fix(llm-security): YAML/workflow parser divergence — block scalars + bare if: (#32,#33,#43)

#33 the frontmatter parser collected a block-scalar body (description: |) but did not skip it, so an indented name:/allowed_tools: inside the body re-matched as a top-level key and overrode the real values TRG-shadow and permission checks depend on; the parser now consumes block-scalar bodies as opaque content. #32 block-scalar headers carrying indentation/chomping indicators (|2, >-, |-2) were not recognized, so their bodies never reached the run: injection sink; now matched via a proper indicator/chomping regex.

#43 the B4 actor auth-bypass detector inspected only braced ${{ }} expressions, missing the canonical bare 'if: github.actor == ...' form (Synacktiv Dependabot-spoof false negative); bare if: expressions now emit a synthetic event the detector reads. Suite 2004/0.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

Claude-Session: https://claude.ai/code/session_01TcQyMTQfyrsAapaCMPxTtQ
This commit is contained in:
Kjell Tore Guttormsen 2026-07-18 10:35:56 +02:00
commit b224e18b42
8 changed files with 244 additions and 7 deletions

View file

@ -19,7 +19,9 @@ export function parseFrontmatter(content) {
const result = {};
// Parse simple key: value pairs
for (const line of block.split('\n')) {
const lines = block.split('\n');
for (let lineIdx = 0; lineIdx < lines.length; lineIdx++) {
const line = lines[lineIdx];
const trimmed = line.trim();
if (!trimmed || trimmed.startsWith('#')) continue;
@ -44,12 +46,13 @@ export function parseFrontmatter(content) {
// Handle multi-line description with |
if (value === '|' || value === '>') {
const descLines = [];
const lines = block.split('\n');
const lineIdx = lines.indexOf(line);
for (let i = lineIdx + 1; i < lines.length; i++) {
const dLine = lines[i];
if (/^\S/.test(dLine) && !dLine.startsWith(' ') && !dLine.startsWith('\t')) break;
descLines.push(dLine.replace(/^ /, ''));
// Consume the body line — block-scalar content is an opaque
// string, never re-parsed as key: value pairs (#33).
lineIdx = i;
}
value = descLines.join('\n').trim();
}