You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
AgentsShield is producing too much noise. It is an essential tool that checks the coding agents environment (used as part of pre-agent startup, pre-commit hooks, and CI checks), but if it produces too much noise users will stop reading scan results. For example, when issues are in an third-party plugins (like in gw0/docker-claude-code), the plugin maintainer may refuse to fix a non-critical issue and one does not want to maintain a fork (workaround would be to exclude that plugin dir #149). Scan results in terminal format are too verbose by default (verbose descriptions/evidence/fix). Because it always finds a ton of issues (in third-party plugins), it would be better to show a condensed list of issues by default and provide a verbose mode to list all the details.
Additionally, full scan results are always shown even if someone provides a baseline file. One would expect that the purpose of a baseline file is that it only shows issues not in this file (no one wants to see again what is already in the baseline file, and no one cares about "RESOLVED" status).
Suggested improvements:
Add --verbose (or --silent) as options to suppress noise. It should just show a condensed list of issues (no verbose descriptions/evidence/fix).
When a baseline file is provided only show new scan results. Skip issues already existing in baseline file. Also do not show resolved issues (unless in --verbose mode). With this the "Baseline Comparison Report" can just be removed as it would show the same information (only the changes).
Other findings:
Duplicate functionality agentshield init and agentshield baseline write, but init is lacking options.
AgentsShield is producing too much noise. It is an essential tool that checks the coding agents environment (used as part of pre-agent startup, pre-commit hooks, and CI checks), but if it produces too much noise users will stop reading scan results. For example, when issues are in an third-party plugins (like in gw0/docker-claude-code), the plugin maintainer may refuse to fix a non-critical issue and one does not want to maintain a fork (workaround would be to exclude that plugin dir #149). Scan results in
terminalformat are too verbose by default (verbose descriptions/evidence/fix). Because it always finds a ton of issues (in third-party plugins), it would be better to show a condensed list of issues by default and provide a verbose mode to list all the details.Additionally, full scan results are always shown even if someone provides a baseline file. One would expect that the purpose of a baseline file is that it only shows issues not in this file (no one wants to see again what is already in the baseline file, and no one cares about "RESOLVED" status).
Suggested improvements:
--verbose(or--silent) as options to suppress noise. It should just show a condensed list of issues (no verbose descriptions/evidence/fix).--verbosemode). With this the "Baseline Comparison Report" can just be removed as it would show the same information (only the changes).Other findings:
agentshield initandagentshield baseline write, but init is lacking options.~/.claudeskip~/.claude/plugins/cache/by default (not just decrease severity) (just add to exclude dir feat: Add --exclude-dir/--exclude options #149).Steps to reproduce the baseline noise:
One would expect to see just an empty list of changes compared to baseline.