Files
msd-core/tests/injection-blocking-config.test.cjs
Alex V. a63684c222 enhance(#1577): WebFetch/WebSearch injection isolation + opt-in blocking (#1585)
* fix(#1577): isolate WebFetch/WebSearch ingress + opt-in injection blocking

Split A of #1573 (security-critical). Scans WebFetch/WebSearch output (the
largest untrusted channel) in gsd-read-injection-scanner; shared
untrusted-input-boundary reference @-included by the 8 ingest agents
(randomized per-wrap delimiters, in-prompt self-scan guard, task-anchoring);
opt-in security.injection_blocking (default advisory — non-breaking).

arXiv: 2506.05739 (PPA), 2507.15219 (PromptArmor), 2504.20472 (Referencing), 2503.00061 (defense-in-depth).

* fix(#1577): address review — honest blocking docs, config key, ADR, property test, revert localized

- A1: rewrote the opt-in-blocking doc + Security changeset honestly — the PostToolUse hook is a
  circuit-breaker (halts the agent's next step), NOT a redactor; it does not scrub content already
  in the transcript. The prompt-level data/instruction boundary is the primary control.
- A2: registered security.injection_blocking in the config schema + defaults manifests (default
  false) + an e2e config-roundtrip test; the dotted setter writes the nested shape the hook reads.
- A3: reverted the 4 hand-edited localized security-model.md (canonical EN only, per convention).
- A5: ADR-1577 (untrusted-input boundary + opt-in blocking; redaction-vs-circuit-breaker rationale).
- A6: property test — scanner never crashes / only emits valid JSON on unicode/large/malformed input.
- Also: inventory (untrusted-input-boundary.md) + agent-size baseline (8 ingest agents) +
  drift-guard matcher update (Read -> Read|WebFetch|WebSearch). A7 (content<20 early-exit) left as
  the noted pre-existing follow-up.

* fix(#1577): allowlist untrusted-input-boundary.md in injection-scan CI gate

The new reference quotes injection phrases ('ignore previous instructions',
'you are now…') as examples agents must NOT comply with, tripping the repo's
own prompt-injection-scan.sh diff gate (the standalone 'security' CI job, red
on HEAD). Allowlist it alongside the other security docs (security-model.md,
TEST-EXAMPLES.md) that legitimately demonstrate injection patterns. The JS
scanner test doesn't scan references/, so only the shell gate needed it.

Verified: scan --diff origin/next -> 0 findings; scanner JS test 15/15.

* fix(#1577): cover AC #2's gsd-ui-researcher + gsd-assumptions-analyzer

trek-e Major 1: the @-included set dropped two AC #2 agents. Restore them so
no named web-ingress agent is uncovered, keeping the two justified additions
(gsd-ai-researcher, gsd-domain-researcher). Final set = AC's 8 + 2 = 10.
 - gsd-ui-researcher carries the full WebSearch/WebFetch + MCP-fetch toolset.
 - gsd-assumptions-analyzer reads 5-15 codebase source files (external/source-
   document ingress per the boundary), though it has no web tools.
INGEST_AGENTS in the isolation test now asserts all 10; size baselines
regenerated (+60 bytes each, both well under the DEFAULT cap); changeset
reworded 8 -> 10.

Verified: untrusted-input-isolation 14/14; agent-size-budget 39/39.

* docs(#1577): document security.injection_blocking + boundary seam

trek-e Major 2 + Minor:
 - docs/CONFIGURATION.md: add the top-level security.injection_blocking key to
   the Full Schema and a Security Settings subsection, distinguishing it from
   the workflow.security_* namespace; honest circuit-breaker-not-redactor
   framing matching ADR-1577 / security-model.
 - CONTEXT.md: add the 'Untrusted-input boundary' seam glossary entry.

Verified: lint:docs ok; config-field-docs + contributor-standards green.

* test(#1577): make read-injection property test git-text, not binary

trek-e nit (and more): the file embedded a raw U+FFFF AND a raw NUL byte as
degenerate-edge inputs. The NUL is what actually made git classify it binary
(git binary = NUL in first 8K). Replace both with text-safe escapes that keep
the identical runtime values: '\\x00' and String.fromCodePoint(0xFFFF). File
now diffs/blames line-by-line.

Verified: property test 2/2; no NUL/raw-noncharacter bytes remain.

* docs(#1577): align untrusted boundary docs

Name all 10 ingress agents in INVENTORY/security-model and allowlist the intentional read-injection property corpus for the prompt-injection scanner.

* docs(#1577): align ADR ingest agent count

Update ADR-1577 from 8 to 10 ingest agents so it matches the actual boundary include set and the rest of the docs.

---------

Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
2026-06-24 17:07:23 -04:00

79 lines
3.4 KiB
JavaScript

'use strict';
/**
* #1577 — `security.injection_blocking` is a first-class config key.
*
* The gsd-read-injection-scanner hook reads `.planning/config.json`
* `security.injection_blocking` to decide whether a HIGH detection blocks
* (opt-in) vs. stays advisory (default). Before this, the key was unregistered:
* `isValidConfigKey` returned false and `gsd config-set security.injection_blocking`
* was rejected as "Unknown config key" — the knob was settable only by hand-editing
* config.json. These tests lock the registration + the nested write shape the hook
* reads, and the advisory-by-default contract.
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const { createTempProject, cleanup, runGsdTools } = require('./helpers.cjs');
const { isValidConfigKey } = require('../gsd-core/bin/lib/config-schema.cjs');
const { CONFIG_DEFAULTS } = require('../gsd-core/bin/lib/configuration.cjs');
describe('#1577 — security.injection_blocking config key', () => {
test('isValidConfigKey accepts security.injection_blocking', () => {
assert.ok(
isValidConfigKey('security.injection_blocking'),
'security.injection_blocking must be a valid config key',
);
});
test('bare security section is not a settable leaf key', () => {
assert.ok(
!isValidConfigKey('security'),
'bare "security" must be rejected (use security.injection_blocking)',
);
});
test('CONFIG_DEFAULTS ships injection_blocking = false (advisory by default)', () => {
assert.equal(
CONFIG_DEFAULTS.security && CONFIG_DEFAULTS.security.injection_blocking,
false,
'default must be false so the hook stays advisory unless explicitly opted in',
);
});
test('config-set writes the nested shape the hook reads, and round-trips', () => {
const proj = createTempProject();
try {
const res = runGsdTools(['config-set', 'security.injection_blocking', 'true'], proj);
assert.ok(res.success, `config-set should succeed: ${res.output || ''}`);
// The hook reads cfg.security?.injection_blocking === true — assert the
// on-disk shape is the nested object it expects, not a flat dotted key.
const cfg = JSON.parse(fs.readFileSync(path.join(proj, '.planning', 'config.json'), 'utf8'));
assert.equal(cfg.security.injection_blocking, true, 'must persist nested security.injection_blocking');
assert.equal(cfg['security.injection_blocking'], undefined, 'must NOT persist a flat dotted key');
const get = runGsdTools(['config-get', 'security.injection_blocking'], proj);
assert.ok(get.success, `config-get should succeed: ${get.output || ''}`);
assert.match(String(get.output || ''), /true/, 'config-get should read back true');
} finally {
cleanup(proj);
}
});
test('a fresh project has no injection_blocking key — hook sees absent → advisory', () => {
const proj = createTempProject();
try {
const cfgPath = path.join(proj, '.planning', 'config.json');
const cfg = fs.existsSync(cfgPath) ? JSON.parse(fs.readFileSync(cfgPath, 'utf8')) : {};
// The hook's exact guard: cfg.security?.injection_blocking === true.
const blocking = cfg.security && cfg.security.injection_blocking === true;
assert.ok(!blocking, 'absent key must evaluate to advisory (not blocking)');
} finally {
cleanup(proj);
}
});
});