test(llm-security): store the malicious-skill demo encoded, materialize at run time
v8.1.0 S2. examples/malicious-skill-demo/evil-project-health/ (7 files, 30 Unicode Tag chars, a base64 exfil blob) is now one archive, evil-project-health.archive.json: rot13 text, every codepoint above U+007E stored as a number, sha256 of each retired file recorded. materialize.mjs writes it to a temp dir (CLI prints the path); run-demo.sh materializes and deletes it itself; the six scanner tests that scanned the tree use it. payload-trees.test.mjs asserts byte identity (mutation-checked). av-surface: b 8->6, c 1->0, d 2->1. Demo 13/13 before and after. All scanners report identical findings except git-forensics: it used to scan this repository's own history (21 findings, none about the demo) and now reports skipped in a temp dir, which git.test.mjs already accepts. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
daa12b3bbb
commit
b3c47330e1
18 changed files with 639 additions and 409 deletions
|
|
@ -10,15 +10,18 @@
|
|||
// - Correct structure of the scanner result envelope
|
||||
// - All findings (if any) have the DS-GIT- prefix
|
||||
|
||||
import { describe, it, beforeEach } from 'node:test';
|
||||
import { describe, it, beforeEach, after } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import { resolve } from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { resetCounter } from '../../scanners/lib/output.mjs';
|
||||
import { scan } from '../../scanners/git-forensics.mjs';
|
||||
import { materializeArchive } from '../../examples/malicious-skill-demo/materialize.mjs';
|
||||
|
||||
const __dirname = fileURLToPath(new URL('.', import.meta.url));
|
||||
const FIXTURE = resolve(__dirname, '../../examples/malicious-skill-demo/evil-project-health');
|
||||
// v8.1.0 (S2): the demo tree is stored encoded and materialized at test time.
|
||||
const { dir: FIXTURE, cleanup } = materializeArchive();
|
||||
after(cleanup);
|
||||
// The plugin root — may or may not be a standalone git repo
|
||||
const PLUGIN_ROOT = resolve(__dirname, '../..');
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue