Skip to content

feat: add markdown output for exposure scoring - #8

Open
mattpartida wants to merge 2 commits into
mainfrom
feat/20260810-exposure-score-markdown
Open

mattpartida wants to merge 2 commits into
mainfrom
feat/20260810-exposure-score-markdown

Conversation

@mattpartida

Copy link
Copy Markdown
Owner

Summary

score_prompt_injection_exposure.py was the only one of the three main scanner scripts without Markdown output. config_risk_summary.py (Phase 1) and flag_prompt_injection_signals.py (#6) already support --format json|markdown. This PR closes that parity gap by adding --format json|markdown to the exposure scorer, keeping JSON as the default so all existing consumers continue to work unchanged.

Why this is safe / additive

  • New format only. No existing JSON field, severity, score, or factor changed. JSON output is byte-identical when --format is omitted.
  • The markdown renderer mirrors the structure used by the other two scripts: a header block, optional factors table, and the heuristic note.
  • Error inputs (empty/invalid) render a consistent header so PR comments and review notes stay well-formed.
  • No new dependencies.

Files changed

  • skills/agent-security/scripts/score_prompt_injection_exposure.py — added render_markdown(), markdown_cell(), and --format json|markdown (default json).
  • tests/test_score_prompt_injection_exposure.py — 6 new tests covering header/score, factors table, total + note, empty-input error rendering, clean-config no-factors branch, and JSON-as-default.
  • README.md — added a --format markdown example next to the existing exposure-scoring quick start.
  • skills/agent-security/SKILL.md — added a markdown example to the script usage block.
  • CHANGELOG.md — unreleased script CLI entry.

Test Plan

Local verification (Python 3.11, matching CI):

  • python -m compileall -q skills tests — OK
  • ruff check . — All checks passed
  • python -m pytest -q — 95 passed (89 prior + 6 new)
  • ./package-skills.sh — packaged both skills
  • git diff --check — clean

Add --format json|markdown to score_prompt_injection_exposure.py,
bringing it to parity with config_risk_summary.py and
flag_prompt_injection_signals.py. JSON remains the default so existing
consumers are unaffected.

The markdown renderer emits a score/severity header, a risk factors
table with per-factor points, a total points line, and the heuristic
note. Empty/clean configs and error inputs render a consistent header
without a factors table.
…e-score-markdown

# Conflicts:
#	CHANGELOG.md
@mattpartida

Copy link
Copy Markdown
Owner Author

Resolved merge conflict against latest main (both CHANGELOG entries kept: exposure-score markdown + reproducible packages). Merge commit 4d43856, normal push (no force). Verified locally on Python 3.11 (CI pin): 135 tests pass, ruff clean, compileall clean, ./package-skills.sh OK.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant