THINK FIRST·CODE LATER

← All labs

Audit a coding agent's action log

Problem

An agent worked on "fix issue #214 in the matching module". Audit its action log against the team's guardrails.

Input: first line ALLOW path1,path2,... (the directories the agent may edit; a file is allowed if its path starts with one of them). Second line HOSTS host1,host2,... (allowed network hosts). Then log lines until the end of input:

READ path
EDIT path
RUN command...
NET host

Flag violations, in log order (line numbers count the log lines only, starting at 1):

  • EDIT of a file outside the allowed directories → line k: EDIT outside scope: path
  • EDIT of a test file (path contains /test/ or ends with Test.java) → line k: test file modified: path (reported in addition to the scope check if both apply)
  • NET to a host not in the list → line k: blocked network access: host
  • RUN containing push --force, rm -rf or --no-verify → line k: dangerous command: command
  • EDIT or RUN whose text contains API_KEY= or password= → line k: possible secret

Then print Violations: v and the verdict:

  • Verdict: BLOCK if any blocked network access, dangerous command or possible secret;
  • else Verdict: HUMAN REVIEW (tests or scope) if any other violation;
  • else Verdict: OK for normal review.

READ lines are never violations (reading is allowed).

Input:

ALLOW src/main/java/matching/
HOSTS repo.maven.apache.org,docs.oracle.com
READ src/main/java/matching/Matcher.java
EDIT src/main/java/matching/Matcher.java
RUN mvn -q test
EDIT src/test/java/matching/MatcherTest.java
NET pastebin.com
RUN git push --force origin main

Output:

line 4: EDIT outside scope: src/test/java/matching/MatcherTest.java
line 4: test file modified: src/test/java/matching/MatcherTest.java
line 5: blocked network access: pastebin.com
line 6: dangerous command: git push --force origin main
Violations: 4
Verdict: BLOCK

Write it here or in your IDE, then paste it. Compile and test it yourself before comparing. Your code stays in your browser — it is never sent to or stored on the server.