DD-333 F.1 — S-MCP-001 silence path + S-MCP-002 rule (v1.1.0) #2

Merged
piersdd merged 1 commit from feat/dd-333-f1 into main 2026-05-22 01:37:59 +00:00
piersdd commented 2026-05-22 01:36:11 +00:00 (Migrated from github.com)

Summary

S-MCP-001 silences on tools listed in non_conformance_rationale.affected_tools (DD-333 F.1 accept-with-rationale path). New S-MCP-002 NonConformanceRationaleMalformed rule covers cross-field invariants AJV cannot express + post-build catalog audit defence-in-depth.

  • package.json 1.0.0 → 1.1.0 (additive minor)
  • src/types.ts — ToolGranularity.scope_filtering union extended with "non-conforming-explicit"; new NonConformanceRationale interface; CatalogEntry gains optional non_conformance_rationale field
  • src/catalog-parser.ts — defensive guard mirroring tools pattern extracts the block into typed shape
  • src/catalog-rules.ts — S-MCP-001 reads affected_tools silence set; new S-MCP-002 emits findings for scope_filtering_off ≠ true, empty contamination_risks, missing/empty reason, affected_tools non-array, AND per-mismatched-name in cross-reference
  • src/index.ts — exports S_MCP_002 and NonConformanceRationale type
  • 17 new test cases across 3 describe blocks (S-MCP-001 silence + S-MCP-002 + parser); tsc --noEmit clean

Cross-PR dependency (strict merge order)

Spec

[[2026-05-22-dd333-f1-non-conformance-schema]] § Section 3

DD reference

[[DD-333]] § "Architect amendment 2026-05-22 — Non-conformance rationale + registry gate". Cross-DD with [[DD-189]] (UI surfaces, F.2+) and [[DD-301]] (memory contamination propagation, F.2+).

Test plan

  • npm test — 114 tests, all pass (97 baseline + 17 new)
  • npm run lint (tsc --noEmit) — clean
  • S-MCP-001 regression preserved: still fires on tools without granularity AND not in affected_tools
  • S-MCP-001 new silence path: tools listed in affected_tools no longer fire
  • S-MCP-002 fires on all 5 malformation paths (scope_off, empty_contamination, empty_reason, affected_tools non-array, cross-ref miss)
  • S-MCP-002 silent on plugin without rationale + silent on valid rationale + silent on pack-type entries
  • Multi-violation entries emit one finding per invariant

🤖 Generated with Claude Code

## Summary S-MCP-001 silences on tools listed in `non_conformance_rationale.affected_tools` (DD-333 F.1 accept-with-rationale path). New S-MCP-002 `NonConformanceRationaleMalformed` rule covers cross-field invariants AJV cannot express + post-build catalog audit defence-in-depth. - `package.json` 1.0.0 → 1.1.0 (additive minor) - `src/types.ts` — `ToolGranularity.scope_filtering` union extended with `"non-conforming-explicit"`; new `NonConformanceRationale` interface; `CatalogEntry` gains optional `non_conformance_rationale` field - `src/catalog-parser.ts` — defensive guard mirroring `tools` pattern extracts the block into typed shape - `src/catalog-rules.ts` — S-MCP-001 reads `affected_tools` silence set; new S-MCP-002 emits findings for `scope_filtering_off ≠ true`, empty `contamination_risks`, missing/empty `reason`, `affected_tools` non-array, AND per-mismatched-name in cross-reference - `src/index.ts` — exports `S_MCP_002` and `NonConformanceRationale` type - 17 new test cases across 3 describe blocks (S-MCP-001 silence + S-MCP-002 + parser); `tsc --noEmit` clean ## Cross-PR dependency (strict merge order) - groupthink-dev/stallari-pack-spec#1 — schema + docs (merge FIRST) - groupthink-dev/stallari-plugins#15 — AJV gate + build-catalog.js (merge SECOND) - groupthink-dev/stallari-secops-scanner#TBD — this PR (merge THIRD) ## Spec `[[2026-05-22-dd333-f1-non-conformance-schema]]` § Section 3 ## DD reference `[[DD-333]]` § "Architect amendment 2026-05-22 — Non-conformance rationale + registry gate". Cross-DD with `[[DD-189]]` (UI surfaces, F.2+) and `[[DD-301]]` (memory contamination propagation, F.2+). ## Test plan - [x] `npm test` — 114 tests, all pass (97 baseline + 17 new) - [x] `npm run lint` (`tsc --noEmit`) — clean - [x] S-MCP-001 regression preserved: still fires on tools without granularity AND not in `affected_tools` - [x] S-MCP-001 new silence path: tools listed in `affected_tools` no longer fire - [x] S-MCP-002 fires on all 5 malformation paths (scope_off, empty_contamination, empty_reason, affected_tools non-array, cross-ref miss) - [x] S-MCP-002 silent on plugin without rationale + silent on valid rationale + silent on pack-type entries - [x] Multi-violation entries emit one finding per invariant 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.
No description provided.