates(deny, allow) -> DIS dead-allow (deny fully covers allow) - rulesIntersect(a, b) -> CNF cross-scope conflict (match sets intersect) DIS now delegates to dominates; conflict-detector :156 delegates to rulesIntersect. A bare deny still covers all params, so true positives are preserved (Bash deny + Bash(npm:*) allow still flagged). Re-seeded the marketplace-medium snapshots: the false-positive CA-DIS finding (Read(src/**) allow + Read(./.env) deny) is correctly gone. This changes snapshot CONTENT only — envelope schema is unchanged, so --json and --raw stay byte-stable. Full suite: 837/837 green (+25). self-audit PASS, A(100)/A(97).
30 lines
1.4 KiB
Text
30 lines
1.4 KiB
Text
[CML] CLAUDE.md Linter: 1 finding(s) (14ms)
|
|
[SET] Settings Validator: 0 finding(s) (1ms)
|
|
[HKV] Hook Validator: 0 finding(s) (1ms)
|
|
[RUL] Rules Validator: 0 finding(s) (1ms)
|
|
[MCP] MCP Config Validator: 0 finding(s) (0ms)
|
|
[IMP] Import Resolver: 0 finding(s) (1ms)
|
|
[CNF] Conflict Detector: 0 finding(s) (1ms)
|
|
[GAP] Feature Gap Scanner: 17 finding(s) (2ms)
|
|
[TOK] Token Hotspots: 1 finding(s) (8ms)
|
|
[CPS] Cache-Prefix Stability: 0 finding(s) (1ms)
|
|
[DIS] Disabled-In-Schema: 0 finding(s) (0ms)
|
|
[COL] Plugin Skill Collision: 0 finding(s) (1ms)
|
|
|
|
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
|
|
Config-Audit Health Score
|
|
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
|
|
|
|
Health: A (98/100) 9 areas scanned
|
|
|
|
Area Scores
|
|
───────────
|
|
CLAUDE.md ........... A (90) Settings ............ A (100)
|
|
Hooks ............... A (100) Rules ............... A (100)
|
|
MCP ................. A (100) Imports ............. A (100)
|
|
Conflicts ........... A (100) Token Efficiency .... A (90)
|
|
Plugin Hygiene ...... A (100)
|
|
|
|
17 opportunities available — run /config-audit feature-gap for recommendations
|
|
|
|
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
|