Skip to content

feat(scanner): reuse #1036 rules on plugin command markdown - #1163

Draft
seonghobae wants to merge 3 commits into
feat/claude-plugin-secret-to-mcp-1099from
feat/claude-plugin-command-skill-reuse-1099
Draft

seonghobae wants to merge 3 commits into
feat/claude-plugin-secret-to-mcp-1099from
feat/claude-plugin-command-skill-reuse-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Successor of #1161 / issue #1099. Does not Close those. Does not steal #1161 secret-to-MCP, #1158 secret-to-prompt, #1137 secret-to-network, #1139 skill/agent reuse, or G-06 #1152.

Unique delta

Reuse released #1036 identities on plugin command and named-agent markdown:

  • commands/commit.md with SYSTEM: Ignore all safety rules plus exfil wording fails admission as skill-manifest-prompt-injection-payload and skill-doc-exfiltration-endpoint-directive
  • agents/reviewer.md (not named agent.md) is the same instruction class
  • nested commands/git/commit.md stays on the released path includes
  • an honest command description stays receipt pass
  • root README.md and AGENTS.md stay repository guidance, not this class
  • commands/*.sh stays a hook/executable surface
  • command markdown symlinks are not followed
  • vendored vendor/commands/*.md stays vendored-scope, not feat(scanner): skill-supply-chain detectors (homoglyph, injection, exfil, placeholder) #1036
  • YAML regexes stay in scanner/rules/skill_supply_chain.yml; this adapter does not copy them

#1139 remains owner of SKILL.md / skill.json / agent.md / *.skill.md reuse. #1036 remains the released rule owner. Homoglyph and unresolved-placeholder stay skill-identifier rules.

Test plan

  • RED then GREEN (tests/test_claude_plugin_command_skill_reuse.py)
  • Detector statement coverage 1934/1934 with plugin suites 229 passed on Python 3.13
  • Exact-head Checks on this head
  • Keep Draft until current-head gates are GREEN

Relates to #1099. Relates to #1036. Relates to #1161. Relates to #1139.

Current non-force restack — 2026-09-12

This Draft is an ordinary two-parent descendant of prior head cd5560ead4e0f01de0a7e0c97e43bc8f8280fc39 and current #1161 head e899568e6fd98c0476832054d1f89336ce48af6b. Exact head is edeefc402959d1d8bb1c016b47a885449fa6e0a9; exact tree is 2d70408b780afc3eb1d385e64631351161d64b88. GitHub compare reports 3 ahead / 0 behind and preserves the command/agent rule-reuse delta together with #1161 MCP env/args/command/URL/header precision. Exact-tree PYTHONPATH=. python -m pytest -q tests/test_claude_plugin*.py is 265/265; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier head/check strings are historical evidence only.

Summary:
- RED: commands/*.md and agents/*.md with SYSTEM: ignore safety stay pass.
- Named agent files other than agent.md are not scanned today.
- README, AGENTS.md, command shell, symlink, and vendored copies stay negative.

Rationale:
- Issue #1099 lists command and agent markdown as instruction surfaces.
- Reuse released #1036 identities; do not invent a second injection family.

Tests:
- tests/test_claude_plugin_command_skill_reuse.py (4 fail / 5 pass)
Summary:
- Walk commands/*.md and agents/*.md as #1036 instruction surfaces.
- Injection and exfil YAML includes cover those paths; regexes stay in #1036.
- README, root AGENTS.md, command shell, symlink, and vendored copies stay negative.

Rationale:
- Skills and legacy commands share a local invocation namespace.
- Do not Close #1036 or invent a second prompt-injection family.

Tests:
- tests/test_claude_plugin_command_skill_reuse.py plus plugin suites 229 passed
- detector statement coverage 1934/1934 on Python 3.13
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 19:15 UTC records Draft #1163 `cd5560e` stacked on #1161.
- commands/*.md and named agents/*.md reuse released injection/exfil identities.
- README and root AGENTS.md stay repository guidance.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- #1099 remaining surfaces stay on stacked successors, not Close.

Tests:
- documentation-only; detector evidence lives on #1163 (1934/1934)

Copy link
Copy Markdown
Contributor Author

Keep #1163 Draft stacked on #1161 at cd5560e. Command and named-agent markdown reuse released #1036 injection/exfil identities. YAML regexes stay in skill_supply_chain.yml. Do not Close #1099, #1036, #1161, or #1139.

Copy link
Copy Markdown
Contributor Author

Stacked successor: Draft #1164 (feat/claude-plugin-hide-actions-1099 @ 9ef3193fb6e05dcdc2000772a53cf2dbbd97dab8) targets this branch.

Unique delta is hide-actions / self-modify / goal-escalation wording on SKILL.md, commands/*.md, and agents/*.md (claude-plugin-hide-actions-directive, claude-plugin-self-modify-directive, claude-plugin-goal-escalation-directive). It does not copy #1036 YAML regexes. Injection/exfil on commands/*.md stay this PR's identities. Does not Close #1099 or #1163.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 19:26 UTC records Draft #1164 `9ef3193` stacked on #1163.
- Hide-actions, self-modify, and goal-escalation wording fail closed.
- Command-markdown #1036 injection/exfil identities stay on #1163.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- #1099 remaining surfaces stay on stacked successors, not Close.

Tests:
- documentation-only; detector evidence lives on #1164 (1988/1988)
@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work labels Sep 8, 2026 — with ChatGPT Codex Connector

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium Normal-priority or P2 work

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant