fix(skills): catch sed flag variants; exempt content-contract prose in plugin code

Review-fold from the 3-angle simplify pass:

- sed -Ei / -iE / --in-place now match the shell-critical tier (the
  bare '\s-i\b' token missed combined short flags and the GNU long
  form); read-only sed stays unflagged. Regression tests added.
- agent_config_contract joins plugin_guard's CODE_EXEMPT_PATTERN_IDS:
  content-contract prose in plugin code files (docstrings/comments)
  is the same false-positive class the existing agent_config_mod
  exemption suppresses. Doc/config files keep the full pattern set.

Efficiency reviewer: 1.24x full-scan cost (+3.4ms/file, install-time
only), worst-case adversarial line 55us — no ReDoS exposure.
This commit is contained in:
kshitijk4poor
2026-08-28 13:26:55 +05:30
committed by Teknium
parent f2f61e0a45
commit 8c098e9e81
3 changed files with 18 additions and 1 deletions

View File

@@ -127,6 +127,22 @@ class TestTruePositivesStillCaught:
result = _scan(tmp_path, "sed -i 's/safe/malicious/' ./AGENTS.md")
assert result.verdict == "dangerous"
@pytest.mark.parametrize(
"line",
[
"sed -Ei 's/a/b/' AGENTS.md", # combined flags, i last
"sed -iE 's/a/b/' CLAUDE.md", # combined flags, i first
"sed --in-place 's/a/b/' AGENTS.md", # GNU long form
],
)
def test_sed_flag_variants_are_dangerous(self, tmp_path, line):
result = _scan(tmp_path, line)
assert result.verdict == "dangerous"
def test_sed_read_only_is_not_flagged(self, tmp_path):
result = _scan(tmp_path, "sed -n '1,10p' AGENTS.md")
assert result.verdict == "safe"
def test_tee_append_is_dangerous(self, tmp_path):
result = _scan(tmp_path, "cat payload.txt | tee -a .cursorrules")
assert result.verdict == "dangerous"

View File

@@ -94,6 +94,7 @@ CODE_EXEMPT_PATTERN_IDS = {
# Plugins legitimately write their own settings into config.yaml during
# post_setup, and encode credentials (e.g. HTTP Basic auth) with base64.
"agent_config_mod",
"agent_config_contract",
"encoded_exfil",
}

View File

@@ -145,7 +145,7 @@ def _shell_write_re(file_alt: str) -> str:
"""
return (
rf'(?:>>|[\w"\'`)\]]\s*>)\s*[~\w./-]*{file_alt}(?!\.?\w)'
rf'|\bsed\b[^\n]*\s-i\b[^\n]*{file_alt}(?!\.?\w)'
rf'|\bsed\b[^\n]*\s(?:-[A-Za-z]*i[A-Za-z]*|--in-place)\b[^\n]*{file_alt}(?!\.?\w)'
rf'|\btee\s+(?:-a\s+)?[~\w./"\'-]*{file_alt}(?!\.?\w)'
rf'|\b(?:cp|mv)\s+[^\s|;&]+\s+[^\n|;&]{{0,40}}?{file_alt}(?!\.?\w)'
)