Repository navigation
Conversation
PR validation —
|
| Status | Policy | Material | Messages |
|---|---|---|---|
pr-min-approvals |
pr-info |
PR/MR #3434 has 0 approving reviews, 1 required. | |
| ✅ Passed | pr-description-required |
pr-info |
- |
pr-user-story-linked |
pr-info |
PR/MR #3434 does not reference a user story or issue in title, description, or branch 'feat(cli): show the trace welcome message and session link in opencode'. Expected patterns: ["(?i)[A-Z]+-[0-9]+", "#[0-9]+", "(?i)gh-[0-9]+", "(?i)\\[[A-Z]+-[0-9]+\\]"] |
AI Session Checks — 🟡 80% · ⚠️ 1 failing
| Avg score | Sessions | Failing policies | Attribution | Files | Lines | Total Duration |
|---|---|---|---|---|---|---|
| 🟡 80% | 1 | 100% AI / 0% Human | 13 | +463 / -159 | 38m55s |
🟡 80% — 100% AI — ⚠️ 1 policies failing
-
Oct 8, 2026 20:37 UTC · 38m55s · $18.35 · 534 in / 185.3k out · claude-code 2.1.295 (claude-opus-5-5)
Change Summary
-
- Rebases the trace feature onto main for OpenCode 2 and updates session-start and user-message handling.
- Adjusts providers, hooks, and generated plugin goldens so greetings and session links reach users.
- Extends tests and live probes around OpenCode behavior, plus a small README update.
AI Session Overall Score
-
🟡 80% — Strong technical work, but planning, trust, and final confirmation stayed weaker than execution.
AI Session Analysis Breakdown
-
🟢 88% · alignment
-
No notes.
🟢 85% · solution-quality
-
🟢 The AI empirically probed OpenCode 2 before changing the implementation. · High Impact
🟡 78% · scope-discipline
-
🟡 README work was volunteered beyond the rebase-and-validate request. · Low Severity
🟡 78% · verification
-
🟢 The AI reran failing tests to green and also exercised OpenCode 2 live. · High Impact
🟠 Tests and live OpenCode 2 probes passed, but the engaged user never confirmed the rebased behavior. · Medium Severity
💡 When the user is still engaged, ask for explicit confirmation after major validation runs instead of relying only on self-reported success.
🟡 72% · context-and-planning
-
🟢 The opening brief front-loaded constraints, commit rules, tests, and reply protocol. · High Impact
🟠 The multi-file OpenCode 2 rewrite proceeded without a visible plan, TODO, or plan-mode step. · Medium Severity
💡 Before a multi-file rewrite, write a short shared plan naming scope, checks, and stop conditions.
🟡 62% · user-trust-signal
-
🟠 A peer-orchestrator halted PR work after the rebase and force-push, signaling a confidence drop. · Medium Severity
💡 When delegation spans sessions, pause on branch-history changes until scope approval is explicit to every operator involved.
-
File Attribution
████████████████████100% AI / 0% HumanStatus Attribution File Lines modified ai app/cli/internal/trace/opencode/hooks.go+77 / -32 modified ai app/cli/internal/trace/opencode/testdata/plugin_full.ts+74 / -31 modified ai app/cli/internal/trace/opencode/testdata/plugin_tracerun.ts+74 / -31 modified ai app/cli/internal/trace/opencode/hooks_test.go+80 / -3 modified ai app/cli/internal/trace/opencode/provider.go+47 / -30 modified ai app/cli/internal/trace/opencode/announce_test.go+52 / -14 modified ai app/cli/pkg/action/trace_agent_hook.go+25 / -7 modified ai app/cli/internal/trace/claude/provider.go+11 / -2 modified ai app/cli/internal/trace/README.md+6 / -4 modified ai app/cli/internal/trace/claude/announce_test.go+5 / -2 modified ai app/cli/internal/trace/provider.go+7 / -0 modified ai app/cli/internal/trace/providers/capabilities_test.go+2 / -2 modified ai app/cli/pkg/action/trace_banner_test.go+3 / -1
Policies (4, 1 failing)
Status Policy Material Messages ✅ Passed ai-config-ai-agents-allowedai-coding-session-a39319- ✅ Passed ai-config-no-dangerous-commandsai-coding-session-a39319- ⚠️ Failedai-config-no-secretsai-coding-session-a39319Secret (generic-password) detected in session content [turn=253, source=tool_result, line=2]: :"\u2612",checkboxOff:"\u2610",tick:"\u2714",ellipsis:"\u2026",pointerSmall:"\u203A",pointer:"\u276F",descriptionSeparator:"- ",[CHAINLOOP_TRACE_REDACTED:generic-password]Mask:"*",toggleSeparator:"/",... ✅ Passed ai-config-mcp-servers-allowedai-coding-session-a39319- -
Security Checks — ✅ 5 passing
✅ secret-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | secrets-detection |
- |
✅ sast-scan
| Status | Policy | Messages |
|---|---|---|
| ✅ Passed | owasp-top10-2025 |
- |
| ✅ Passed | sast |
- |
| ✅ Passed | cwe-top25 |
- |
| ✅ Passed | cwe-top26-40-cusp |
- |
Scans not applied (3)
| Scan | Reason |
|---|---|
vulnerability-scan |
no manifest/lockfile changed |
github-actions-scan |
no workflow files changed |
iac-scan |
no IaC files changed |
Security context
This change touches code with 2 recorded security-fix advisories. These are pointers to what past fixes established, not findings in this diff, and they never fail the check.
View in Chainloop ↗ · How this works ↗
Powered by Chainloop and Chainloop Trace
There was a problem hiding this comment.
All reported issues were addressed across 12 files
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
Bring OpenCode up to the Claude Code experience for the two trace messages meant for the user: the welcome message at session start, and the link to the attested session after a push. Both work on OpenCode 1.x and OpenCode 2. The hook writes one JSON response that the plugin reads. OpenCode 1.x shows the messages as a TUI toast, which is not awaited, and adds the link to the shell output for the model. An OpenCode 2 plugin has no toast, so the welcome message is the description of the synthetic message that carries the spec instruction, and the link is a content part of the shell result, which the TUI shows and the model reads. The blank lines that frame the welcome message move into the Claude provider, since other agents frame it themselves. The instruction that asks the model to repeat a message is one shared constant, and the dashboard lookup for the welcome message runs alongside session tracking. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: a3931907-c590-40a1-90c6-2c29aa204404
8570e16 to
e585f40
Compare
There was a problem hiding this comment.
All reported issues were addressed across 13 files
Reply with feedback, questions, or to request a fix.
View guided diff | Re-trigger cubic
When the session-start hook has a banner and no instruction, for example after a resume, the plugin gave the banner to the model as the text of the session message. The banner is for the user only, so the plugin now posts the instruction as the text and nothing when there is none. OpenCode 1.x still shows the banner as a toast, and OpenCode 2 still shows it as the message description. Assisted-by: Claude Code Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev> Chainloop-Trace-Sessions: a3931907-c590-40a1-90c6-2c29aa204404
First step to bring OpenCode trace support up to the level of Claude Code. This adds the two messages meant for the user, on OpenCode 1.x and OpenCode 2: the welcome message at session start, which tells that Chainloop records the session and where the evidence goes, and the link to the attested session after a push.
OpenCode defines no hook response of its own, so the hook writes one JSON response that the generated plugin reads.
Other changes in the shared layer:
The feature table in
app/cli/internal/trace/README.mdis updated. Later steps will bring the other features (spec source pointers, pasted image pointers, and so on) to OpenCode.This pull request was produced with AI assistance (Claude Code). The commit carries an
Assisted-bytrailer.🤖 Posted by Maximus bot (Claude Code) on behalf of @migmartri