Skip to content

fix(malicious-scan): allow zero-width spaces in PR descriptions - #16

Merged
EmilyRagan merged 1 commit into
mainfrom
allow-zero-width-space-in-pr-description
Oct 1, 2026
Merged

EmilyRagan merged 1 commit into
mainfrom
allow-zero-width-space-in-pr-description

Conversation

@EmilyRagan

@EmilyRagan EmilyRagan commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Dependabot PR descriptions contain @<U+200B>name so people aren't pinged, and the scan blocked every dependency bump on the zero-width rule (e.g. OpenC3/cosmos run 36786709915: 29 blocking findings, all U+200B in the description of cosmos#3968).
  • metadata_scan now removes U+200B from the PR description before the rules run. It is removed rather than exempted, so it cannot split a phrase such as "ignore previous instructions" to slip past the prompt-injection rules.
  • Other zero-width characters in the description, and U+200B in the title, commit messages or code, still block.

Test plan

  • New test_zero_width_space_is_allowed_in_pr_description; all 86 tests in tests/test_ai_review.py pass
  • Patched metadata_scan on the real cosmos#3968 title and description: 0 findings
  • After merge, re-run the failed cosmos scans

🤖 Generated with Claude Code

Dependabot writes @<U+200B>name in PR descriptions to avoid mentions, which
blocked every dependency bump on the zero-width rule. Remove U+200B from the
description before the rules run, so it cannot split a phrase to slip past
the prompt-injection rules. Other zero-width characters, and U+200B in the
title, commit messages or code, still block.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@EmilyRagan
EmilyRagan requested a review from ryanmelt October 1, 2026 14:52
@EmilyRagan EmilyRagan self-assigned this Oct 1, 2026
@EmilyRagan
EmilyRagan requested a review from ryan-pratt October 1, 2026 14:52
@EmilyRagan
EmilyRagan merged commit 63d4682 into main Oct 1, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants