fix(skills): catch sed flag variants; exempt content-contract prose in plugin code

Review-fold from the 3-angle simplify pass:

- sed -Ei / -iE / --in-place now match the shell-critical tier (the
  bare '\s-i\b' token missed combined short flags and the GNU long
  form); read-only sed stays unflagged. Regression tests added.
- agent_config_contract joins plugin_guard's CODE_EXEMPT_PATTERN_IDS:
  content-contract prose in plugin code files (docstrings/comments)
  is the same false-positive class the existing agent_config_mod
  exemption suppresses. Doc/config files keep the full pattern set.

Efficiency reviewer: 1.24x full-scan cost (+3.4ms/file, install-time
only), worst-case adversarial line 55us — no ReDoS exposure.
This commit is contained in:
kshitijk4poor
2026-08-28 13:26:55 +05:30
committed by Teknium
parent f2f61e0a45
commit 8c098e9e81
3 changed files with 18 additions and 1 deletions
+1
View File
@@ -94,6 +94,7 @@ CODE_EXEMPT_PATTERN_IDS = {
# Plugins legitimately write their own settings into config.yaml during
# post_setup, and encode credentials (e.g. HTTP Basic auth) with base64.
"agent_config_mod",
"agent_config_contract",
"encoded_exfil",
}