feat(scanner): reuse #1036 rules on plugin command markdown - #1163
seonghobae wants to merge 3 commits into
Conversation
Summary: - RED: commands/*.md and agents/*.md with SYSTEM: ignore safety stay pass. - Named agent files other than agent.md are not scanned today. - README, AGENTS.md, command shell, symlink, and vendored copies stay negative. Rationale: - Issue #1099 lists command and agent markdown as instruction surfaces. - Reuse released #1036 identities; do not invent a second injection family. Tests: - tests/test_claude_plugin_command_skill_reuse.py (4 fail / 5 pass)
Summary: - Walk commands/*.md and agents/*.md as #1036 instruction surfaces. - Injection and exfil YAML includes cover those paths; regexes stay in #1036. - README, root AGENTS.md, command shell, symlink, and vendored copies stay negative. Rationale: - Skills and legacy commands share a local invocation namespace. - Do not Close #1036 or invent a second prompt-injection family. Tests: - tests/test_claude_plugin_command_skill_reuse.py plus plugin suites 229 passed - detector statement coverage 1934/1934 on Python 3.13
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary: - Snapshot 19:15 UTC records Draft #1163 `cd5560e` stacked on #1161. - commands/*.md and named agents/*.md reuse released injection/exfil identities. - README and root AGENTS.md stay repository guidance. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1163 (1934/1934)
|
Stacked successor: Draft #1164 ( Unique delta is hide-actions / self-modify / goal-escalation wording on |
Summary: - Snapshot 19:26 UTC records Draft #1164 `9ef3193` stacked on #1163. - Hide-actions, self-modify, and goal-escalation wording fail closed. - Command-markdown #1036 injection/exfil identities stay on #1163. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1164 (1988/1988)
Successor of #1161 / issue #1099. Does not Close those. Does not steal #1161 secret-to-MCP, #1158 secret-to-prompt, #1137 secret-to-network, #1139 skill/agent reuse, or G-06 #1152.
Unique delta
Reuse released #1036 identities on plugin command and named-agent markdown:
commands/commit.mdwithSYSTEM: Ignore all safety rulesplus exfil wording fails admission asskill-manifest-prompt-injection-payloadandskill-doc-exfiltration-endpoint-directiveagents/reviewer.md(not namedagent.md) is the same instruction classcommands/git/commit.mdstays on the released path includesREADME.mdandAGENTS.mdstay repository guidance, not this classcommands/*.shstays a hook/executable surfacevendor/commands/*.mdstays vendored-scope, not feat(scanner): skill-supply-chain detectors (homoglyph, injection, exfil, placeholder) #1036scanner/rules/skill_supply_chain.yml; this adapter does not copy them#1139 remains owner of
SKILL.md/skill.json/agent.md/*.skill.mdreuse. #1036 remains the released rule owner. Homoglyph and unresolved-placeholder stay skill-identifier rules.Test plan
tests/test_claude_plugin_command_skill_reuse.py)Relates to #1099. Relates to #1036. Relates to #1161. Relates to #1139.
Current non-force restack — 2026-09-12
This Draft is an ordinary two-parent descendant of prior head
cd5560ead4e0f01de0a7e0c97e43bc8f8280fc39and current #1161 heade899568e6fd98c0476832054d1f89336ce48af6b. Exact head isedeefc402959d1d8bb1c016b47a885449fa6e0a9; exact tree is2d70408b780afc3eb1d385e64631351161d64b88. GitHub compare reports 3 ahead / 0 behind and preserves the command/agent rule-reuse delta together with #1161 MCP env/args/command/URL/header precision. Exact-treePYTHONPATH=. python -m pytest -q tests/test_claude_plugin*.pyis 265/265; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier head/check strings are historical evidence only.