Luigit
repositories / dotfiles

dotfiles

bugabingas dorkfiles

owned by admin

pi/agent/workflows/security-scan-workers.json

Raw
{
  "name": "security-scan-workers",
  "description": "Run isolated security-scan worker tasks with a path-gated review writer.",
  "args": {
    "hint": "JSON object containing a tasks array"
  },
  "schemas": {
    "WorkerResult": {
      "type": "object",
      "properties": {
        "taskId": {
          "type": "string"
        },
        "outputPath": {
          "type": "string"
        },
        "ok": {
          "type": "boolean"
        },
        "count": {
          "type": "integer",
          "minimum": 0
        },
        "result": {
          "type": "string"
        }
      },
      "required": [
        "taskId",
        "outputPath",
        "ok",
        "count",
        "result"
      ]
    }
  },
  "phases": [
    {
      "id": "work",
      "kind": "fanout",
      "over": "{args.tasks}",
      "concurrency": 4,
      "writeIsolation": "Every task descriptor owns one unique outputPath beneath ai-workspace/security-reviews; callers must never submit duplicate output paths in one run.",
      "step": {
        "summary": "Run security task {item}",
        "prompt": "Execute this security-scan task: {item}. Read the agentTemplate named in the descriptor and follow its security analysis, scope, evidence, severity, and document-format instructions. The descriptor and this prompt override the template's harness-specific tool and final-response instructions. Use lowercase Pi tools. Use security_review_writer instead of Write, and write only the descriptor's outputPath. Do not modify source code, config, findings outside outputPath, or any other file. Read only the stated scope plus imported shared controls needed to verify a claim. After writing, read outputPath back and verify it. Then submit structured output matching WorkerResult: echo taskId and outputPath, set ok, set count to the number of findings, reviews, or scenarios produced as appropriate, and summarize the result tersely. Never return the report body through structured output.",
        "tools": [
          "read",
          "grep",
          "find",
          "ls"
        ],
        "dynamicExtensions": [
          "security-review-writer"
        ],
        "model": "large",
        "thinkingLevel": "high",
        "schema": "WorkerResult"
      }
    }
  ],
  "return": "{work.results}"
}