* fix(#1577): isolate WebFetch/WebSearch ingress + opt-in injection blocking Split A of #1573 (security-critical). Scans WebFetch/WebSearch output (the largest untrusted channel) in gsd-read-injection-scanner; shared untrusted-input-boundary reference @-included by the 8 ingest agents (randomized per-wrap delimiters, in-prompt self-scan guard, task-anchoring); opt-in security.injection_blocking (default advisory — non-breaking). arXiv: 2506.05739 (PPA), 2507.15219 (PromptArmor), 2504.20472 (Referencing), 2503.00061 (defense-in-depth). * fix(#1577): address review — honest blocking docs, config key, ADR, property test, revert localized - A1: rewrote the opt-in-blocking doc + Security changeset honestly — the PostToolUse hook is a circuit-breaker (halts the agent's next step), NOT a redactor; it does not scrub content already in the transcript. The prompt-level data/instruction boundary is the primary control. - A2: registered security.injection_blocking in the config schema + defaults manifests (default false) + an e2e config-roundtrip test; the dotted setter writes the nested shape the hook reads. - A3: reverted the 4 hand-edited localized security-model.md (canonical EN only, per convention). - A5: ADR-1577 (untrusted-input boundary + opt-in blocking; redaction-vs-circuit-breaker rationale). - A6: property test — scanner never crashes / only emits valid JSON on unicode/large/malformed input. - Also: inventory (untrusted-input-boundary.md) + agent-size baseline (8 ingest agents) + drift-guard matcher update (Read -> Read|WebFetch|WebSearch). A7 (content<20 early-exit) left as the noted pre-existing follow-up. * fix(#1577): allowlist untrusted-input-boundary.md in injection-scan CI gate The new reference quotes injection phrases ('ignore previous instructions', 'you are now…') as examples agents must NOT comply with, tripping the repo's own prompt-injection-scan.sh diff gate (the standalone 'security' CI job, red on HEAD). Allowlist it alongside the other security docs (security-model.md, TEST-EXAMPLES.md) that legitimately demonstrate injection patterns. The JS scanner test doesn't scan references/, so only the shell gate needed it. Verified: scan --diff origin/next -> 0 findings; scanner JS test 15/15. * fix(#1577): cover AC #2's gsd-ui-researcher + gsd-assumptions-analyzer trek-e Major 1: the @-included set dropped two AC #2 agents. Restore them so no named web-ingress agent is uncovered, keeping the two justified additions (gsd-ai-researcher, gsd-domain-researcher). Final set = AC's 8 + 2 = 10. - gsd-ui-researcher carries the full WebSearch/WebFetch + MCP-fetch toolset. - gsd-assumptions-analyzer reads 5-15 codebase source files (external/source- document ingress per the boundary), though it has no web tools. INGEST_AGENTS in the isolation test now asserts all 10; size baselines regenerated (+60 bytes each, both well under the DEFAULT cap); changeset reworded 8 -> 10. Verified: untrusted-input-isolation 14/14; agent-size-budget 39/39. * docs(#1577): document security.injection_blocking + boundary seam trek-e Major 2 + Minor: - docs/CONFIGURATION.md: add the top-level security.injection_blocking key to the Full Schema and a Security Settings subsection, distinguishing it from the workflow.security_* namespace; honest circuit-breaker-not-redactor framing matching ADR-1577 / security-model. - CONTEXT.md: add the 'Untrusted-input boundary' seam glossary entry. Verified: lint:docs ok; config-field-docs + contributor-standards green. * test(#1577): make read-injection property test git-text, not binary trek-e nit (and more): the file embedded a raw U+FFFF AND a raw NUL byte as degenerate-edge inputs. The NUL is what actually made git classify it binary (git binary = NUL in first 8K). Replace both with text-safe escapes that keep the identical runtime values: '\\x00' and String.fromCodePoint(0xFFFF). File now diffs/blames line-by-line. Verified: property test 2/2; no NUL/raw-noncharacter bytes remain. * docs(#1577): align untrusted boundary docs Name all 10 ingress agents in INVENTORY/security-model and allowlist the intentional read-injection property corpus for the prompt-injection scanner. * docs(#1577): align ADR ingest agent count Update ADR-1577 from 8 to 10 ingest agents so it matches the actual boundary include set and the rest of the docs. --------- Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
228 lines
8.9 KiB
JavaScript
228 lines
8.9 KiB
JavaScript
#!/usr/bin/env node
|
||
// gsd-hook-version: {{GSD_VERSION}}
|
||
// GSD Read Injection Scanner — PostToolUse hook (#2201)
|
||
// Pattern-based pre-filter / blocklist: scans content returned by Read, WebFetch,
|
||
// and WebSearch for known prompt-injection patterns (regex + heuristic rules).
|
||
// This is a static pattern match — NOT a semantic guard, NOT PromptArmor.
|
||
// It does NOT understand context, intent, or novel phrasing; it catches
|
||
// known injection signatures at ingestion before they enter conversation context.
|
||
//
|
||
// Defense-in-depth: long GSD sessions hit context compression, and the
|
||
// summariser does not distinguish user instructions from content read from
|
||
// external files. Poisoned instructions that survive compression become
|
||
// indistinguishable from trusted context. This hook warns at ingestion time.
|
||
// Prompt-level self-guard and task-anchor controls (untrusted-input-boundary.md)
|
||
// operate independently as a complementary layer.
|
||
//
|
||
// Triggers on: Read, WebFetch, WebSearch PostToolUse events
|
||
// Action: Advisory warning by default; blocks HIGH only when security.injection_blocking=true
|
||
// Severity: LOW (1–2 patterns), HIGH (3+ patterns)
|
||
//
|
||
// False-positive exclusion: .planning/, REVIEW.md, CHECKPOINT, security docs,
|
||
// hook source files — these legitimately contain injection-like strings.
|
||
|
||
const path = require('path');
|
||
const fs = require('fs');
|
||
|
||
// Summarisation-specific patterns (novel — not in gsd-prompt-guard.js).
|
||
// These target instructions specifically designed to survive context compression.
|
||
const SUMMARISATION_PATTERNS = [
|
||
/when\s+(?:summari[sz]ing|compressing|compacting),?\s+(?:retain|preserve|keep)\s+(?:this|these)/i,
|
||
/this\s+(?:instruction|directive|rule)\s+is\s+(?:permanent|persistent|immutable)/i,
|
||
/preserve\s+(?:these|this)\s+(?:rules?|instructions?|directives?)\s+(?:in|through|after|during)/i,
|
||
/(?:retain|keep)\s+(?:this|these)\s+(?:in|through|after)\s+(?:summar|compress|compact)/i,
|
||
];
|
||
|
||
// Markdown link patterns — mirrors scripts/security.cjs MARKDOWN_LINK_PATTERNS, inlined for hook independence.
|
||
// Issue #113: detect javascript:, data: (non-safe-list), userinfo credentials, and token-in-query.
|
||
//
|
||
// Sources:
|
||
// MD-LINK-JS-SCHEME: OWASP XSS Prevention
|
||
// https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
|
||
// MD-LINK-DATA-SCHEME: OWASP File Upload (SVG unsafe)
|
||
// https://cheatsheetseries.owasp.org/cheatsheets/File_Upload_Cheat_Sheet.html#svg-files
|
||
// MD-LINK-USERINFO: RFC 3986 §3.2.1, RFC 9110 §4.2.4
|
||
// https://www.rfc-editor.org/rfc/rfc3986#section-3.2.1
|
||
// https://www.rfc-editor.org/rfc/rfc9110#section-4.2.4
|
||
// MD-LINK-TOKEN-IN-QUERY: RFC 9700 §4.3.1
|
||
// https://www.rfc-editor.org/rfc/rfc9700#section-4.3.1
|
||
const DATA_URI_SAFE_MIME_RE = /^data:(image\/(png|jpe?g|gif|webp|bmp|ico|avif|heic)|font\/(woff2?|otf|ttf))(;[^,]*)?,/i;
|
||
|
||
const MARKDOWN_LINK_PATTERNS = [
|
||
{
|
||
pattern: /\]\(\s*javascript:/i,
|
||
ruleId: 'MD-LINK-JS-SCHEME',
|
||
},
|
||
{
|
||
pattern: /\]\(\s*data:/i,
|
||
ruleId: 'MD-LINK-DATA-SCHEME',
|
||
safePredicate: (line) => {
|
||
const m = line.match(/\]\(\s*(data:[^)]*)/i);
|
||
if (!m) return false;
|
||
return DATA_URI_SAFE_MIME_RE.test(m[1]);
|
||
},
|
||
},
|
||
{
|
||
pattern: /\]\(\s*https?:\/\/[^/\s]+:[^/@\s]+@/i,
|
||
ruleId: 'MD-LINK-USERINFO',
|
||
},
|
||
{
|
||
pattern: /[?&](token|access_token|id_token|refresh_token|api_key|apikey|secret|password|client_secret|code)=/i,
|
||
ruleId: 'MD-LINK-TOKEN-IN-QUERY',
|
||
},
|
||
];
|
||
|
||
// Standard injection patterns — mirrors gsd-prompt-guard.js, inlined for hook independence.
|
||
const INJECTION_PATTERNS = [
|
||
/ignore\s+(all\s+)?previous\s+instructions/i,
|
||
/ignore\s+(all\s+)?above\s+instructions/i,
|
||
/disregard\s+(all\s+)?previous/i,
|
||
/forget\s+(all\s+)?(your\s+)?instructions/i,
|
||
/override\s+(system|previous)\s+(prompt|instructions)/i,
|
||
/you\s+are\s+now\s+(?:a|an|the)\s+/i,
|
||
/act\s+as\s+(?:a|an|the)\s+(?!plan|phase|wave)/i,
|
||
/pretend\s+(?:you(?:'re| are)\s+|to\s+be\s+)/i,
|
||
/from\s+now\s+on,?\s+you\s+(?:are|will|should|must)/i,
|
||
/(?:print|output|reveal|show|display|repeat)\s+(?:your\s+)?(?:system\s+)?(?:prompt|instructions)/i,
|
||
/<\/?(?:system|assistant|human)>/i,
|
||
/\[SYSTEM\]/i,
|
||
/\[INST\]/i,
|
||
/<<\s*SYS\s*>>/i,
|
||
];
|
||
|
||
const ALL_PATTERNS = [...INJECTION_PATTERNS, ...SUMMARISATION_PATTERNS];
|
||
|
||
function isExcludedPath(filePath) {
|
||
const p = filePath.replace(/\\/g, '/');
|
||
return (
|
||
p.includes('/.planning/') ||
|
||
p.includes('.planning/') ||
|
||
/(?:^|\/)REVIEW\.md$/i.test(p) ||
|
||
/CHECKPOINT/i.test(path.basename(p)) ||
|
||
/[/\\](?:security|techsec|injection)[/\\.]/i.test(p) ||
|
||
/security\.cjs$/.test(p) ||
|
||
p.includes('/.claude/hooks/')
|
||
);
|
||
}
|
||
|
||
let inputBuf = '';
|
||
const stdinTimeout = setTimeout(() => process.exit(0), 5000);
|
||
process.stdin.setEncoding('utf8');
|
||
process.stdin.on('data', chunk => { inputBuf += chunk; });
|
||
process.stdin.on('end', () => {
|
||
clearTimeout(stdinTimeout);
|
||
try {
|
||
const data = JSON.parse(inputBuf);
|
||
|
||
const toolName = data.tool_name;
|
||
const SCANNED_TOOLS = new Set(['Read', 'WebFetch', 'WebSearch']);
|
||
if (!SCANNED_TOOLS.has(toolName)) {
|
||
process.exit(0);
|
||
}
|
||
|
||
// Source label + path-exclusion (path-exclusion applies to file reads only)
|
||
let source;
|
||
if (toolName === 'Read') {
|
||
source = data.tool_input?.file_path || '';
|
||
if (!source) process.exit(0);
|
||
if (isExcludedPath(source)) process.exit(0);
|
||
} else if (toolName === 'WebFetch') {
|
||
source = data.tool_input?.url || 'web';
|
||
} else { // WebSearch
|
||
source = `search: ${data.tool_input?.query || ''}`;
|
||
}
|
||
|
||
// Extract content from tool_response — string, {content}, or arbitrary object
|
||
let content = '';
|
||
const resp = data.tool_response;
|
||
if (typeof resp === 'string') {
|
||
content = resp;
|
||
} else if (resp && typeof resp === 'object') {
|
||
const c = resp.content;
|
||
if (Array.isArray(c)) {
|
||
content = c.map(b => (typeof b === 'string' ? b : b.text || '')).join('\n');
|
||
} else if (c != null) {
|
||
content = String(c);
|
||
} else {
|
||
// WebSearch results etc. — scan the serialized response
|
||
try { content = JSON.stringify(resp); } catch { content = ''; }
|
||
}
|
||
}
|
||
|
||
if (!content || content.length < 20) {
|
||
process.exit(0);
|
||
}
|
||
|
||
const findings = [];
|
||
|
||
for (const pattern of ALL_PATTERNS) {
|
||
if (pattern.test(content)) {
|
||
// Trim pattern source for readable output
|
||
findings.push(pattern.source.replace(/\\s\+/g, '-').replace(/[()\\]/g, '').substring(0, 50));
|
||
}
|
||
}
|
||
|
||
// Markdown link patterns (issue #113)
|
||
const lines = content.split('\n');
|
||
for (const entry of MARKDOWN_LINK_PATTERNS) {
|
||
for (let i = 0; i < lines.length; i++) {
|
||
const line = lines[i];
|
||
const m = line.match(entry.pattern);
|
||
if (!m) continue;
|
||
if (entry.safePredicate && entry.safePredicate(line)) continue;
|
||
findings.push(`${entry.ruleId}:${m[0].substring(0, 40)}`);
|
||
}
|
||
}
|
||
|
||
// Invisible Unicode (zero-width, RTL override, soft hyphen, BOM)
|
||
if (/[\u200B-\u200F\u2028-\u202F\uFEFF\u00AD\u2060-\u2069]/.test(content)) {
|
||
findings.push('invisible-unicode');
|
||
}
|
||
|
||
// Unicode tag block U+E0000–E007F (invisible instruction injection vector)
|
||
try {
|
||
if (/[\u{E0000}-\u{E007F}]/u.test(content)) {
|
||
findings.push('unicode-tag-block');
|
||
}
|
||
} catch {
|
||
// Engine does not support Unicode property escapes — skip this check
|
||
}
|
||
|
||
if (findings.length === 0) {
|
||
process.exit(0);
|
||
}
|
||
|
||
const severity = findings.length >= 3 ? 'HIGH' : 'LOW';
|
||
const label = toolName === 'Read' ? path.basename(source) : source;
|
||
const detail = severity === 'HIGH'
|
||
? 'Multiple patterns — strong injection signal. Review for embedded instructions before proceeding.'
|
||
: 'Single pattern match may be a false positive (e.g., documentation). Proceed with awareness.';
|
||
const advisory =
|
||
`\u26a0\ufe0f INJECTION SCAN [${severity}] (${toolName}): "${label}" triggered ` +
|
||
`${findings.length} pattern(s): ${findings.join(', ')}. ` +
|
||
`This content is now in your conversation context. ${detail} Source: ${source}`;
|
||
|
||
// Opt-in blocking: only when configured AND high-confidence
|
||
let blocking = false;
|
||
if (severity === 'HIGH') {
|
||
try {
|
||
const cfgBase = data.cwd || process.cwd();
|
||
const cfgPath = path.join(cfgBase, '.planning', 'config.json');
|
||
const cfg = JSON.parse(fs.readFileSync(cfgPath, 'utf8'));
|
||
blocking = cfg.security?.injection_blocking === true;
|
||
} catch { /* no config ⇒ advisory */ }
|
||
}
|
||
|
||
const output = blocking
|
||
? { decision: 'block',
|
||
reason: `Prompt-injection blocked (${toolName}). ${advisory}`,
|
||
hookSpecificOutput: { hookEventName: 'PostToolUse', additionalContext: advisory } }
|
||
: { hookSpecificOutput: { hookEventName: 'PostToolUse', additionalContext: advisory } };
|
||
|
||
process.stdout.write(JSON.stringify(output));
|
||
} catch {
|
||
// Silent fail — never block tool execution
|
||
process.exit(0);
|
||
}
|
||
});
|