Commit a3dc420
danger: extend classifier and injection-scanner coverage (#43)
* danger: extend classifier and injection-scanner coverage
Close several gaps in the danger package's risk classification and
prompt-injection detection:
Classifier (classifier.go):
- File-mutating commands (cp/mv/tee/ln/install/touch/mkdir/chmod/rm/…)
that target a system path now classify as system_write instead of
short-circuiting to local_write (auto-allow). This closed a
sandbox-escape where an agent could write /etc/cron.d/, /usr/bin/,
/etc/profile.d/, etc. without approval.
- chmod that sets the setuid/setgid bit (u+s, g+s, 4755, 2755, 6755, …)
is system_write — privilege escalation regardless of path.
- Added disk/partition destroyers to the destructive set: wipefs,
blkdiscard, sgdisk, gdisk, cfdisk, sfdisk, mkswap, badblocks,
cryptsetup, zerofree, and more mkfs.* variants.
- shred is now recognised and handled like rm: local file -> local_write,
block device / catastrophic wipe target -> destructive.
- Machine power-control commands (shutdown, reboot, halt, poweroff,
init/telinit at a halt runlevel) classify as destructive with an
accurate label instead of falling through to unknown.
- Piping untrusted data into a non-shell interpreter (curl … | python,
… | perl, … | node, … | awk) is now code_execution, the non-shell
analogue of the existing … | bash detection.
Injection scanner (injection.go):
- Concealment instructions ("do not tell the user", "without informing",
"keep this secret", "silently exfiltrate").
- Chat control-token / role-marker injection (<|im_start|>, [INST],
<<SYS>>, <|system|>, forged <system> tags).
- Markdown-image and templated-request exfiltration beacons.
Updated the package doc and the chmod-root test to reflect the stronger
classifications, and added coverage_extension_test.go with positive and
false-negative/false-positive cases for every new behaviour.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DXDpyFBMT1baGHVoRnuQEP
* danger: raise test coverage to ~95% and document new behaviours
Add internal/danger/whitebox_coverage_test.go targeting the previously
untested or thinly-covered paths, raising package statement coverage from
85.3% to 94.9%:
- CheckOperation (was 0%): allow / deny / blocked-always-denies / prompt
via a fake Approver / approver-denies / nil-approver TTY fallback with
trusted-class short-circuit.
- TTYApprover.prompt interactive path via a file-backed TTY (TTYPath):
approve, deny, trust-session caching, friction full-word gate,
trust-disabled-for-destructive, read-error on missing newline, and the
non-interactive no-TTY fallback. os.Stderr is silenced during these.
- isOdekTrustAnchor / isSensitiveOdekPath / ClassifyPath home-relative
branches, driven with a synthetic $HOME so they no longer depend on the
runner's home (they were skipped under root).
- decodeANSIC escape decoding, parseBrowserIP inet_aton encodings,
hostnameIsInternal, isOctalMode, chmodSetsSUIDGID, commandName,
isAssignment, substValue, basenameFirstToken, isEnvironmentDump,
classifyResourceToken, rmRecursiveOrForce, isBlocked dd-split-of=,
extractSubstitutions, isInstall / isPackageManagerRun, hasArgAfter,
and the config action-resolution layers.
Docs: SECURITY.md "Danger classifier" and injection-scan sections now
describe the extended coverage (system-path writes, setuid chmod, disk
destroyers, shred, power-control, pipe-to-interpreter; and the new
concealment / control-token / exfiltration-beacon injection patterns).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DXDpyFBMT1baGHVoRnuQEP
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent 2e61578 commit a3dc420
6 files changed
Lines changed: 1136 additions & 9 deletions
File tree
- docs
- internal/danger
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
| |||
90 | 90 | | |
91 | 91 | | |
92 | 92 | | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
93 | 97 | | |
94 | 98 | | |
95 | 99 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
68 | 68 | | |
69 | 69 | | |
70 | 70 | | |
71 | | - | |
72 | | - | |
73 | | - | |
74 | | - | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
75 | 78 | | |
76 | 79 | | |
77 | 80 | | |
| |||
710 | 713 | | |
711 | 714 | | |
712 | 715 | | |
| 716 | + | |
| 717 | + | |
| 718 | + | |
| 719 | + | |
713 | 720 | | |
714 | 721 | | |
715 | 722 | | |
| |||
720 | 727 | | |
721 | 728 | | |
722 | 729 | | |
723 | | - | |
| 730 | + | |
| 731 | + | |
| 732 | + | |
| 733 | + | |
| 734 | + | |
| 735 | + | |
| 736 | + | |
| 737 | + | |
| 738 | + | |
| 739 | + | |
724 | 740 | | |
725 | 741 | | |
726 | 742 | | |
| |||
755 | 771 | | |
756 | 772 | | |
757 | 773 | | |
| 774 | + | |
| 775 | + | |
| 776 | + | |
| 777 | + | |
| 778 | + | |
| 779 | + | |
| 780 | + | |
| 781 | + | |
| 782 | + | |
| 783 | + | |
758 | 784 | | |
759 | 785 | | |
760 | 786 | | |
| |||
957 | 983 | | |
958 | 984 | | |
959 | 985 | | |
| 986 | + | |
| 987 | + | |
| 988 | + | |
| 989 | + | |
| 990 | + | |
| 991 | + | |
| 992 | + | |
| 993 | + | |
960 | 994 | | |
961 | 995 | | |
962 | 996 | | |
| |||
1762 | 1796 | | |
1763 | 1797 | | |
1764 | 1798 | | |
| 1799 | + | |
| 1800 | + | |
| 1801 | + | |
| 1802 | + | |
| 1803 | + | |
| 1804 | + | |
| 1805 | + | |
| 1806 | + | |
| 1807 | + | |
| 1808 | + | |
| 1809 | + | |
| 1810 | + | |
| 1811 | + | |
1765 | 1812 | | |
1766 | 1813 | | |
1767 | 1814 | | |
| |||
1775 | 1822 | | |
1776 | 1823 | | |
1777 | 1824 | | |
| 1825 | + | |
| 1826 | + | |
| 1827 | + | |
| 1828 | + | |
| 1829 | + | |
| 1830 | + | |
| 1831 | + | |
| 1832 | + | |
| 1833 | + | |
| 1834 | + | |
| 1835 | + | |
| 1836 | + | |
| 1837 | + | |
| 1838 | + | |
| 1839 | + | |
| 1840 | + | |
1778 | 1841 | | |
1779 | 1842 | | |
1780 | 1843 | | |
| |||
1810 | 1873 | | |
1811 | 1874 | | |
1812 | 1875 | | |
| 1876 | + | |
| 1877 | + | |
| 1878 | + | |
| 1879 | + | |
| 1880 | + | |
| 1881 | + | |
| 1882 | + | |
| 1883 | + | |
| 1884 | + | |
| 1885 | + | |
| 1886 | + | |
| 1887 | + | |
| 1888 | + | |
| 1889 | + | |
| 1890 | + | |
| 1891 | + | |
| 1892 | + | |
| 1893 | + | |
| 1894 | + | |
| 1895 | + | |
| 1896 | + | |
1813 | 1897 | | |
1814 | 1898 | | |
1815 | 1899 | | |
| |||
1827 | 1911 | | |
1828 | 1912 | | |
1829 | 1913 | | |
| 1914 | + | |
| 1915 | + | |
| 1916 | + | |
| 1917 | + | |
| 1918 | + | |
| 1919 | + | |
| 1920 | + | |
| 1921 | + | |
| 1922 | + | |
| 1923 | + | |
| 1924 | + | |
| 1925 | + | |
| 1926 | + | |
| 1927 | + | |
| 1928 | + | |
| 1929 | + | |
| 1930 | + | |
| 1931 | + | |
| 1932 | + | |
| 1933 | + | |
| 1934 | + | |
| 1935 | + | |
| 1936 | + | |
| 1937 | + | |
| 1938 | + | |
| 1939 | + | |
| 1940 | + | |
| 1941 | + | |
| 1942 | + | |
| 1943 | + | |
| 1944 | + | |
| 1945 | + | |
| 1946 | + | |
| 1947 | + | |
| 1948 | + | |
| 1949 | + | |
| 1950 | + | |
| 1951 | + | |
| 1952 | + | |
| 1953 | + | |
| 1954 | + | |
| 1955 | + | |
| 1956 | + | |
| 1957 | + | |
| 1958 | + | |
| 1959 | + | |
| 1960 | + | |
1830 | 1961 | | |
1831 | 1962 | | |
1832 | 1963 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
758 | 758 | | |
759 | 759 | | |
760 | 760 | | |
761 | | - | |
| 761 | + | |
| 762 | + | |
762 | 763 | | |
763 | | - | |
764 | | - | |
| 764 | + | |
| 765 | + | |
765 | 766 | | |
766 | 767 | | |
767 | 768 | | |
| |||
0 commit comments