Skip to content

security(agent): normalise text before injection scan (#89 follow-up) - #96

Merged
paulgnz merged 1 commit into
mainfrom
security/scanner-normalise-89
Sep 28, 2026
Merged

paulgnz merged 1 commit into
mainfrom
security/scanner-normalise-89

Conversation

@paulgnz

@paulgnz paulgnz commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

Follow-up to #89, closed as out of scope, with these hardening changes promised in the reply.

  • scanInbound also matches block patterns against a normalised copy of the input: NFKC, format characters removed, Cyrillic/Greek look-alikes and curly quotes folded, lower-cased, and runs of single letters collapsed ("I.g.n.o.r.e", "i g n o r e"). The returned text is unchanged, and benign content is unaffected.
  • New inbound patterns for the scanInbound silently allows 13/16 prompt-injection payloads — no flag, no block, text delivered verbatim to the agent LLM #89 framings: ignore_everything, obey_only_me, new_task_execute.
  • tests/security-scan.test.ts: the reporter payload, obfuscated variants, a documented role-play residual, and benign job-text negatives.
  • SECURITY.md and the security.ts header state that the scanner is best-effort defence in depth, not an authorization boundary.

Runner suite 54/54 and tsc --noEmit pass locally.

scanInbound now also matches block patterns against a normalised copy of the
input (NFKC, zero-width/bidi/format characters removed, Cyrillic/Greek
look-alikes and curly quotes folded, lower-cased, runs of single letters
joined by one repeated separator collapsed), so spaced, dotted, fullwidth and
homoglyph variants of known phrases are blocked. Returned text is unchanged.

New inbound patterns for the #89 framings: ignore_everything, obey_only_me,
new_task_execute. Regression corpus with benign job-text negatives in
tests/security-scan.test.ts. SECURITY.md and the module header state that the
scanner is best-effort defence in depth, not an authorization boundary.
@paulgnz
paulgnz merged commit ad86168 into main Sep 28, 2026
7 checks passed
@paulgnz
paulgnz deleted the security/scanner-normalise-89 branch September 28, 2026 00:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant