Run your tests without the repo-root addopts / coverage-gate leakage that silently mis-scores agent-eval and benchmark grading.
cov-shield is the fixer companion to harness-audit: harness-audit detects the corruption class; cov-shield neutralizes it at invocation and tells you exactly what it stripped.
A repo-root pyproject.toml (or pytest.ini / tox.ini / setup.cfg) with
[tool.pytest.ini_options]
addopts = "--cov=harness --cov-fail-under=80"makes any pytest run under that tree pick up the host's coverage gate — even for unrelated workspaces that aren't part of the graded project. A functionally-passing test suite is scored 0.0 because --cov-fail-under=80 fails when coverage isn't measured. This is the exact bug class documented in sudo-ai-git/vulcanbench-findings and handled by mcp-benchmark-hygiene — the one that turned every functionally-passing task into a "failure."
Zero dependencies. Deterministic. MIT. It never edits your files — it neutralizes at invocation:
# instead of:
pytest -q
# run:
cov-shield pytest -qIf a leaked addopts is found, cov-shield injects the -o addopts= override (the portable, guaranteed-correct fix — it resets both --cov gates and --cov-fail-under at the CLI) and reports:
[cov-shield] neutralized pytest addopts leakage from ['/repo/pyproject.toml']
[cov-shield] stripped: --cov=harness --cov-fail-under=80 / abort: (none)
[cov-shield] running: pytest -q -o addopts=
On a clean workspace, cov-shield runs the command verbatim — zero behavior change. Exit code is always the child's (no masking).
If your agent-quality / benchmark / CI pipeline invokes pytest or a graded command inside a repo with a stray addopts, your leaderboard is wrong and you don't know it. cov-shield makes the graded run honest with a one-word change and surfaces the source of the leak.
# from GitHub (no package needed):
uv tool install git+https://github.com/sudo-ai-git/cov-shield
# or run in place:
python3 cov_shield.py pytest -qcov-shield --debug -- <cmd>— print the full chain + classification before running.cov-shield --show-chain -- <cmd>— just show what would be neutralized.- Any
-o/--override-iniyou pass yourself always wins (cov-shield won't double-inject).
- Parses the pytest ini chain from CWD upward (same rootdir rule pytest uses):
pyproject.toml,pytest.ini,tox.ini,setup.cfg. - Neutralizes coverage gates (
--cov,--cov-fail-under,--cov-report,--cov-config) and abort gates (--maxfail,--strict,--pdb,-x,--ff). --no-covis added only when the coverage plugin is actually installed (so it can't break a cov-free env).
v0.1.0. MIT. Deterministic, zero-dependency, tested (11 tests incl. a live pytest run that proves the neutralization un-fails a graded run). Part of the same agent-trust family as mcp-skill-sec, mcp-verify-claim, mcp-benchmark-hygiene, harness-audit, agent-connector.