Skip to content

Observability detection - #159

Open
ericksondelacruz wants to merge 3 commits into
mainfrom
feat/observability-detection
Open

ericksondelacruz wants to merge 3 commits into
mainfrom
feat/observability-detection

Conversation

@ericksondelacruz

Copy link
Copy Markdown
Collaborator

Summary

  • Ships the production rule packs for the paired engine-repo Phase 1 agent-observability detection PR.
  • 9 repo-scope absence rules (one per SDK pack: OAI-203, CSDK-208, LC-202, PYD-202, VAI-201, CREW-202, ADK-202, AG2-202, MCP-202), severity low, gated on repo_observability_inspectable so they don't fire on a language the
    pass never parses.
  • 3 agent-scope outlier rules (PYD-107, LC-112, VAI-101) — fires when the repo is instrumented but this specific agent isn't wired in.
  • New cross-SDK observability quality category: OBS-001 (imported but never initialized, medium), OBS-002 (console-only exporter, low), OBS-003 (full prompt/response capture, medium), OBS-005 (dependency declared but never
    wired, medium).
  • OBS-002/OBS-003 ship language: python — their exporter-construction and content-capture detection has no TS/JS counterpart yet, so they don't claim coverage of the TS-heavy SDKs listed in applies_to (vercel_ai, and
    the TS variants of claude_sdk/langchain/google_adk/mcp).
  • Verified byte-identical against the engine repo's testdata/rules-fixture/ mirror via check-rules-sync.sh; grounded in the paired trustabl-rulebook PR.
  • Merges in latest main (CSKILL keyword false-positive fix, CSDK bypassPermissions gap fix) with no conflicts.

Test plan

  • check-rules-sync.sh confirms this pack matches the engine repo's fixture 1:1
  • The paired engine-repo PR's go test ./... exercises every rule's fire/silent case via TestPolicyRules_AllRulesCovered

Erick dela Cruz added 3 commits September 21, 2026 15:55
Mirrors testdata/rules-fixture/ in the engine, which ships the six
repo-scope observability predicates these rules evaluate and advertises
schema_version 18. An older binary loads the pack leniently and skips
what it cannot evaluate.

- nine repo-scope absence rules, one per SDK pack (OAI-203, CSDK-208,
  LC-202, PYD-202, VAI-201, CREW-202, ADK-202, AG2-202, MCP-202), all
  severity low so a demo repo or a library does not fail CI, gated on
  repo_observability_inspectable so none can fire on a language the
  observability pass never parsed, and on repo_observability_declared: false
  so a repo that ships a tracing dependency it never wired gets OBS-005
  instead
- three agent-scope outlier rules (PYD-107, LC-112, VAI-101), gated on
  repo_has_observability so they read as "this agent is the outlier"
  rather than repeating a repo-wide complaint per agent
- the new observability category: OBS-001 imported but never initialized,
  OBS-002 sole exporter writes to the console, OBS-003 tracing captures
  full prompt and response content. These deliberately widen applies_to
  across every SDK token because their text is vendor-framed, not
  SDK-framed; per-SDK copies would be byte-identical.
- OBS-005, at medium: an observability package is declared in a hand-edited
  dependency manifest but nothing in code imports it. The dependency, the
  lockfile and the SBOM all attest to tracing that does not exist, which is a
  worse position than never having tried -- the gap survives review. Reads
  RepoProfile.ObsDeps and ignores poetry.lock, whose transitive closure proves
  nobody's intent.

schema_version 17 -> 18.
Their exporter-construction and content-capture detection
(pyObservabilitySignals in the engine) has no TS/JS counterpart yet, so
without language: python the rules silently claimed coverage of the
TS-heavy SDKs listed in their applies_to (vercel_ai, and the TS variants
of claude_sdk/langchain/google_adk/mcp) that does not exist. Mirrors the
same fix in the engine repo's testdata/rules-fixture.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants