Summary
dependency_sources caps its analysis at a fixed 5 s of wall-clock time that cannot be raised:
_MAX_ANALYSIS_SECONDS = 5.0
...
timeout_seconds=(
_MAX_ANALYSIS_SECONDS
if timeout_seconds is None
else min(_MAX_ANALYSIS_SECONDS, max(0.0, timeout_seconds))
),
When the cap is hit, the ledger records runtime_limit, the analysis is incomplete, and safe_to_install is false. Because the cap is wall-clock time, the same unchanged tree gets a complete result on an idle machine and an incomplete one under load. Unlike the aggregate workflow budget (#460, SKILLSPECTOR_MAX_WORKFLOW_SECONDS) and the per-artifact static budget (SKILLSPECTOR_MAX_STATIC_ANALYSIS_SECONDS_PER_ARTIFACT), there is no way to raise it.
Versions: v2.12.0 (c7958a3); the constant is unchanged on main (2226747).
Observed
The same 51-file tree (a skill with Python scripts and a JSON file under scripts/reviewed/), scanned repeatedly with --no-llm:
- idle machine: about 27 s, complete;
- under load: 105-148 s; one run complete, the next with
{"reason_code": "runtime_limit", "path": "scripts/reviewed"} and partially_inspected_files: 1.
With --no-llm the only runtime_limit source we found is dependency_sources.
Expected
The cap follows the workflow budget or an environment variable like the other budgets, so a verdict does not depend on machine load. Alternatively, a timed-out dependency-source pass could be reported without making the file partially inspected when every other analyzer completed.
Summary
dependency_sourcescaps its analysis at a fixed 5 s of wall-clock time that cannot be raised:When the cap is hit, the ledger records
runtime_limit, the analysis is incomplete, andsafe_to_installis false. Because the cap is wall-clock time, the same unchanged tree gets a complete result on an idle machine and an incomplete one under load. Unlike the aggregate workflow budget (#460,SKILLSPECTOR_MAX_WORKFLOW_SECONDS) and the per-artifact static budget (SKILLSPECTOR_MAX_STATIC_ANALYSIS_SECONDS_PER_ARTIFACT), there is no way to raise it.Versions: v2.12.0 (
c7958a3); the constant is unchanged onmain(2226747).Observed
The same 51-file tree (a skill with Python scripts and a JSON file under
scripts/reviewed/), scanned repeatedly with--no-llm:{"reason_code": "runtime_limit", "path": "scripts/reviewed"}andpartially_inspected_files: 1.With
--no-llmthe onlyruntime_limitsource we found isdependency_sources.Expected
The cap follows the workflow budget or an environment variable like the other budgets, so a verdict does not depend on machine load. Alternatively, a timed-out dependency-source pass could be reported without making the file partially inspected when every other analyzer completed.