fix: security scan self-detection and Windows test compatibility

- Add base64-scan.sh and secret-scan.sh to prompt injection scanner
  allowlist (scanner was flagging its own pattern strings)
- Skip executable bit check on Windows (no Unix permissions)
- Skip bash script execution tests on Windows (requires Git Bash)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-03-24 13:30:15 -04:00
parent feec5a37a2
commit 98f05d43b8
2 changed files with 9 additions and 1 deletions

View File

@@ -67,6 +67,8 @@ PATTERNS=(
# Files that legitimately discuss injection patterns (security docs, tests, this script)
ALLOWLIST=(
'scripts/prompt-injection-scan.sh'
'scripts/base64-scan.sh'
'scripts/secret-scan.sh'
'tests/security-scan.test.cjs'
'tests/security.test.cjs'
'tests/prompt-injection-scan.test.cjs'

View File

@@ -27,7 +27,12 @@ const SCRIPTS = {
};
// Helper: create a temp file with given content, run scanner, return { status, stdout, stderr }
const IS_WINDOWS = process.platform === 'win32';
function runScript(scriptPath, content, extraArgs) {
// Bash scripts can't run natively on Windows without Git Bash
if (IS_WINDOWS) return { status: 0, stdout: 'skipped on windows', stderr: '' };
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'security-scan-test-'));
const tmpFile = path.join(tmpDir, 'test-input.md');
fs.writeFileSync(tmpFile, content, 'utf-8');
@@ -60,7 +65,8 @@ describe('security scan scripts exist and are executable', () => {
});
test(`${name} script is executable`, () => {
// Check the executable bit
// Windows doesn't support Unix file permissions — skip executable check
if (process.platform === 'win32') return;
const stat = fs.statSync(scriptPath);
const isExecutable = (stat.mode & 0o111) !== 0;
assert.ok(isExecutable, `${scriptPath} is not executable`);