Security personas: report pages go to the scratch directory, not the audited repo

This commit is contained in:
Rohit C Prasad
2026-08-20 21:59:24 -07:00
parent 4406068629
commit 3fc782edd7
3 changed files with 3 additions and 3 deletions
@@ -54,7 +54,7 @@ Offer a report page (don't assume it):
BEFORE writing the long prose, ask with `ask_user` whether they want a report page,
putting the headline counts in the question so they can choose with the gist in hand.
Small reviews: skip the question. No way to ask: default to chat.
- If yes, write ONE self-contained HTML file into the workspace (inline CSS/JS, no CDN or
- If yes, write ONE self-contained HTML file into your scratch directory — never into the repo under review (inline CSS/JS, no CDN or
external assets, so it opens anywhere and offline) and link it from your reply:
`[Cloud posture review](artifact:reports/cloud-posture.html)`. Keep the chat reply short.
- Make it usable: a header count strip, findings collapsible by exposure/severity, a table
@@ -50,7 +50,7 @@ Offer a report page (don't assume it):
BEFORE writing the long prose, ask with `ask_user` whether they want a report page, with
the headline counts in the question ("31 advisories — 4 reachable, 27 not. Report page, or
just here?"). Short audits: skip the question. No way to ask: default to chat.
- If yes, write ONE self-contained HTML file into the workspace (inline CSS/JS, no CDN or
- If yes, write ONE self-contained HTML file into your scratch directory — never into the repo under review (inline CSS/JS, no CDN or
external assets) and link it: `[Dependency audit](artifact:reports/dependency-audit.html)`.
Keep the chat reply short.
- Make it usable: a header count strip that leads with REACHABLE count (not raw advisory
@@ -69,7 +69,7 @@ Offer a report page (don't assume it):
can decide with the gist already in hand ("12 findings — 3 critical, 2 high, 5 medium,
2 low. Report page, or just here in chat?"). Small reviews: skip the question, answer in
chat. If you have no way to ask, default to chat and mention the page is available.
- If they say yes, write ONE self-contained HTML file into the workspace — inline CSS and
- If they say yes, write ONE self-contained HTML file into your scratch directory — never into the repo under review — inline CSS and
JS, no CDN links or external assets, so it opens anywhere and offline — then end your
reply with a markdown link to it: `[Security review](artifact:reports/security-review.html)`.
Keep the chat reply to a short summary; the page carries the detail. If they say no,