Continuous integration

Run AttackTree's checks and simulation in CI without an agent, upload findings to GitHub code scanning as SARIF, and gate pull requests on residual risk.

The engine needs no LLM, so every check and the simulation run in CI. This guide covers the bundled GitHub Action and the plain command line.

# GitHub Action

# .github/workflows/attacktree.yml
name: AttackTree
on: [pull_request]
permissions:
  contents: read
  security-events: write   # for the SARIF upload
jobs:
  attacktree:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: hupe1980/spec-kit-attacktree@v0.1.0
        with:
          feature-dir: specs/007-agent-assistant

The action runs the checks, uploads the findings to code scanning under the attacktree category, runs the simulation, and fails the job on HIGH or CRITICAL findings.

InputDefaultEffect
feature-dirauto-detectFeature directory; otherwise SPECIFY_FEATURE, the branch name, or the newest spec.
formatmdCheck report format in the log: md or json.
strictfalseAlso fail on MEDIUM findings.
scenariocurrentControl statuses the simulation counts: none, current, verified, planned, or all.
fail-on-blocking-goalsfalseFail while a goal is at risk.block_on residual risk without a decision.
upload-sariftrueUpload findings to code scanning.
fail-on-findingstrueFail on the check’s exit code.

Outputs: exit-code (check), simulate-exit-code, and sarif (the file path).

# Which gate to use

  • Every pull request: the default. Structural errors and missing links fail the build; verification gaps before implementation stay LOW, so they don’t.
  • Before merging to main: add fail-on-blocking-goals: "true" with scenario: planned. The agreed roadmap must bring every goal below the blocking level.
  • After implementation: scenario: verified counts only controls with evidence.

# Command line

The same engine runs anywhere Python and PyYAML are available:

EXT=.specify/extensions/attacktree/scripts/bash/attacktree.sh
$EXT --feature-dir specs/007-agent-assistant check --format sarif --output attacktree.sarif
$EXT --feature-dir specs/007-agent-assistant simulate --scenario current --no-monte-carlo
CommandExit 0Exit 1Exit 2
checknothing above MEDIUMHIGH, or MEDIUM with --strictCRITICAL
simulateno blocking goala goal at risk.block_on—
converge-applyconvergednot converged—

# Phase-aware verification findings

Check A9, a requirement without verification, follows implementation progress. It is LOW while no task for the requirement is done, MEDIUM while some are, and MEDIUM or HIGH once all are done but nothing verifies it. HIGH applies when the control guards a high or critical goal. A pull request that only changes the spec therefore does not fail for missing evidence.

# Code scanning

With upload-sarif, findings appear in the repository’s Security → Code scanning tab and as annotations on the pull request, with rule IDs A1 to A16, the file, and a recommendation.