security(agent): normalise text before injection scan (#89 follow-up) - #96
Merged
Merged
Conversation
scanInbound now also matches block patterns against a normalised copy of the input (NFKC, zero-width/bidi/format characters removed, Cyrillic/Greek look-alikes and curly quotes folded, lower-cased, runs of single letters joined by one repeated separator collapsed), so spaced, dotted, fullwidth and homoglyph variants of known phrases are blocked. Returned text is unchanged. New inbound patterns for the #89 framings: ignore_everything, obey_only_me, new_task_execute. Regression corpus with benign job-text negatives in tests/security-scan.test.ts. SECURITY.md and the module header state that the scanner is best-effort defence in depth, not an authorization boundary.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #89, closed as out of scope, with these hardening changes promised in the reply.
scanInboundalso matches block patterns against a normalised copy of the input: NFKC, format characters removed, Cyrillic/Greek look-alikes and curly quotes folded, lower-cased, and runs of single letters collapsed ("I.g.n.o.r.e", "i g n o r e"). The returned text is unchanged, and benign content is unaffected.ignore_everything,obey_only_me,new_task_execute.tests/security-scan.test.ts: the reporter payload, obfuscated variants, a documented role-play residual, and benign job-text negatives.security.tsheader state that the scanner is best-effort defence in depth, not an authorization boundary.Runner suite 54/54 and
tsc --noEmitpass locally.