Files
hermes-agent/tests
AIalliAI 42e6149451 fix(skills-guard): reduce false-positive CRITICAL/HIGH on benign skill patterns
Five targeted fixes for #60709 (reported by @mvanhorn):

1. ruby_env_secret: scope ENV[] to case-sensitive Ruby constant
   ((?-i:ENV)) — no longer matches Python env[key] dict access.

2. python_environ_get_secret: downgrade critical→medium — reading
   an API key via os.environ.get() is normal auth, not exfiltration.

3. python_os_environ: skip comment lines with ^(?!\s*#) — no longer
   flags os.environ references in docstrings or code comments.

4. deception_hide: downgrade critical→high + negative lookahead for
   UX guidance context (unless/except/until/confirm/diagnose/verify).

5. oversized_skill: downgrade high→low + raise cap 1MB→5MB — large
   skills are legitimate; structural size is informational only.

All 80 existing tests pass. 6 new verification tests added for each fix.
2026-08-28 03:46:21 -07:00
..