An agent worked on "fix issue #214 in the matching module". Audit its action log against the team's guardrails.
Input: first line ALLOW path1,path2,... (the directories the agent may edit; a file is allowed if its path starts with one of them). Second line HOSTS host1,host2,... (allowed network hosts). Then log lines until the end of input:
READ path
EDIT path
RUN command...
NET host
Flag violations, in log order (line numbers count the log lines only, starting at 1):
EDITof a file outside the allowed directories →line k: EDIT outside scope: pathEDITof a test file (path contains/test/or ends withTest.java) →line k: test file modified: path(reported in addition to the scope check if both apply)NETto a host not in the list →line k: blocked network access: hostRUNcontainingpush --force,rm -rfor--no-verify→line k: dangerous command: commandEDITorRUNwhose text containsAPI_KEY=orpassword=→line k: possible secret
Then print Violations: v and the verdict:
Verdict: BLOCKif any blocked network access, dangerous command or possible secret;- else
Verdict: HUMAN REVIEW (tests or scope)if any other violation; - else
Verdict: OK for normal review.
READ lines are never violations (reading is allowed).
Input:
ALLOW src/main/java/matching/
HOSTS repo.maven.apache.org,docs.oracle.com
READ src/main/java/matching/Matcher.java
EDIT src/main/java/matching/Matcher.java
RUN mvn -q test
EDIT src/test/java/matching/MatcherTest.java
NET pastebin.com
RUN git push --force origin main
Output:
line 4: EDIT outside scope: src/test/java/matching/MatcherTest.java
line 4: test file modified: src/test/java/matching/MatcherTest.java
line 5: blocked network access: pastebin.com
line 6: dangerous command: git push --force origin main
Violations: 4
Verdict: BLOCK