Skip to content

fix(lh-132058): align harness grading and skill guidance with runs - #41

Merged
huides00 merged 3 commits into
mainfrom
LH-132058-harness-skill-guidance
Oct 2, 2026
Merged

huides00 merged 3 commits into
mainfrom
LH-132058-harness-skill-guidance

Conversation

@huides00

@huides00 huides00 commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

https://cisco-sbg.atlassian.net/browse/LH-132058

Description

Recent Bedrock reliability runs passed 449 of 450 samples, but the review showed that the one
recurring failure and several weaker signals came from the test harness and the CLI skill rather
than from agent behavior. The missing-profile scenario rejected correct answers that described the
configuration command as not exposed, because it only accepted three exact phrasings. It now
accepts those equivalent wordings and still fails an answer that never says the command is missing.

The CLI skill now tells users that API tokens are generated in the SCC Firewall Manager UI by an
API-only user, replacing guidance that sent them to the developer documentation site, which does
not issue tokens. The skill also stops naming the profile file location, which agents had been
repeating to users despite being told not to state paths they had not observed.

The Bedrock lane now tells the agent where its loaded skill file lives, so the setup skill can find
its helper scripts without the repeated searching seen in the runs. A follow-up Bedrock run is
still needed to confirm the improvement in practice.

Bedrock reliability runs showed the missing-profile scenario failing on correct answers that said
the configuration command "isn't exposed" instead of one of three exact phrasings. The fixture now
accepts those equivalent wordings, including curly apostrophes, while still failing an answer that
never says the command is missing.

The CLI skill told agents that API tokens come from developer.cisco.com, which only hosts the
documentation, so nearly every missing-profile answer sent users to the wrong place. It now states
that tokens are generated in the SCC Firewall Manager UI by an API-only user. The skill also no
longer names the profile file location, which agents repeated despite the rule against stating a
path not seen in tool output.

The Bedrock lane inlines the skill text without its location, so the setup skill could not resolve
its helper scripts and agents spent many commands searching for them. The system prompt now states
the path of the staged skill file the agent can reach inside its sandbox.
Two urllib3 advisories, PYSEC-2026-4175 and PYSEC-2026-4177, were published after the last green
main build and now fail the runtime dependency audit on every branch. Both are fixed in urllib3
2.8.0, but the SCC Firewall Manager SDK requires urllib3 below 2.1.0 in both the locked release
and the newest one on PyPI, so the patched version cannot be resolved.

The two IDs join the existing exception list kept for the same SDK pin, and the guard test that
counts the exceptions is raised to match so further additions still need an explicit change. The
exceptions should be removed once the SDK permits a patched urllib3 release.
The fix commit on this branch makes the next release a patch, and release preparation requires
the target version to be recorded in source. Add the 0.43.1 entry covering the harness grading,
skill guidance, Bedrock skill path, and urllib3 audit exception changes.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Consistency Check

No consistency issues found.

Checker output
✓ No issues found across 5 file(s).

@huides00
huides00 merged commit 3a0599b into main Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants