Skip to content

bug: Gator routes unmerged PR security regressions into private triage #4337

Description

@johntmyers

User Story

I use OpenShell's supervised Gator sandboxes to review my OpenShell pull requests with explicit test authorization. On PR #4323, I encountered a generic private-security blocker instead of actionable review feedback about a regression in the unmerged changes.

Problem Statement

Gator's broad instruction to follow SECURITY.md for security vulnerabilities does not clearly distinguish PR-introduced regressions from pre-existing vulnerabilities independent of the PR. A reviewer can therefore retain actionable findings only in the sandbox, post a generic private-triage notice, and suspend authorized test dispatch solely because the finding is security-related.

The observed watcher completed its review cycle with exit code 0 and private_security_review_required. This issue concerns review routing, not the technical details or validity of that finding. No evidence of external disclosure was found in the inspected retained logs.

Impact / Why This Matters

Authors cannot address unmerged security regressions through the normal PR review workflow. Maintainers must inspect sandbox artifacts and resolve an unnecessary disclosure-process detour before review can advance.

Acceptance Criteria

  • Security regressions introduced or newly exposed by an unmerged PR appear as actionable findings in that PR's normal review evidence contract.
  • A new reachable path, trusted sink, or security contract remains PR-owned even if an underlying unsafe primitive pre-existed.
  • Security classification alone does not create a private-triage gate or suspend operator-authorized tests; normal evidence, blocker, and test authorization rules remain intact.
  • Pre-existing vulnerabilities independent of the PR continue to follow SECURITY.md without publishing exploit details.
  • External reporting requires explicit operator authorization.
  • The gate skill, top-level prompt, independent reviewer, and launcher guidance consistently state this distinction, with regression checks and an immutable payload bump.

Reproduction Steps

  1. Launch a supervised OpenShell Gator watcher for PR feat(ocsf): emit full JSON records to supervisor stderr #4323 with explicit /ok to test authorization using payload 11.
  2. Inspect its public disposition and /sandbox/.openshell-agent/status.json with OpenShell.
  3. Observe a generic private-security notice and private_security_review_required rather than actionable PR-owned review findings.

Environment

  • OpenShell gateway: 0.1.3-dev.58+gb74694141
  • OS: Linux
  • Compute driver: Docker; gateway docker-dev, workspace gator
  • Gator: Codex harness, supervised watch mode, payload 11

Scope

Clarify contributor review instructions. Do not change SECURITY.md, publish the retained finding, waive normal review blockers, or initiate external disclosure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions