You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/skillspector/nodes/analyzers/pattern_defaults.py
+4Lines changed: 4 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -82,6 +82,7 @@ class PatternCategory(StrEnum):
82
82
"TM1": "Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).",
83
83
"TM2": "Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.",
84
84
"TM3": "Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.",
85
+
"TM4": "Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.",
85
86
# Rogue Agent (B.1.11)
86
87
"RA1": "Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.",
87
88
"RA2": "Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.",
@@ -172,6 +173,7 @@ class PatternCategory(StrEnum):
172
173
"TM1": PatternCategory.TOOL_MISUSE.value,
173
174
"TM2": PatternCategory.TOOL_MISUSE.value,
174
175
"TM3": PatternCategory.TOOL_MISUSE.value,
176
+
"TM4": PatternCategory.TOOL_MISUSE.value,
175
177
"RA1": PatternCategory.ROGUE_AGENT.value,
176
178
"RA2": PatternCategory.ROGUE_AGENT.value,
177
179
"SC4": PatternCategory.SUPPLY_CHAIN.value,
@@ -248,6 +250,7 @@ class PatternCategory(StrEnum):
248
250
"TM1": "Tool Parameter Abuse",
249
251
"TM2": "Chaining Abuse",
250
252
"TM3": "Unsafe Defaults",
253
+
"TM4": "Privileged Kubernetes Workload",
251
254
"RA1": "Self-Modification",
252
255
"RA2": "Session Persistence",
253
256
"SC4": "Known Vulnerable Dependency",
@@ -329,6 +332,7 @@ class PatternCategory(StrEnum):
329
332
"TM1": "Validate all tool parameters against an allowlist. Reject dangerous parameter values (shell=True, --force, -rf /) and use safe defaults.",
330
333
"TM2": "Limit tool chaining depth and validate the output of each tool before passing it to the next. Require explicit user approval for multi-step chains.",
331
334
"TM3": "Override unsafe defaults with secure settings (verify=True, auth required, restrictive permissions). Review and harden all tool configurations.",
335
+
"TM4": "Remove privileged, hostPath, and host-namespace settings from workloads. Use a least-privilege securityContext, drop capabilities, and avoid mounting the host filesystem.",
332
336
# Rogue Agent (B.1.11)
333
337
"RA1": "Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.",
334
338
"RA2": "Remove any persistence mechanisms (cron jobs, startup scripts, state files). Skills should not maintain state across sessions without explicit user consent.",
0 commit comments