feat(scanner): reject plugin hide-actions and goal-escalation wording - #1164
Draft
seonghobae wants to merge 3 commits into
Draft
seonghobae wants to merge 3 commits into
seonghobae wants to merge 3 commits into
Conversation
Summary: - RED: SKILL.md hide-your-actions, rewrite-system-prompt, and expand-goal stay pass. - Honest tool-call reporting, README, vendored copies, and #1163 exfil stay negative. Rationale: - Issue #1099 lists command/agent/skill text that hides actions, self-modifies, or escalates goals. - Do not copy #1036/#1163 injection or exfil YAML regexes. Tests: - tests/test_claude_plugin_hide_actions.py (6 fail / 4 pass)
Summary: - Fail closed when SKILL.md, commands/*.md, or agents/*.md hides tool use, rewrites the system prompt, or expands the declared goal. - One instruction-override family; #1036 injection/exfil YAML stays uncopied. - README, honest tool-call reporting, and vendored copies stay negative. Rationale: - Issue #1099 lists hide-actions, self-modify, and goal-escalation as instruction text. - Do not Close #1099 or steal #1163 command-markdown identities. Tests: - tests/test_claude_plugin_hide_actions.py plus plugin suites 239 passed - detector statement coverage 1988/1988 on Python 3.13
2 of 4 tasks
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 19:26 UTC records Draft #1164 `9ef3193` stacked on #1163. - Hide-actions, self-modify, and goal-escalation wording fail closed. - Command-markdown #1036 injection/exfil identities stay on #1163. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1164 (1988/1988)
This was referenced Sep 7, 2026
seonghobae
added a commit
that referenced
this pull request
Sep 7, 2026
Summary: - Snapshot 20:04 UTC records Draft #1165 `5790559` stacked on #1164. - Setuid/setgid and world-writable executable/hook modes fail closed. - #1068 live head `2379b37` is another empty Strix retrigger. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1165 (2035/2035)
Contributor
Author
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Successor of #1163 / issue #1099. Does not Close those. Does not copy #1036 regexes. Injection/exfil on
commands/*.mdstay #1163 identities (skill-manifest-prompt-injection-payload,skill-doc-exfiltration-endpoint-directive). Does not steal #1161 secret-to-MCP, #1158 secret-to-prompt, or G-06 #1152.Unique delta
Fail closed when
SKILL.md,commands/*.md, oragents/*.mdinstructs hiding tool use, self-modifying the prompt/policy, or escalating the declared goal. One instruction-to-the-model family:SKILL.md"do not tell the user you are calling tools / hide your actions" →claude-plugin-hide-actions-directiveclaude-plugin-self-modify-directiveclaude-plugin-goal-escalation-directivecommands/*.mdstaysskill-doc-exfiltration-endpoint-directiveSnippets omit secrets and bidi. Command-markdown #1036 reuse stays #1163.
Test plan
tests/test_claude_plugin_hide_actions.py)Relates to #1099. Relates to #1163. Relates to #1036.
Current non-force restack — 2026-09-12
This Draft is an ordinary two-parent descendant of prior head
9ef3193fb6e05dcdc2000772a53cf2dbbd97dab8and current #1163 headedeefc402959d1d8bb1c016b47a885449fa6e0a9. Exact head isfe1a2ec5749ad7bba6d1189efb970b73785b4bca; exact tree is59e1938524ccfee5dd54524acdb23d6916f0a2f2. GitHub compare reports 3 ahead / 0 behind and preserves hide-actions/self-modify/goal-escalation detection together with the entire current command-rule and MCP precision lineage. Exact-tree Claude-plugin tests are 275/275; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier head/check strings are historical evidence only.