security-review/.security-review-skip
Adam Moussa 094a253c37
feat(canary): add anti-complacency recall-floor corpus + repo skip marker
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed,
answer-revealing comments stripped so it measures real detection) and canary-meta/
(KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it).
One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so
it stays a CWE-798 finding without tripping push protection.

Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip
this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as
its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
2026-06-29 12:10:54 -04:00

9 lines
576 B
Text

This repo is excluded from the org-wide security sweep and the local git pre-push gate.
Reason: it intentionally contains secret-shaped / deliberately-vulnerable content that would
otherwise always ALARM — the `canary/` anti-complacency corpus (planted vulns, answer key in
`canary-meta/`) and the checker test fixtures under `checkers/fixtures/`.
The nightly sweep scans `canary/` DIRECTLY as its recall-floor check, bypassing this skip marker
(that is the whole point of the canary). Repos skipped via a committed marker are logged in the
sweep report for auditability.