Skip to content

feat(scanner): reject plugin setuid and world-writable modes - #1165

Draft
seonghobae wants to merge 3 commits into
feat/claude-plugin-hide-actions-1099from
feat/claude-plugin-insecure-file-mode-1099
Draft

seonghobae wants to merge 3 commits into
feat/claude-plugin-hide-actions-1099from
feat/claude-plugin-insecure-file-mode-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Successor of #1164 / issue #1099. Does not Close those. Does not steal #1164 hide-actions/self-modify/goal-escalation, #1163 command-markdown #1036 reuse, or G-06 #1152.

Unique delta

Fail closed when a materialized plugin executable or hook has privilege or tamper modes:

  • declared hooks/session.sh with setuid (04755) → claude-plugin-setuid-executable
  • scripts/run.sh with setgid (02755) is the same class
  • world-writable declared hook (0777) → claude-plugin-world-writable-executable
  • world-writable unsuffixed scripts/run is this class
  • setuid install.py outside hook dirs is this class
  • declared 0755 hooks stay receipt pass
  • world-writable LICENSE, Git metadata, .mcp.json, vendored copies, and symlink hooks are not this class
  • chmod +x of a downloaded payload stays unsigned-download

Snippets are path labels. Oversized byte/file caps stay claude-plugin-oversized-package.

Test plan

  • RED then GREEN (tests/test_claude_plugin_insecure_file_mode.py)
  • Detector statement coverage 2035/2035 with plugin suites 251 passed on Python 3.13
  • Exact-head Checks on this head
  • Keep Draft until current-head gates are GREEN

Relates to #1099. Relates to #1164.

Current non-force restack — 2026-09-12

This Draft is an ordinary two-parent descendant of prior head 57905590731b5fb5cb7bf8b5e9bed43241bd5605 and current #1164 head fe1a2ec5749ad7bba6d1189efb970b73785b4bca. Exact head is 4714d13ec38d85a4c2f34e9518064b70127753c8; exact tree is 5165fd5b7550a6f5a929cd8b86f8d1ef3e637222. GitHub compare reports 3 ahead / 0 behind and preserves setuid/setgid/world-writable mode detection with all current directive, command-rule, and MCP precision deltas. Exact-tree Claude-plugin tests are 287/287; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier head/check strings are historical evidence only.

Summary:
- RED: setuid/setgid and world-writable hooks stay receipt pass.
- 0755 declared hooks, world-writable LICENSE, vendored copies, and
  symlink hooks stay negative.

Rationale:
- Issue #1099 lists arbitrary host-filesystem authority as admission fail.
- chmod +x of a download stays the unsigned-download class.

Tests:
- tests/test_claude_plugin_insecure_file_mode.py (5 fail / 4 pass)
Summary:
- Setuid/setgid hook and executable files fail as claude-plugin-setuid-executable.
- World-writable hook and executable files fail as claude-plugin-world-writable-executable.
- 0755 declared hooks, LICENSE, Git metadata, .mcp.json, and vendored copies stay negative.

Rationale:
- Host-filesystem privilege bits are admission evidence, not inventory.
- chmod +x of a download stays the unsigned-download class.

Tests:
- tests/test_claude_plugin_insecure_file_mode.py plus plugin suites 251 passed
- detector statement coverage 2035/2035 on Python 3.13
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-project-automation github-project-automation Bot moved this to Backlog in Security Sep 7, 2026
seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 20:04 UTC records Draft #1165 `5790559` stacked on #1164.
- Setuid/setgid and world-writable executable/hook modes fail closed.
- #1068 live head `2379b37` is another empty Strix retrigger.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- #1099 remaining surfaces stay on stacked successors, not Close.

Tests:
- documentation-only; detector evidence lives on #1165 (2035/2035)

Copy link
Copy Markdown
Contributor Author

Keep #1165 Draft stacked on #1164 at 5790559. Setuid/setgid and world-writable executable/hook modes fail closed. Do not Close #1099 or #1164.

Copy link
Copy Markdown
Contributor Author

Stacked successor: #1166 (feat/claude-plugin-decompression-bomb-1099 @ 90cd031da4feb6538f0853883cd8dbbafd752c1d) adds claude-plugin-decompression-bomb for zip/tar members whose uncompressed/compressed ratio exceeds 100 or whose nested archive depth exceeds 1. Bomb payloads are not extracted. This does not Close #1099 or #1165. Oversized byte/file caps stay claude-plugin-oversized-package. Archive path traversal stays #1135. Setuid/world-writable modes stay this PR.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 20:26 UTC records Draft #1166 `90cd031` stacked on #1165.
- Archive ratio >100 or nesting deeper than 1 fail closed.
- Bomb members are not extracted; zip-slip stays #1135.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- #1099 remaining surfaces stay on stacked successors, not Close.

Tests:
- documentation-only; detector evidence lives on #1166 (2201/2201)
seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 21:03 UTC records Draft #1166 `0ef0f7d` stacked on #1165.
- Aggregate in-root uncompressed bytes fail closed before extract.
- Ratio/depth bombs and zip-slip stay their existing classes.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- RED `e1b3f39` on the canonical writer is not Close; it is GREEN.

Tests:
- documentation-only; detector evidence lives on #1166 (2238/2238)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: high

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant