feat(active-content,okf): bound the last two detection surfaces
`scan_active_content` called directly and `okf.link_graph` were the two surfaces still reading attacker-supplied text with no cap — the first reached by an adapter that wants the active-content classes alone, the second running a `findall` over every body in a bundle. Both are detection-shaped, so they truncate and flag rather than raise the way the transform surfaces do: what a detector shortens is its own coverage, not the caller's content. Truncation is only honest if it is visible, so neither goes quiet: the scanner emits `active:oversize-input` (LLM10), and `link_graph` records `(from_id, body_length)` in `LinkGraphResult.truncated` — the field that lets a caller tell "no links past here" from "no links read past here". Reached through `scan_output`, the text is already under that surface's cap and `max_scan_chars` is now passed down, so the flag is raised once, there.
This commit is contained in:
parent
0bf07295c2
commit
b90233481a
6 changed files with 111 additions and 22 deletions
|
|
@ -336,6 +336,7 @@ def scan_output(
|
|||
# 6. Active-content constructs with an external target (the EchoLeak class,
|
||||
# OWASP LLM05) — reported here so disposition sees them; defanging stays
|
||||
# neutralize's separate, opt-in job.
|
||||
report.extend(scan_active_content(scan_text, source).findings)
|
||||
# scan_text is already <= cap, so no second oversize finding is emitted.
|
||||
report.extend(scan_active_content(scan_text, source, max_scan_chars).findings)
|
||||
|
||||
return report
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue