H7: Role Confusion #
The message sequence contains a selected role or ordering inconsistency.
Applies to: Recognized structured message arrays; not Python extraction mode. Manual repair; no automatic fix for this example.
What triggers it #
Checks multiple system messages, a misplaced system message, consecutive same-role user/assistant messages, orphan tool results, and missing roles. It does not validate every provider protocol.
How to repair it #
Repair the message array according to the target API. In this example, consolidate the two system instructions into the leading system message.
Reproduce the finding #
Use uv and Python 3.10+, plus curl. Run the examples in a scratch directory.
{
"messages": [
{
"role": "system",
"content": "Review invoice totals."
},
{
"role": "system",
"content": "Return discrepancies as JSON."
},
{
"role": "user",
"content": "Check this invoice."
}
]
}
curl -fsS https://lintlang.ai/examples/rules/h7-bad.json -o h7-bad.json
uvx --from lintlang==0.8.0 lintlang scan h7-bad.json --format json
Expected with 0.8.0: the JSON report includes H7, severity HIGH. This example exercises multiple system messages. Confirm your provider’s message contract before changing production conversation ordering.
Improved example #
Download the improved example.
{
"messages": [
{
"role": "system",
"content": "Review invoice totals and return discrepancies as JSON."
},
{
"role": "user",
"content": "Check this invoice."
}
]
}
curl -fsS https://lintlang.ai/examples/rules/h7-improved.json -o h7-improved.json
uvx --from lintlang==0.8.0 lintlang scan h7-improved.json --format json
Expected with 0.8.0: H7 is absent. Other diagnostics may still appear; this repair targets the rule above.
Both commands use advisory mode: a finding does not itself make the command fail. To fail CI on HIGH or CRITICAL findings, add --fail-on fail. --fail-on review also gates MEDIUM. See outputs and exit codes.
Detection details #
Released H7 detection contract and scope
Checks multiple system messages, a system message not at position zero, consecutive same-role messages, orphan tool results without preceding tool use, and messages missing a role. Coverage is limited to recognized message arrays, not every provider's protocol.