Skip to content

security-guidance: deliver commit and push findings on stderr - #6379

Draft
mhegazy wants to merge 1 commit into
mainfrom
mhegazy/sg-commit-findings-stderr
Draft

mhegazy wants to merge 1 commit into
mainfrom
mhegazy/sg-commit-findings-stderr

Conversation

@mhegazy

@mhegazy mhegazy commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Human: @mhegazy

Summary

Commit and push findings could be replaced by an unrelated warning (anthropics/claude-code#99839, also anthropics/claude-code#92987). The findings went only into hookSpecificOutput.additionalContext, which Claude Code's asyncRewake path does not read: it shows Claude the hook's stderr, or its stdout when stderr is empty. When the agentic reviewer's inner claude printed a warning to stderr, Claude got the warning instead of the findings.

What changes

  • Findings go to stderr for every event, as the Stop path already did. stdout keeps the one JSON line with metrics and the summary.
  • The inner CLI's stderr (first 20 lines per review) and the Agent SDK's own log lines go to the plugin's debug log instead of the hook's stderr.

No version bump here. A separate PR bumps the plugin to 2.0.13 and should merge after this one.

Test plan

New tests/test_findings_delivery.py, 4 tests. Without the fix 3 of them fail. The plugin's suite passes, 192 tests, under pytest on Linux.

End to end. Run in tmux with public Claude Code 2.1.292, the plugin loaded by --plugin-dir, against a local fake API that scripts Claude and answers the plugin's review calls. The agentic reviewer's inner CLI is a stub that prints "claude.ai connectors are disabled" and exits 1, so the review falls back to a single call, which finds the bug. Claude writes a file with a shell-injection bug and commits it.

Before (main) After
What Claude was shown when the review finished The inner CLI's warning and an SDK error line. No finding. The finding. No warning.
Where the warning went To Claude The plugin's debug log

Not verified: macOS and Windows.


Generated by Claude Code

@mhegazy mhegazy self-assigned this Oct 8, 2026
@mhegazy
mhegazy force-pushed the mhegazy/sg-commit-findings-stderr branch from a4debd2 to 8f2fb08 Compare October 9, 2026 16:03
Commit and push findings went only into
hookSpecificOutput.additionalContext, which Claude Code's asyncRewake path
never reads: it shows Claude stderr, or stdout when stderr is empty. When
the agentic reviewer's inner CLI printed a warning to stderr, Claude got
that warning instead of the findings (anthropics/claude-code#99839, also
anthropics/claude-code#92987).

Findings now go to stderr for every event, as the Stop path already did.
The inner CLI's stderr and the Agent SDK's own log lines go to the
plugin's debug log.
@mhegazy
mhegazy force-pushed the mhegazy/sg-commit-findings-stderr branch from 8f2fb08 to d3fed7d Compare October 9, 2026 16:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant