Summary
build_declared_marker_views reads a Docker argv list in Python as an ambiguous text-removal directive (the verb drop in --cap-drop, followed by several quoted strings) and marks the file obfuscated_instruction_text. The file then counts as partially inspected, so the target cannot reach safe_to_install. Related to the JSON case fixed in #515, but this is plain Python code and still reproduces on current main.
Versions: v2.12.0 (c7958a3) and main at 2226747, --no-llm.
Reproducer
repro/capture.py:
import subprocess
def capture_argv(name, image):
return ["docker", "run", "-d", "--name", name,
"--cap-drop", "ALL", "--cap-add", "NET_RAW", "--read-only", image]
def docker(*args):
return subprocess.run(["docker", *args], capture_output=True, text=True)
skillspector scan repro --no-llm --format json --output r.json
Actual
"partially_inspected_files": 1,
"ledger_exceptions": [{"reason_code": "obfuscated_instruction_text", "path": "capture.py", ...}]
Writing the flag as one token ("--cap-drop=ALL") in the same list still triggers it. In a larger file we saw the same for dictionary keys such as {"Path": path, "Read": True, "Write": False, "Delete": False}.
Expected
A removal verb that is part of a command-line flag, a code identifier or a dictionary key, inside source code, is not a natural-language instruction, and the file completes static analysis.
Summary
build_declared_marker_viewsreads a Docker argv list in Python as an ambiguous text-removal directive (the verbdropin--cap-drop, followed by several quoted strings) and marks the fileobfuscated_instruction_text. The file then counts as partially inspected, so the target cannot reachsafe_to_install. Related to the JSON case fixed in #515, but this is plain Python code and still reproduces on currentmain.Versions: v2.12.0 (
c7958a3) andmainat2226747,--no-llm.Reproducer
repro/capture.py:skillspector scan repro --no-llm --format json --output r.jsonActual
Writing the flag as one token (
"--cap-drop=ALL") in the same list still triggers it. In a larger file we saw the same for dictionary keys such as{"Path": path, "Read": True, "Write": False, "Delete": False}.Expected
A removal verb that is part of a command-line flag, a code identifier or a dictionary key, inside source code, is not a natural-language instruction, and the file completes static analysis.