Sitelet https://github.com/sudo-ai-git/cov-shield
Skip to content

About

Run pytest with repo-root addopts/coverage-gate leakage neutralized — fixer companion to harness-audit

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

1 Commit

Folders and files

Repository files navigation

cov-shield

Run your tests without the repo-root addopts / coverage-gate leakage that silently mis-scores agent-eval and benchmark grading.

cov-shield is the fixer companion to harness-audit: harness-audit detects the corruption class; cov-shield neutralizes it at invocation and tells you exactly what it stripped.

The bug this fixes

A repo-root pyproject.toml (or pytest.ini / tox.ini / setup.cfg) with

[tool.pytest.ini_options]
addopts = "--cov=harness --cov-fail-under=80"

makes any pytest run under that tree pick up the host's coverage gate — even for unrelated workspaces that aren't part of the graded project. A functionally-passing test suite is scored 0.0 because --cov-fail-under=80 fails when coverage isn't measured. This is the exact bug class documented in sudo-ai-git/vulcanbench-findings and handled by mcp-benchmark-hygiene — the one that turned every functionally-passing task into a "failure."

What cov-shield does

Zero dependencies. Deterministic. MIT. It never edits your files — it neutralizes at invocation:

# instead of:
pytest -q

# run:
cov-shield pytest -q

If a leaked addopts is found, cov-shield injects the -o addopts= override (the portable, guaranteed-correct fix — it resets both --cov gates and --cov-fail-under at the CLI) and reports:

[cov-shield] neutralized pytest addopts leakage from ['/repo/pyproject.toml']
[cov-shield] stripped: --cov=harness --cov-fail-under=80 / abort: (none)
[cov-shield] running: pytest -q -o addopts=

On a clean workspace, cov-shield runs the command verbatim — zero behavior change. Exit code is always the child's (no masking).

Why it's worth using before your eval harness trusts a number

If your agent-quality / benchmark / CI pipeline invokes pytest or a graded command inside a repo with a stray addopts, your leaderboard is wrong and you don't know it. cov-shield makes the graded run honest with a one-word change and surfaces the source of the leak.

Install

# from GitHub (no package needed):
uv tool install git+https://github.com/sudo-ai-git/cov-shield
# or run in place:
python3 cov_shield.py pytest -q

Options

  • cov-shield --debug -- <cmd> — print the full chain + classification before running.
  • cov-shield --show-chain -- <cmd> — just show what would be neutralized.
  • Any -o / --override-ini you pass yourself always wins (cov-shield won't double-inject).

Checks

  • Parses the pytest ini chain from CWD upward (same rootdir rule pytest uses): pyproject.toml, pytest.ini, tox.ini, setup.cfg.
  • Neutralizes coverage gates (--cov, --cov-fail-under, --cov-report, --cov-config) and abort gates (--maxfail, --strict, --pdb, -x, --ff).
  • --no-cov is added only when the coverage plugin is actually installed (so it can't break a cov-free env).

Status

v0.1.0. MIT. Deterministic, zero-dependency, tested (11 tests incl. a live pytest run that proves the neutralization un-fails a graded run). Part of the same agent-trust family as mcp-skill-sec, mcp-verify-claim, mcp-benchmark-hygiene, harness-audit, agent-connector.

About

Run pytest with repo-root addopts/coverage-gate leakage neutralized — fixer companion to harness-audit

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages