Summary
This proposal covers two bounded static-analysis paths in SkillSpector: PowerShell code that invokes or embeds shell commands, and SC8's shipped-bytecode scan budget. If either path cannot finish or prove the supported syntax it is examining, the scan must retain an incomplete ledger result rather than report the affected content as clean.
PowerShell shell projection
static_patterns_tool_misuse.has_bounded_parse_exhaustion analyzes shell commands embedded in PowerShell source and Markdown powershell fences. PowerShell comments, closed here-strings, and inert quoted text should not be mistaken for shell commands. Supported executable payloads passed through bash/sh -c, Invoke-Expression, script-block creation, and call operators must retain the existing bounded shell checks and source locations.
Projection is deliberately conservative. Unclosed strings, here-strings or fences; unresolved dynamic calls; unsupported nested command syntax; and companion context that cannot be proven must remain STATIC_PARSE_LIMIT and make the public analysis partial. For ForEach-Object -Parallel, the fixed companion binding must be tied to the exact loaded source and established before the parallel call. A matching assignment after the call is not proof that the call used that companion and must remain partial.
SC8 shipped-bytecode budget
The shipped-bytecode pass needs two independent limits: its five-second active-processing allowance and the enclosing workflow's monotonic wall deadline. Time spent waiting while sibling work proceeds must not consume the active-processing allowance. The workflow wall deadline remains a hard bound, and a standalone SC8 pass remains wall-clock bounded. Exhausting either bound records runtime_limit and leaves the scan incomplete; it must never turn skipped work into a clean result.
Related work and scope
Regression coverage
The candidate adds or extends checks for PowerShell literals and nested executable payloads, dynamic or unclosed PowerShell contexts, Markdown fence completeness and original line offsets, exact companion identity/order (including assignment-after-call), and SC8 active time versus workflow wall time. Depth, output, and CLI completeness reporting remain covered.
Please advise whether the PowerShell portion should follow PR #627, be added to #694, or remain a separate issue. The local candidate has not passed every contribution gate yet; its complete test and review results will be reported with a PR.
Summary
This proposal covers two bounded static-analysis paths in SkillSpector: PowerShell code that invokes or embeds shell commands, and SC8's shipped-bytecode scan budget. If either path cannot finish or prove the supported syntax it is examining, the scan must retain an incomplete ledger result rather than report the affected content as clean.
PowerShell shell projection
static_patterns_tool_misuse.has_bounded_parse_exhaustionanalyzes shell commands embedded in PowerShell source and Markdownpowershellfences. PowerShell comments, closed here-strings, and inert quoted text should not be mistaken for shell commands. Supported executable payloads passed throughbash/sh -c,Invoke-Expression, script-block creation, and call operators must retain the existing bounded shell checks and source locations.Projection is deliberately conservative. Unclosed strings, here-strings or fences; unresolved dynamic calls; unsupported nested command syntax; and companion context that cannot be proven must remain
STATIC_PARSE_LIMITand make the public analysis partial. ForForEach-Object -Parallel, the fixed companion binding must be tied to the exact loaded source and established before the parallel call. A matching assignment after the call is not proof that the call used that companion and must remain partial.SC8 shipped-bytecode budget
The shipped-bytecode pass needs two independent limits: its five-second active-processing allowance and the enclosing workflow's monotonic wall deadline. Time spent waiting while sibling work proceeds must not consume the active-processing allowance. The workflow wall deadline remains a hard bound, and a standalone SC8 pass remains wall-clock bounded. Exhausting either bound records
runtime_limitand leaves the scan incomplete; it must never turn skipped work into a clean result.Related work and scope
dependency_sourcesceiling and its operator configuration. This proposal does not changedependency_sources.pyor that setting; it concerns the separate SC8 pass and PowerShell projection.static_parse_limitresults for Rust, Python, and POSIX shell. This proposal is PowerShell-specific, but uses the same bounded-parser hook, so maintainers should decide whether to keep it separate or extend static_parse_limit on valid Rust, Python and POSIX shell source leaves files partially inspected #694._markdown_shell_text. The PowerShell-fence work touches that same function and overlapping return/fence-processing hunks. Please coordinate whether it belongs as a follow-up to fix(analyzer): avoid false shell parse limits in Markdown #627 before opening parallel work.static_parse_limit, forcing partial scans and a HIGH AE1 finding #628.Regression coverage
The candidate adds or extends checks for PowerShell literals and nested executable payloads, dynamic or unclosed PowerShell contexts, Markdown fence completeness and original line offsets, exact companion identity/order (including assignment-after-call), and SC8 active time versus workflow wall time. Depth, output, and CLI completeness reporting remain covered.
Please advise whether the PowerShell portion should follow PR #627, be added to #694, or remain a separate issue. The local candidate has not passed every contribution gate yet; its complete test and review results will be reported with a PR.