Harden the docs-fetcher gate and raw-read stage (follow-ups from #6481 security review)
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- bash, javascript, node.js
- Lĩnh vực
- security
Hướng nghiên cứu
Start by reading the security review context in PR #6481, then the four named entry points: lib/docs-fetcher-gate.mjs plus both plugins/*/hooks/hooks.json (item 1, fail-open), plugins/discovery/agents/docs-fetcher.md maxTurns (item 2), parseRaw in plugins/discovery/workflows/research-sweep.js and plugins/multi-agent/workflows/drift-audit.js (item 3), and lib/fetch-docs.sh (item 4). Each item states its own fix, so pick one, implement it, and verify by simulating the failure (missing node, mismatched byte length, curl args). "Done" means the gate denies instead of failing open and each stage rejects a bad raw slice.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
The ready-flip security review of #6481 (docs-fetcher agent, its PreToolUse Bash gate, and the raw-read stage in research-sweep and drift-audit) found four hardening items. None blocks the PR; each needs its own design or a behavior check, so they are filed here instead of folded into it.
1. The gate fails open when it cannot run (P3, structural)
plugins/discovery/hooks/hooks.json and plugins/multi-agent/hooks/hooks.json launch lib/docs-fetcher-gate.mjs with node. When node is missing, the hook times out (10 s), or the script crashes (for example a stdin error event, which main() does not handle), Claude Code treats the hook error as non-blocking, so the docs-fetcher's Bash is held only by the session's permission rules. Under auto mode or a broad Bash allow rule, a command injected by page text could run. prerequisites.json already says so for a missing node.
Options: deny on a stdin error when the agent_type matches; have the workflows skip the Fetch stage unless a node probe passed (/discovery:check, /multi-agent:check); or wrap the hook in a shell form that exits 2 when node is absent and stdin names the fetcher. Mention the fail-open in both README docs-fetcher rows.
2. The discovery docs-fetcher can make several fetches of attacker-chosen URLs (P4)
plugins/discovery/agents/docs-fetcher.md sets maxTurns: 4, and the discovery gate allows any public https host with a query string, any number of times. A fetched page could tell the fetcher to call docs-raw.sh again on https://attacker.example/?d=<data> and leak what is in its context. "Never retry" is an instruction only.
Options: lower maxTurns to the minimum one Bash call plus the structured return needs (check the turn count a structured-output return takes before lowering it); optionally deny query strings in the discovery gate, with rawable() matching.
3. Raw slices are a model's copy, and parseRaw checks only the header URL (P4, structural)
In plugins/discovery/workflows/research-sweep.js and plugins/multi-agent/workflows/drift-audit.js, parseRaw checks that the header URL equals the requested URL, but the body is up to 64 KB retyped by the fetcher model. Injected page text or a copy error can produce a wrong body under a valid header, and readers and skeptics prefer slices over their own WebFetch.
Fix: compare the header's bytes= with the body's UTF-8 length, and for kind=page the sha256= with a hash of the body when the runtime has one; mark the slice unread on a mismatch.
4. curl inherits ~/.curlrc on attacker-steered requests (P4)
lib/fetch-docs.sh (and synced copies) runs curl without -q, so a user's ~/.curlrc (insecure, proxy, user) applies to requests whose URL a web page chose, which can remove the TLS name check that currently limits redirect and DNS SSRF to trusted https hosts. Fix: pass -q as curl's first argument and re-sync the copies. Separately, decide whether off-origin redirects should be refused before they are followed.
Lower priority
plugins/discovery/hooks/webfetch-truncation.mjsputstool_input.urlverbatim and unbounded intoadditionalContext; echo a normalized, length-capped form instead.- Up to 40 attacker-sized pages per sweep can enter the shared docs cache and push the user's own entries out of the LRU; consider a per-run cache dir for generic hosts.
- Ngôn ngữ chính
- Shell
- Star
- 22
- Fork
- 2
- Merge trung bình
- 5 giờ 15 phút
- Pull request đã merge (30 ngày)
- 833
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6631 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
melodic-software/claude-code-plugins#6547 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
melodic-software/claude-code-plugins#6535 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)Đang mởgood first issue needs-triage priority: low
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6532 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
good first issue needs-triage priority: low
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
melodic-software/claude-code-plugins#6390 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của melodic-software/claude-code-plugins
Issue tương tự
-
`check_java_version()` fails when Java path contains spaces (Windows / Git Bash, `C:\Program Files`)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
aws-samples/appmod-blueprints#972 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: remote-ls --updates reports up-to-date OCI refs because it ignores deployed Alt-idCó thể đã có người làm @Joao-kouznetz đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
status:needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày