fix(skills): catch sed flag variants; exempt content-contract prose in plugin code
Review-fold from the 3-angle simplify pass: - sed -Ei / -iE / --in-place now match the shell-critical tier (the bare '\s-i\b' token missed combined short flags and the GNU long form); read-only sed stays unflagged. Regression tests added. - agent_config_contract joins plugin_guard's CODE_EXEMPT_PATTERN_IDS: content-contract prose in plugin code files (docstrings/comments) is the same false-positive class the existing agent_config_mod exemption suppresses. Doc/config files keep the full pattern set. Efficiency reviewer: 1.24x full-scan cost (+3.4ms/file, install-time only), worst-case adversarial line 55us — no ReDoS exposure.
This commit is contained in:
@@ -127,6 +127,22 @@ class TestTruePositivesStillCaught:
|
||||
result = _scan(tmp_path, "sed -i 's/safe/malicious/' ./AGENTS.md")
|
||||
assert result.verdict == "dangerous"
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
"line",
|
||||
[
|
||||
"sed -Ei 's/a/b/' AGENTS.md", # combined flags, i last
|
||||
"sed -iE 's/a/b/' CLAUDE.md", # combined flags, i first
|
||||
"sed --in-place 's/a/b/' AGENTS.md", # GNU long form
|
||||
],
|
||||
)
|
||||
def test_sed_flag_variants_are_dangerous(self, tmp_path, line):
|
||||
result = _scan(tmp_path, line)
|
||||
assert result.verdict == "dangerous"
|
||||
|
||||
def test_sed_read_only_is_not_flagged(self, tmp_path):
|
||||
result = _scan(tmp_path, "sed -n '1,10p' AGENTS.md")
|
||||
assert result.verdict == "safe"
|
||||
|
||||
def test_tee_append_is_dangerous(self, tmp_path):
|
||||
result = _scan(tmp_path, "cat payload.txt | tee -a .cursorrules")
|
||||
assert result.verdict == "dangerous"
|
||||
|
||||
@@ -94,6 +94,7 @@ CODE_EXEMPT_PATTERN_IDS = {
|
||||
# Plugins legitimately write their own settings into config.yaml during
|
||||
# post_setup, and encode credentials (e.g. HTTP Basic auth) with base64.
|
||||
"agent_config_mod",
|
||||
"agent_config_contract",
|
||||
"encoded_exfil",
|
||||
}
|
||||
|
||||
|
||||
@@ -145,7 +145,7 @@ def _shell_write_re(file_alt: str) -> str:
|
||||
"""
|
||||
return (
|
||||
rf'(?:>>|[\w"\'`)\]]\s*>)\s*[~\w./-]*{file_alt}(?!\.?\w)'
|
||||
rf'|\bsed\b[^\n]*\s-i\b[^\n]*{file_alt}(?!\.?\w)'
|
||||
rf'|\bsed\b[^\n]*\s(?:-[A-Za-z]*i[A-Za-z]*|--in-place)\b[^\n]*{file_alt}(?!\.?\w)'
|
||||
rf'|\btee\s+(?:-a\s+)?[~\w./"\'-]*{file_alt}(?!\.?\w)'
|
||||
rf'|\b(?:cp|mv)\s+[^\s|;&]+\s+[^\n|;&]{{0,40}}?{file_alt}(?!\.?\w)'
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user