You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Browse filesBrowse the repository at this point in the historyBrowse files
authored
fix(analyzers): HIGH SC8 when skill ships __pycache__ or .pyc (#357)
* fix(analyzers): HIGH SC8 when skill ships __pycache__ or .pyc
Close the silent bytecode skip described in #356: discovery excludes
__pycache__ and treats .pyc as binary, so presence alone must fail the
score even before full disassembly exists.
Signed-off-by: Alex J Lennon <ajlennon@dynamicdevices.co.uk>
Co-authored-by: Cursor <cursoragent@cursor.com>
* fix(sc8): enforce fail-closed bytecode verdict
Signed-off-by: Narendran Raghavan <nraghavan@nvidia.com>
---------
Signed-off-by: Alex J Lennon <ajlennon@dynamicdevices.co.uk>
Signed-off-by: Narendran Raghavan <nraghavan@nvidia.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Narendran Raghavan <nraghavan@nvidia.com>
Copy file name to clipboardExpand all lines: src/skillspector/nodes/analyzers/pattern_defaults.py
+4Lines changed: 4 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -91,6 +91,7 @@ class PatternCategory(StrEnum):
91
91
"SC5": "Dependency appears abandoned or unmaintained. Abandoned packages no longer receive security patches, leaving known and future vulnerabilities unaddressed.",
92
92
"SC6": "Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.",
93
93
"SC7": "Code pulls a container image with signature or registry verification disabled (--disable-content-trust, DOCKER_CONTENT_TRUST=0, --insecure-registry). This accepts tampered or unverified images and is a container supply-chain risk.",
94
+
"SC8": "Skill ships Python bytecode (__pycache__/ or .pyc/.pyo). Discovery skips these paths, so malicious bytecode can score SAFE while decoy sources look clean.",
94
95
# Trigger Abuse
95
96
"TR1": "Skill uses overly broad trigger patterns that match common words or phrases, causing it to activate in unintended contexts and potentially shadow other skills.",
96
97
"TR2": "Skill trigger shadows a common built-in command or another skill's trigger, potentially intercepting requests meant for trusted functionality.",
@@ -181,6 +182,7 @@ class PatternCategory(StrEnum):
181
182
"SC5": PatternCategory.SUPPLY_CHAIN.value,
182
183
"SC6": PatternCategory.SUPPLY_CHAIN.value,
183
184
"SC7": PatternCategory.SUPPLY_CHAIN.value,
185
+
"SC8": PatternCategory.SUPPLY_CHAIN.value,
184
186
"TR1": PatternCategory.TRIGGER_ABUSE.value,
185
187
"TR2": PatternCategory.TRIGGER_ABUSE.value,
186
188
"TR3": PatternCategory.TRIGGER_ABUSE.value,
@@ -259,6 +261,7 @@ class PatternCategory(StrEnum):
259
261
"SC5": "Abandoned Dependency",
260
262
"SC6": "Typosquatting Dependency",
261
263
"SC7": "Untrusted Container Image",
264
+
"SC8": "Shipped Python Bytecode",
262
265
"TR1": "Overly Broad Trigger",
263
266
"TR2": "Shadow Command Trigger",
264
267
"TR3": "Keyword Baiting Trigger",
@@ -344,6 +347,7 @@ class PatternCategory(StrEnum):
344
347
"SC5": "Replace the abandoned dependency with an actively maintained alternative. Check the package's repository for last commit date and open issues.",
345
348
"SC6": "Verify the package name is correct and not a typosquatting variant. Compare against the official package name on PyPI or npm.",
346
349
"SC7": "Keep image signature verification (Docker Content Trust / cosign) and registry TLS enabled. Pull only signed images from trusted registries; never disable content-trust or use insecure registries in skill code.",
350
+
"SC8": "Do not ship __pycache__/ or .pyc/.pyo in skills. Delete bytecode before packaging; if presence is intentional for a lab fixture, quarantine it outside the skill install path.",
347
351
# Trigger Abuse
348
352
"TR1": "Use specific, narrow trigger patterns that match only the skill's intended use case. Avoid single-word or common-phrase triggers.",
349
353
"TR2": "Choose triggers that do not conflict with built-in commands or other skills. Prefix with a unique namespace if necessary.",
0 commit comments