feat(dis): flag forbidden-param permission rules CC silently ignores
Extends the DIS scanner and its shared permission-rules lib with a third
documented Claude Code permission footgun. Verified verbatim against
code.claude.com/docs/en/permissions (fetched 2026-06-19).
CC's Tool(param:value) matching (2.1.178) is off-limits for a tool's own
canonicalizing field — CC ignores such a rule and emits a startup warning,
because e.g. Bash(command:rm *) is bypassable by a compound command. The
forbidden fields: command (Bash/PowerShell), file_path (Read/Edit/Write),
path (Grep/Glob), notebook_path (NotebookEdit), url (WebFetch).
- lib/permission-rules.mjs: new forbiddenParamRule(entry) returning
{ tool, key, hint } or null. Only the param:value form (colon present)
whose key equals the tool's forbidden field is flagged; Bash(npm:*),
WebFetch(domain:host), Agent(model:opus), and Bash(command) (no colon)
are left valid. FORBIDDEN_PARAMS map is the single source of truth.
- DIS: scans allow + deny + ask and splits severity by intent — deny/ask
hits are false security (medium: the block never applies), allow hits are
dead config (low: param:value matching is deny/ask-only). Two findings,
permissions-hygiene, CA-DIS-NNN.
- 11 new tests (7 lib, 4 DIS) + 1 fixture forbidden-param-permissions
(force-added past .gitignore .claude/). Suite 918 -> 929. Snapshot
unchanged (SC-5 byte-equal), contamination grep clean, gitleaks clean.
README/CLAUDE document the broadened DIS mandate; test badge synced.
self-audit: PASS, configGrade A 97, pluginGrade A 100, scanners 13.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ter3E2JSi1Khgmuf2kady8
This commit is contained in:
parent
b0bf8c5817
commit
d678765fad
7 changed files with 269 additions and 6 deletions
17
tests/fixtures/forbidden-param-permissions/.claude/settings.json
vendored
Normal file
17
tests/fixtures/forbidden-param-permissions/.claude/settings.json
vendored
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
{
|
||||
"permissions": {
|
||||
"allow": [
|
||||
"Read(file_path:/etc/passwd)",
|
||||
"Bash(npm:*)",
|
||||
"WebFetch(domain:good.com)"
|
||||
],
|
||||
"deny": [
|
||||
"Bash(command:rm *)",
|
||||
"Grep(path:/secrets)",
|
||||
"Agent(model:opus)"
|
||||
],
|
||||
"ask": [
|
||||
"WebFetch(url:http://evil.com)"
|
||||
]
|
||||
}
|
||||
}
|
||||
|
|
@ -6,6 +6,7 @@ import {
|
|||
dominates,
|
||||
rulesIntersect,
|
||||
isIneffectiveAllowGlob,
|
||||
forbiddenParamRule,
|
||||
} from '../../scanners/lib/permission-rules.mjs';
|
||||
|
||||
describe('permission-rules — parseRule', () => {
|
||||
|
|
@ -109,6 +110,55 @@ describe('permission-rules — isIneffectiveAllowGlob (CC silently skips these a
|
|||
});
|
||||
});
|
||||
|
||||
describe('permission-rules — forbiddenParamRule (CC ignores Tool(param:value) for the tool\'s own canonicalizing field)', () => {
|
||||
// CC: "Fields that a tool already matches with its own canonicalizing rules
|
||||
// are not matchable this way: command for Bash and PowerShell, file_path for
|
||||
// Read/Edit/Write, path for Grep/Glob, notebook_path for NotebookEdit, and
|
||||
// url for WebFetch. ... Claude Code ignores it and emits a startup warning."
|
||||
// (code.claude.com/docs/en/permissions — "Match by input parameter")
|
||||
|
||||
it('flags command: for Bash and PowerShell', () => {
|
||||
assert.equal(forbiddenParamRule('Bash(command:rm *)').key, 'command');
|
||||
assert.equal(forbiddenParamRule('PowerShell(command:Remove-Item *)').key, 'command');
|
||||
});
|
||||
|
||||
it('flags file_path: for Read/Edit/Write', () => {
|
||||
assert.equal(forbiddenParamRule('Read(file_path:/etc/passwd)').key, 'file_path');
|
||||
assert.equal(forbiddenParamRule('Edit(file_path:/src/x)').tool, 'Edit');
|
||||
assert.equal(forbiddenParamRule('Write(file_path:/src/x)').tool, 'Write');
|
||||
});
|
||||
|
||||
it('flags path: for Grep/Glob, notebook_path: for NotebookEdit, url: for WebFetch', () => {
|
||||
assert.equal(forbiddenParamRule('Grep(path:/secrets)').key, 'path');
|
||||
assert.equal(forbiddenParamRule('Glob(path:/secrets)').key, 'path');
|
||||
assert.equal(forbiddenParamRule('NotebookEdit(notebook_path:/nb.ipynb)').key, 'notebook_path');
|
||||
assert.equal(forbiddenParamRule('WebFetch(url:http://evil.com)').key, 'url');
|
||||
});
|
||||
|
||||
it('returns a tool-specific correct-syntax hint', () => {
|
||||
assert.match(forbiddenParamRule('Bash(command:rm *)').hint, /Bash\(/);
|
||||
assert.match(forbiddenParamRule('WebFetch(url:http://x)').hint, /domain:/);
|
||||
});
|
||||
|
||||
it('does NOT flag valid specifier/param syntax for the same tools', () => {
|
||||
assert.equal(forbiddenParamRule('Bash(npm:*)'), null); // npm: is a trailing-wildcard prefix, not command:
|
||||
assert.equal(forbiddenParamRule('WebFetch(domain:good.com)'), null); // domain: is the valid WebFetch syntax
|
||||
assert.equal(forbiddenParamRule('Read(./path)'), null); // gitignore-style path, no param:value
|
||||
assert.equal(forbiddenParamRule('Bash(command)'), null); // literal command-prefix, no colon
|
||||
});
|
||||
|
||||
it('does NOT flag param:value on tools that have no forbidden field', () => {
|
||||
assert.equal(forbiddenParamRule('Agent(model:opus)'), null);
|
||||
assert.equal(forbiddenParamRule('Bash(run_in_background:true)'), null);
|
||||
});
|
||||
|
||||
it('bare tools and non-strings → null', () => {
|
||||
assert.equal(forbiddenParamRule('Bash'), null);
|
||||
assert.equal(forbiddenParamRule('Bash(*)'), null);
|
||||
assert.equal(forbiddenParamRule(null), null);
|
||||
});
|
||||
});
|
||||
|
||||
describe('permission-rules — rulesIntersect (cross-scope conflict)', () => {
|
||||
it('exact same rule intersects', () => {
|
||||
assert.equal(rulesIntersect('Bash(npm run *)', 'Bash(npm run *)'), true);
|
||||
|
|
|
|||
|
|
@ -126,6 +126,50 @@ describe('DIS scanner — ineffective allow wildcards (CC skips unanchored tool-
|
|||
});
|
||||
});
|
||||
|
||||
describe('DIS scanner — forbidden-param rules CC silently ignores (Tool(param:value) on a canonicalizing field)', () => {
|
||||
// fixture forbidden-param-permissions/.claude/settings.json:
|
||||
// allow: Read(file_path:/etc/passwd), Bash(npm:*), WebFetch(domain:good.com)
|
||||
// deny: Bash(command:rm *), Grep(path:/secrets), Agent(model:opus)
|
||||
// ask: WebFetch(url:http://evil.com)
|
||||
// CC ignores command:/file_path:/path:/url: and emits a startup warning.
|
||||
// deny/ask hits = false security (medium); allow hits = dead config (low).
|
||||
// Bash(npm:*), WebFetch(domain:good.com), Agent(model:opus) are VALID — never flagged.
|
||||
|
||||
it('flags deny/ask forbidden-param rules with MEDIUM severity (false security)', async () => {
|
||||
const result = await runScanner('forbidden-param-permissions');
|
||||
const f = result.findings.find(x => /silently ignored.*deny\/ask|deny\/ask.*forbidden param/i.test(x.title || ''));
|
||||
assert.ok(f, `expected a medium forbidden-param finding; got: ${result.findings.map(x => x.title).join(' | ')}`);
|
||||
assert.equal(f.severity, 'medium', `expected medium, got ${f.severity}`);
|
||||
assert.match(f.id, /^CA-DIS-\d{3}$/);
|
||||
});
|
||||
|
||||
it('medium evidence cites the deny + ask forbidden entries, not the valid ones', async () => {
|
||||
const result = await runScanner('forbidden-param-permissions');
|
||||
const f = result.findings.find(x => /silently ignored.*deny\/ask|deny\/ask.*forbidden param/i.test(x.title || ''));
|
||||
assert.ok(f);
|
||||
assert.match(String(f.evidence || ''), /command:/); // Bash(command:rm *)
|
||||
assert.match(String(f.evidence || ''), /path:/); // Grep(path:/secrets)
|
||||
assert.match(String(f.evidence || ''), /url:/); // WebFetch(url:...) from ask
|
||||
assert.doesNotMatch(String(f.evidence || ''), /Agent/); // model:opus is valid
|
||||
});
|
||||
|
||||
it('flags allow forbidden-param rules with LOW severity (dead config)', async () => {
|
||||
const result = await runScanner('forbidden-param-permissions');
|
||||
const f = result.findings.find(x => /silently ignored.*allow|allow.*forbidden param/i.test(x.title || ''));
|
||||
assert.ok(f, `expected a low forbidden-param finding; got: ${result.findings.map(x => x.title).join(' | ')}`);
|
||||
assert.equal(f.severity, 'low', `expected low, got ${f.severity}`);
|
||||
assert.match(String(f.evidence || ''), /file_path:/); // Read(file_path:/etc/passwd)
|
||||
assert.doesNotMatch(String(f.evidence || ''), /npm:/); // Bash(npm:*) is valid
|
||||
assert.doesNotMatch(String(f.evidence || ''), /domain:/); // WebFetch(domain:...) is valid
|
||||
});
|
||||
|
||||
it('valid param/specifier syntax produces no forbidden-param finding', async () => {
|
||||
const result = await runScanner('param-qualified-permissions');
|
||||
const f = result.findings.find(x => /forbidden param|silently ignored/i.test(x.title || ''));
|
||||
assert.equal(f, undefined, `expected no forbidden-param finding for valid syntax; got: ${f?.title}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('DIS scanner — deny-all glob Tool(*) kills a bare allow (end-to-end)', () => {
|
||||
// settings.json: allow: ["Bash"], deny: ["Bash(*)"]
|
||||
// Bash(*) deny ≡ bare Bash deny → the bare Bash allow is dead config.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue