First consumer swap of step 4. ZERO_WIDTH_CHARS (5), the Unicode Tag range,
BIDI_CHARS (9) and HOMOGLYPH_MAP (28) stop being hardcoded constants in
unicode-scanner.mjs and string-utils.mjs and are built from the vendored
commons artifact codepoints/carriers.json by the new lib/codepoints.mjs.
Started here rather than at injection-patterns, which the plan ordered first:
that table is the one table that cannot be loaded verbatim (the
hybrid-xss:script-tag divergence is directional, and loading the lexicon as-is
would reverse the 90f576f recall fix). The codepoint tables were measured
byte-equal to the source constants BEFORE the swap - same members, same
values, same insertion order on HOMOGLYPH_MAP - so they load verbatim.
Proof the swap is content-preserving: the golden dump differs in exactly one
record, the sha256 of string-utils.mjs, which changes by construction when a
table leaves the file. All 83 regex records and the
table:string-utils:HOMOGLYPH_MAP digest are byte-identical, and
reference-run.json is unchanged at 61/61. patterns.json is re-blessed for the
file digest alone.
The gate is proven red-capable against the SUBJECT, both directions:
- dropping U+00AD from the vendored zero_width table fails the new
codepoints gate by name, twice;
- altering one homoglyph value reddens the golden table digest AND a
behavioural homoglyph test.
That second direction is a property the swap creates rather than preserves:
the golden gate now transitively pins the vendored commons data, where before
it pinned a source literal and a commons mutation was invisible to it.
NOT ported: commons carries cyrillic_confusables (13), and unicode-scanner.mjs
declares a set by that name - but nothing reads it. The homoglyph-mixing
detector tests isCyrillic(cp), the whole U+0400-U+04FF block. Loading it would
move dead data into the load path, so the dead const stays where it is and is
recorded instead. The recorded v8.x-B i/x drift between that set and the
lexicon class is therefore latent, not live. commons' private_use table has no
constant behind it here at all.
Graceful-empty is kept deliberately: codepoints.mjs is on string-utils'
import path and hooks import string-utils in fresh per-tool-call processes, so
a module-load throw would break the tool call rather than degrade the scan.
The loud half is the test, which asserts exact per-table counts through the
real default commons root - the same shape as the lexicon load-assertion.
Drive-by, unavoidable: the deleted JSDoc carried the "~25 entries" claim for a
28-entry table (v8.x-C). It needed a re-bless of the same file digest this
swap already forces, so it closes here at no extra cost.
Suite 2158 -> 2164, all green.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X7XEEFrAJsREqa9N4tpfm8
576 lines
19 KiB
JSON
576 lines
19 KiB
JSON
{
|
|
"artifact": "golden-pattern-dump",
|
|
"schema": 1,
|
|
"counts": {
|
|
"regex": 83,
|
|
"table": 7,
|
|
"file": 5
|
|
},
|
|
"records": [
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[0].pattern",
|
|
"source": "ignore\\s+(?:all\\s+)?previous",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[1].pattern",
|
|
"source": "forget\\s+your\\s+(?:instructions|rules|guidelines|directives)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[10].pattern",
|
|
"source": "<\\/system>",
|
|
"flags": ""
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[11].pattern",
|
|
"source": "^###\\s*Instructions\\s*:",
|
|
"flags": "m"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[12].pattern",
|
|
"source": "you\\s+are\\s+no\\s+longer",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[13].pattern",
|
|
"source": "you\\s+are\\s+now\\s+(?!able|going|ready|done|running|using|looking|in\\s|at\\s|on\\s)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[14].pattern",
|
|
"source": "your\\s+new\\s+role\\s+is",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[15].pattern",
|
|
"source": "your\\s+new\\s+primary\\s+directive",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[16].pattern",
|
|
"source": "pretend\\s+you\\s+are",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[17].pattern",
|
|
"source": "ignore\\s+your\\s+CLAUDE\\.md",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[18].pattern",
|
|
"source": "override\\s+your\\s+system\\s+prompt",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[19].pattern",
|
|
"source": "bypass\\s+your\\s+safety",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[2].pattern",
|
|
"source": "disregard\\s+your",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[20].pattern",
|
|
"source": "disable\\s+output\\s+filtering",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[3].pattern",
|
|
"source": "override\\s+your",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[4].pattern",
|
|
"source": "suspend\\s+all\\s+constraints",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[5].pattern",
|
|
"source": "all\\s+prior\\s+constraints",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[6].pattern",
|
|
"source": "^#+\\s*SYSTEM\\s*:",
|
|
"flags": "m"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[7].pattern",
|
|
"source": "^\\[INST\\]",
|
|
"flags": "m"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[8].pattern",
|
|
"source": "<\\|system\\|>",
|
|
"flags": ""
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:CRITICAL_PATTERNS[9].pattern",
|
|
"source": "<system>",
|
|
"flags": ""
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[0].pattern",
|
|
"source": "always\\s+prioritize\\s+user\\s+requests?\\s+over",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[1].pattern",
|
|
"source": "user\\s+intent\\s+takes?\\s+precedence\\s+over",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[10].pattern",
|
|
"source": "<[^>]{1,256}style\\s*=\\s*\"[^\"]{0,256}position\\s*:\\s*absolute[^\"]{0,256}-\\d{3,}px[^\"]{0,256}\"[^>]{0,256}>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[11].pattern",
|
|
"source": "<[^>]{1,256}style\\s*=\\s*\"[^\"]{0,256}font-size\\s*:\\s*0[^\"]{0,256}\"[^>]{0,256}>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[12].pattern",
|
|
"source": "<[^>]{1,256}style\\s*=\\s*\"[^\"]{0,256}opacity\\s*:\\s*0[^\"]{0,256}\"[^>]{0,256}>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[13].pattern",
|
|
"source": "<[^>]{1,256}style\\s*=\\s*\"[^\"]{0,256}(?:height|width)\\s*:\\s*0[^\"]{0,256}overflow\\s*:\\s*hidden[^\"]{0,256}\"[^>]{0,256}>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[14].pattern",
|
|
"source": "aria-label\\s*=\\s*\"[^\"]{0,256}(?:ignore|override|system|instruction|execute|exfiltrate)[^\"]{0,256}\"",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[15].pattern",
|
|
"source": "for\\s+educational\\s+purposes?\\s+only",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[16].pattern",
|
|
"source": "(?:this\\s+is\\s+)?a\\s+hypothetical\\s+scenario",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[17].pattern",
|
|
"source": "in\\s+a\\s+fictional\\s+(?:setting|scenario|world)\\s+where",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[18].pattern",
|
|
"source": "(?:this\\s+is\\s+)?a\\s+red[- ]?team(?:ing)?\\s+(?:exercise|simulation|test)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[19].pattern",
|
|
"source": "security\\s+audit\\s+simulation",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[2].pattern",
|
|
"source": "if\\s+CLAUDE\\.md\\s+conflicts",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[20].pattern",
|
|
"source": "pretend\\s+(?:this\\s+is|we\\s+are\\s+in)\\s+a\\s+(?:test|lab|sandbox|simulation)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[21].pattern",
|
|
"source": "as\\s+a\\s+thought\\s+experiment",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[22].pattern",
|
|
"source": "for\\s+(?:research|academic|scientific)\\s+purposes",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[23].pattern",
|
|
"source": "in\\s+an?\\s+(?:academic|research|educational)\\s+context",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[24].pattern",
|
|
"source": "(?:approve|accept|confirm)\\s+(?:this\\s+)?immediately",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[25].pattern",
|
|
"source": "no\\s+need\\s+to\\s+review",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[26].pattern",
|
|
"source": "(?:just|simply)\\s+(?:approve|accept|confirm)\\s+(?:it|this|everything)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[27].pattern",
|
|
"source": "(?:don'?t|do\\s+not)\\s+(?:bother\\s+)?(?:check|review|verify|inspect|read)(?:ing)?\\s+(?:this|the|it)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[28].pattern",
|
|
"source": "for\\s+brevity[\\s,]+(?:skipping|omitting|leaving\\s+out)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[29].pattern",
|
|
"source": "(?:too\\s+(?:long|verbose|detailed)\\s+to\\s+(?:show|display|list|include))",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[3].pattern",
|
|
"source": "skip\\s+confirmation\\s+for",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[30].pattern",
|
|
"source": "(?:details?\\s+(?:omitted|redacted|hidden|suppressed))",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[31].pattern",
|
|
"source": "(?:minor|trivial|small|cosmetic)\\s+(?:change|update|fix|adjustment)\\b[^.]{0,80}(?:delet|remov|drop|truncat|reset|destroy|\\bformat\\b|wipe)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[4].pattern",
|
|
"source": "your\\s+actual\\s+task\\s+is",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[5].pattern",
|
|
"source": "your\\s+real\\s+purpose\\s+is",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[6].pattern",
|
|
"source": "what\\s+you\\s+should\\s+actually\\s+do",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[7].pattern",
|
|
"source": "<!--\\s*(?:AGENT|AI|HIDDEN|ACTUAL\\s+TASK|REAL\\s+INSTRUCTION)\\s*:",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[8].pattern",
|
|
"source": "<[^>]{1,256}style\\s*=\\s*\"[^\"]{0,256}display\\s*:\\s*none[^\"]{0,256}\"[^>]{0,256}>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HIGH_PATTERNS[9].pattern",
|
|
"source": "<[^>]{1,256}style\\s*=\\s*\"[^\"]{0,256}visibility\\s*:\\s*hidden[^\"]{0,256}\"[^>]{0,256}>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[0].pattern",
|
|
"source": "(?:ignore|override|disregard|forget)[^.]{0,60}(?:SELECT\\s+\\*|DROP\\s+TABLE|UNION\\s+SELECT|DELETE\\s+FROM|INSERT\\s+INTO|UPDATE\\s+\\w+\\s+SET)(?:\\b|(?=\\s|$))",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[1].pattern",
|
|
"source": "(?:SELECT\\s+\\*|DROP\\s+TABLE|UNION\\s+SELECT|DELETE\\s+FROM)\\s[^;]{0,80}(?:ignore|override|disregard|bypass)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[2].pattern",
|
|
"source": "(?:inject|insert|embed|include)\\s+(?:this|the\\s+following)\\s+(?:into|in)\\s+(?:your|the)\\s+(?:output|response|reply|message|prompt|context)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[3].pattern",
|
|
"source": "(?:when|if)\\s+(?:the\\s+)?(?:user|human|operator)\\s+(?:asks?|requests?|queries)[^.]{0,60}(?:respond\\s+with|output|reply\\s+with|include)\\s+(?:this|the\\s+following)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[4].pattern",
|
|
"source": "<script\\b[^>]*>",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[5].pattern",
|
|
"source": "javascript\\s*:",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[6].pattern",
|
|
"source": "\\bon(?:error|load|click|mouseover|focus|blur)\\s*=",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:HYBRID_PATTERNS[7].pattern",
|
|
"source": "<iframe\\b[^>]*src\\s*=\\s*[\"'][^\"']*(?:javascript:|data:text\\/html)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[0].pattern",
|
|
"source": "[1!|l][gq9]n[o0]r[e3]\\s+(?:all\\s+)?pr[e3]v[i1!|l][o0]us",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[1].pattern",
|
|
"source": "f[o0]rg[e3]t\\s+y[o0]ur\\s+[i1!|l]nstruct[i1!|l][o0]ns",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[10].pattern",
|
|
"source": "ignor(?:ar?|e)\\s+(?:las?\\s+)?instrucciones?\\s+anteriores?",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[11].pattern",
|
|
"source": "ignorier(?:e|en)?\\s+(?:alle\\s+)?vorherigen?\\s+(?:Anweisungen|Instruktionen)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[12].pattern",
|
|
"source": "\\[\\/\\/\\]:\\s*#\\s*\\(.*(?:ignore|override|system|instruction|execute)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[13].pattern",
|
|
"source": "data:(?:text\\/html|application\\/javascript|text\\/javascript)[;,]",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[14].pattern",
|
|
"source": "\\[[^\\]]*(?:system|ignore|override|exfiltrate|execute)[^\\]]*\\]\\([^)]+\\)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[15].pattern",
|
|
"source": "(?:create|spawn|launch|start|run)\\s+(?:an?\\s+)?(?:new\\s+)?(?:sub-?agent|agent|task|worker)\\s+(?:that|to|which|with)\\s+(?:.*?\\s+)?(?:execute|run|delete|remove|send|post|exfiltrate|access|reads?\\s+(?:.*?\\s+)?(?:secret|credential|key|token|\\.env|\\.ssh))",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[16].pattern",
|
|
"source": "(?:delegate|dispatch)\\s+(?:to\\s+)?(?:an?\\s+)?(?:new\\s+)?(?:agent|sub-?agent|task)\\s+.*?(?:bypass|override|ignore|without\\s+(?:review|confirmation|approval))",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[17].pattern",
|
|
"source": "fetch\\s+(?:this|the|that)\\s+(?:URL|link|endpoint)\\s+and\\s+(?:execute|run|eval)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[18].pattern",
|
|
"source": "send\\s+(?:this|the|that|all)\\s+(?:data|content|output|result|information|file)\\s+to\\s+(?:https?:\\/\\/|ftp:\\/\\/|\\S+@\\S+)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[19].pattern",
|
|
"source": "read\\s+(?:the\\s+)?(?:contents?\\s+of\\s+)?(?:~\\/)?\\.(?:ssh|aws|gnupg|env)\\b",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[2].pattern",
|
|
"source": "d[i1!|l]sr[e3]g[a4@]rd\\s+y[o0]ur",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[20].pattern",
|
|
"source": "(?:extract|copy|dump|exfiltrate)\\s+(?:all\\s+)?(?:the\\s+)?(?:credentials?|secrets?|tokens?|keys?|passwords?)\\s+(?:and|then)\\s+(?:send|post|upload|transmit)",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[21].pattern",
|
|
"source": "(?:download|fetch|retrieve)\\s+(?:from\\s+)?\\S+\\s+(?:and|then)\\s+(?:execute|run|eval|pipe\\s+to\\s+(?:bash|sh|node|python))",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[3].pattern",
|
|
"source": "[o0]v[e3]rr[i1!|l]d[e3]\\s+y[o0]ur",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[4].pattern",
|
|
"source": "[a-zA-Z][\\u0430\\u0435\\u043E\\u0440\\u0441\\u0456\\u0443]|[\\u0430\\u0435\\u043E\\u0440\\u0441\\u0456\\u0443][a-zA-Z]",
|
|
"flags": ""
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[5].pattern",
|
|
"source": "\\w[\\u200B\\u200C\\u200D\\uFEFF]\\w",
|
|
"flags": ""
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[6].pattern",
|
|
"source": "(?:note|message|instruction)\\s+(?:to|for)\\s+(?:the\\s+)?(?:AI|assistant|model|LLM|Claude)\\b",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[7].pattern",
|
|
"source": "(?:dear|attention)\\s+(?:AI|assistant|model|LLM|Claude)\\b",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[8].pattern",
|
|
"source": "when\\s+(?:you|the\\s+AI|the\\s+assistant|Claude)\\s+(?:read|see|encounter|process)\\s+this",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "regex",
|
|
"key": "injection-patterns:MEDIUM_PATTERNS[9].pattern",
|
|
"source": "ignor(?:ez?|er?)\\s+(?:les?\\s+)?instructions?\\s+pr[e\\u00e9]c[e\\u00e9]dentes?",
|
|
"flags": "i"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "severity:OWASP_AGENTIC_MAP",
|
|
"entries": 16,
|
|
"digest": "sha256:1157c0746c7da7af13560f251aa6118d35e0e06b553c8097328208347d4d6d72"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "severity:OWASP_MAP",
|
|
"entries": 16,
|
|
"digest": "sha256:9908eeada4a5f3220b51bb313006edd3ea8598b1ac8bc3f4af4f3aa70fe3d25e"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "severity:OWASP_MCP_MAP",
|
|
"entries": 16,
|
|
"digest": "sha256:123403de05cb19d4beeb4d6444893f7d75e1336d6d0520863586c0730eaa26fa"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "severity:OWASP_SKILLS_MAP",
|
|
"entries": 16,
|
|
"digest": "sha256:cf84906d2c5e352124e63970a9b4833894ea77fddd4af98c41552e79a3f2cf7b"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "severity:SEVERITY",
|
|
"entries": 5,
|
|
"digest": "sha256:8194d777c31fd9ad85898647c0e65677abca6638506247c529d35e8b7d58c1e1"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "string-utils:HOMOGLYPH_MAP",
|
|
"entries": 28,
|
|
"digest": "sha256:ff9f334e5fbecd7472af84ee6c1824eaf872aed90570d14d19d1ac7b54bb86ed"
|
|
},
|
|
{
|
|
"kind": "table",
|
|
"key": "string-utils:TYPOSQUAT_SUSPICIOUS_TOKENS",
|
|
"entries": 19,
|
|
"digest": "sha256:ac076fe3292c32e622d62bfbeff407f81116a64989cb433db4b1eba89291bf56"
|
|
},
|
|
{
|
|
"kind": "file",
|
|
"key": "knowledge/attack-mutations.json",
|
|
"sha256": "40b99cd14fea4ca510937bdbdc4179a1d4007bcd5548849935408237fb2cd6f2"
|
|
},
|
|
{
|
|
"kind": "file",
|
|
"key": "knowledge/signatures.json",
|
|
"sha256": "0155368f194c51e01f48e5b253067282a9c083549401a2d374afc46bb89c66bc"
|
|
},
|
|
{
|
|
"kind": "file",
|
|
"key": "scanners/lib/injection-patterns.mjs",
|
|
"sha256": "9965d51aca86b4837181920064ce3af23e9baaf958979eef51ed2ee8f8f9d078"
|
|
},
|
|
{
|
|
"kind": "file",
|
|
"key": "scanners/lib/severity.mjs",
|
|
"sha256": "7c9a5b0ca9cd99e96af24960a7fb2efe9b1073346f7e1edd61dc7c717a4bac3d"
|
|
},
|
|
{
|
|
"kind": "file",
|
|
"key": "scanners/lib/string-utils.mjs",
|
|
"sha256": "1ff54b33453a3ddc9eb7dbe5e1c1590740d8cf7b3ebba2810e120345b658416c"
|
|
}
|
|
]
|
|
}
|