feat(scanner): reject plugin setuid and world-writable modes - #1165
seonghobae wants to merge 3 commits into
Conversation
Summary: - RED: setuid/setgid and world-writable hooks stay receipt pass. - 0755 declared hooks, world-writable LICENSE, vendored copies, and symlink hooks stay negative. Rationale: - Issue #1099 lists arbitrary host-filesystem authority as admission fail. - chmod +x of a download stays the unsigned-download class. Tests: - tests/test_claude_plugin_insecure_file_mode.py (5 fail / 4 pass)
Summary: - Setuid/setgid hook and executable files fail as claude-plugin-setuid-executable. - World-writable hook and executable files fail as claude-plugin-world-writable-executable. - 0755 declared hooks, LICENSE, Git metadata, .mcp.json, and vendored copies stay negative. Rationale: - Host-filesystem privilege bits are admission evidence, not inventory. - chmod +x of a download stays the unsigned-download class. Tests: - tests/test_claude_plugin_insecure_file_mode.py plus plugin suites 251 passed - detector statement coverage 2035/2035 on Python 3.13
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary: - Snapshot 20:04 UTC records Draft #1165 `5790559` stacked on #1164. - Setuid/setgid and world-writable executable/hook modes fail closed. - #1068 live head `2379b37` is another empty Strix retrigger. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1165 (2035/2035)
|
Stacked successor: #1166 ( |
Summary: - Snapshot 20:26 UTC records Draft #1166 `90cd031` stacked on #1165. - Archive ratio >100 or nesting deeper than 1 fail closed. - Bomb members are not extracted; zip-slip stays #1135. Rationale: - #999 is the single writer of the product-technical gap baseline. - #1099 remaining surfaces stay on stacked successors, not Close. Tests: - documentation-only; detector evidence lives on #1166 (2201/2201)
Summary: - Snapshot 21:03 UTC records Draft #1166 `0ef0f7d` stacked on #1165. - Aggregate in-root uncompressed bytes fail closed before extract. - Ratio/depth bombs and zip-slip stay their existing classes. Rationale: - #999 is the single writer of the product-technical gap baseline. - RED `e1b3f39` on the canonical writer is not Close; it is GREEN. Tests: - documentation-only; detector evidence lives on #1166 (2238/2238)
Successor of #1164 / issue #1099. Does not Close those. Does not steal #1164 hide-actions/self-modify/goal-escalation, #1163 command-markdown #1036 reuse, or G-06 #1152.
Unique delta
Fail closed when a materialized plugin executable or hook has privilege or tamper modes:
hooks/session.shwith setuid (04755) →claude-plugin-setuid-executablescripts/run.shwith setgid (02755) is the same class0777) →claude-plugin-world-writable-executablescripts/runis this classinstall.pyoutside hook dirs is this class0755hooks stay receipt pass.mcp.json, vendored copies, and symlink hooks are not this classchmod +xof a downloaded payload stays unsigned-downloadSnippets are path labels. Oversized byte/file caps stay
claude-plugin-oversized-package.Test plan
tests/test_claude_plugin_insecure_file_mode.py)Relates to #1099. Relates to #1164.
Current non-force restack — 2026-09-12
This Draft is an ordinary two-parent descendant of prior head
57905590731b5fb5cb7bf8b5e9bed43241bd5605and current #1164 headfe1a2ec5749ad7bba6d1189efb970b73785b4bca. Exact head is4714d13ec38d85a4c2f34e9518064b70127753c8; exact tree is5165fd5b7550a6f5a929cd8b86f8d1ef3e637222. GitHub compare reports 3 ahead / 0 behind and preserves setuid/setgid/world-writable mode detection with all current directive, command-rule, and MCP precision deltas. Exact-tree Claude-plugin tests are 287/287; detector/CLI compile and diff checks pass. No hosted workflow or qualifying independent current-head review exists, so this custom-base PR remains Draft. Earlier head/check strings are historical evidence only.