Skip to content

feat(scanner): reject plugin browser-profile stores - #1150

Draft
seonghobae wants to merge 3 commits into
feat/claude-plugin-hidden-executable-1099from
feat/claude-plugin-browser-profile-1099
Draft

seonghobae wants to merge 3 commits into
feat/claude-plugin-hidden-executable-1099from
feat/claude-plugin-browser-profile-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Current repair boundary — 2026-09-12

Successor of #1146 / issue #1099. Does not Close those. Does not steal G-06 #1133, #1145 eval, or #1146 hidden-executable unique delta. Docker sockets stay claude-plugin-docker-socket.

Unique delta

Fail closed on host browser profile stores (claude-plugin-browser-profile-access):

  • hook copy of Google/Chrome Cookies fails admission
  • Firefox cookies.sqlite, Chromium Login Data, and %LOCALAPPDATA%\Google\Chrome fail admission
  • a plugin.json command string that names Chrome Cookies fails admission
  • README documentation of those paths is not this finding
  • a bare Firefox product name stays browser_profile_access inventory, not this finding
  • /var/run/docker.sock stays claude-plugin-docker-socket
  • feat(scanner): reject hidden undeclared plugin executables #1146 hidden undeclared executables stay that class
  • snippets omit secrets and raw bidi

#1146 remains owner of hidden undeclared executable/config surfaces.

Test plan

  • RED then GREEN (tests/test_claude_plugin_browser_profile.py)
  • Detector statement coverage 1444/1444 with plugin suites on Python 3.13
  • Exact-head Checks on this head
  • Keep Draft until current-head gates are GREEN

Relates to #1099. Relates to #1146.

RED contract for host Chrome/Firefox profile stores on hook and
manifest surfaces. README text and a bare Firefox word stay
inventory. Relates to #1099.
Fail closed when a hook or manifest names a host Chrome, Chromium, or
Firefox profile store. Bare product names stay inventory. Relates to
#1099.
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Refresh the single-writer gap baseline from live exact-head evidence:
Draft #1150 on #1146, concurrent #1148 sentinel, and G-06 #1133
exact-head coverage SUCCESS. Relates to #1099.

Copy link
Copy Markdown
Contributor Author

Stacked successor Draft #1151 (feat/claude-plugin-deceptive-description-1099 @ 822ca12f1d8b55ae81f7feb882cc6f3073587256) adds claude-plugin-deceptive-description only. It does not Close #1099 or #1150. Browser-profile access stays this PR. Inventory remains evidence, not permission.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 15:28 UTC records Draft #1151 `822ca12` on #1150 and
  Draft #1152 `255cfd8` on #1133.
- `_scan_file` emits poll analyzer findings once per (rule_id, file).
- Deceptive read-only descriptions fail closed when inventory shows
  write or egress.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- G-06 emission waited on #1133 exact-head coverage SUCCESS.

Tests:
- documentation-only; evidence lives on #1151 (1560/1560) and #1152
  (417/417 analyzer statements)
seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 2026-09-07 23:23 UTC records Draft #1171 `9370a0d` stacked on #1170.
- Host cookie/token stores beyond browser profiles fail closed.
- Remaining leftover: deep directory recursion, Cosign/GPG, deployment-write.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- Do not Close #1099, #1170, #1150, or #1137.

Tests:
- documentation-only; detector evidence lives on #1171 (2505/2505)
@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work labels Sep 8, 2026 — with ChatGPT Codex Connector

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium Normal-priority or P2 work

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant