Skip to main content
← Back to list
01Issue
BugOpenExtensionsPublic
AssigneesNone

Relationships

≡ duplicated by #2289

#2583 verify-reviews: adversarial review path guard is a hand-kept list, so new extensions silently skip it

Opened by skunk-ape · 9/28/2026

verification/workflow-verify-reviews.yaml decides whether to run the adversarial review by matching changed paths against a hard-coded list of directories (agent-runner/, deno-runner/, ..., software-factory/, typesafe-ai/, extensions/). A new extension directory is not on the list until someone remembers to add it, and until then its changes get no adversarial review. Nothing fails or warns: the step shows as skipped (guarded), which looks the same as a legitimate skip.

This happened on PR #327 (swamp-club #2576): gatorwalk-factory/ was missing, the first verify-reviews run skipped the adversarial review, and it was only noticed by reading the checklist. It was added to the list by hand in that PR.

verification/checks.yaml already has the complete list of extension directories (scripts/verification_harness_test.ts enforces that every extension has a target). Fix options: derive the guard's directory list from checks.yaml targets, or add a harness test asserting every extensions/vaults/datastores target in checks.yaml is matched by the adversarial guard.

02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/28/2026, 2:40:10 PM

No activity in this phase yet.

03Sludge Pulse
skunk-ape linked duplicated by #22899/30/2026, 4:48:43 PM
Editable. Press Enter to edit.

skunk-ape commented 9/30/2026, 4:49:55 PM

#2289 was closed as a duplicate of this issue. It is the specific case where the guard omits extensions/, so bundled extension changes skip review. Make sure the fix covers it.

Sign in to post a ripple.