fix(llm-security): hook coverage — pathguard on Edit, trifecta window, pipe-to-shell, provider keys (#9,#10,#12,#13,#11-doc)
#9 pathguard registered matcher Write only, so an Edit/MultiEdit to an existing protected file (settings.json, .env, .ssh, the hooks themselves) bypassed it entirely; matcher now Edit|Write (the script already reads only tool_input.file_path). #10 the primary trifecta detector's 20-entry window counted marker lines, so accumulated markers scrolled a real leg out (false negative); the window now counts tool-call entries. #13 pre-edit-secrets caught bare provider keys only inside a quoted label assignment; added anchored patterns for Anthropic sk-ant, OpenAI sk-proj, fine-grained github_pat_, Google AIza, and JWT eyJ (minimum-length guarded against prose false positives). #12 the remote-pipe-to-shell block required a shell immediately after the first pipe, so xargs/sudo/tee/env interposition evaded it and the comment falsely claimed xargs was caught; broadened to reach a shell through intermediate segments while leaving shell-OR fallbacks unblocked. #11 (doc only): knowledge/owasp-skills-top10.md claimed pre-bash-destructive blocks persistence commands — it does not; corrected to mark persistence detection as unimplemented/future (the detector itself is deferred to v8). Suite 2004/0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TcQyMTQfyrsAapaCMPxTtQ
This commit is contained in:
parent
21c6c2b534
commit
8a59d616fb
9 changed files with 337 additions and 6 deletions
|
|
@ -40,8 +40,13 @@ const BLOCK_RULES = [
|
|||
{
|
||||
name: 'Pipe-to-shell (curl|sh, wget|sh, curl|bash)',
|
||||
// Matches: curl ... | sh, curl ... | bash, wget ... | sh, etc.
|
||||
// Also catches variations with xargs sh, xargs bash
|
||||
pattern: /(?:curl|wget)\b[^|]*\|\s*(?:bash|sh|zsh|ksh|dash)\b/,
|
||||
// v7.8.3 #12: also catches a shell reached through interposition —
|
||||
// intermediate pipe stages (curl x | tee y | sh) and wrapper commands
|
||||
// with optional flags/assignments (xargs sh, sudo -E bash, env FOO=1 sh,
|
||||
// nohup bash, command sh — chains like `xargs sudo bash` included).
|
||||
// The intermediate-segment group requires a non-empty segment so `||`
|
||||
// (shell OR, e.g. `curl x || sh fallback.sh`) does not match.
|
||||
pattern: /(?:curl|wget)\b[^|]*\|(?:[^|]+\|)*\s*(?:(?:sudo|xargs|env|nohup|command)(?:\s+(?:-{1,2}[\w=/.-]+|\w+=\S*))*\s+)*(?:bash|sh|zsh|ksh|dash)\b/,
|
||||
description:
|
||||
'Piping remote content directly into a shell interpreter allows ' +
|
||||
'arbitrary remote code execution without inspection. Download the script first, ' +
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue