Keep live checks aligned with corpus and output bounds - #12
Merged
Merged
Conversation
|
Reviewed this PR against the read-only MCP server's provenance/escaping/truncation-disclosure/no-scope-creep checklist. Scope: test-only changes ( Checked specifically:
No findings. LGTM. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Live verification could report two false failures after normal corpus changes: an upstream Git file named by the wide-fence test was removed, and the shared MCP output budget omitted
catalog_kindfrom a partial row. Check the complete API file inventory before declaring the optional Git case unavailable, and compare filtered row identities and available fields against the API's bounded page while honoring disclosed truncation. Incorrect values, changed ordering, incomplete inventories, and API errors still fail. The independent oversized ExploitDB read remains mandatory.Validation: Ruff, formatting, mypy, and 1,970 hermetic tests passed at 97.33% coverage. Against the current production API with the deployed SDK version, all 227 live checks passed; two explicit corpus-conditional skips cover an unavailable undocumented verdict and the removed wide-fence file. Three independent review lenses found no significant issues; reviewers also exercised negative controls. No runtime behavior or deployment changes.