T09 · Insecure Skill Coding Practices
- Location
scanner.js:290- Finding
Unsafe whitelist matching can suppress malicious scan findings
- Content
View full analysis
0) { // Check if it's whitelisted if (!this.isWhitelisted(matches[0])) { const lineNumbers = this.findLineNumbers(content, regex); this.findings.push({ pattern: patternName, level: patternDef.level, description: patternDef.description, recommendation: patternDef.recommendation, matches: matches.slice(0, 3), lineNumbers: lineNumbers.slice(0, 3), count: matches.length, }); } } } } ``` ```javascript isWhitelisted(match) { // Check whitelisted domains for (const domain of this.config.whitelistedDomains) { if (match.includes(domain)) { return true; } } // Check whitelisted commands for (const cmd of this.config.whitelistedCommands) { if (match.includes(cmd)) { return true; } } return false; } ``` ### Technical Analysis The scanner treats a match as trusted whenever its raw text contains a whitelisted domain or command as an unrestricted substring. This does not establish that a URL's normalized hostname is the trusted domain. For example, an attacker-controlled hostname or URL component may contain a trusted string such as `github.com` without being operated by GitHub. The scanner also applies the whitelist decision only to `matches[0]`. If the first result for a particular regular expression is considered whitelisted, the entire result set for that expression is discarded. Consequently, later malicious matches covered by the same expression are not rep ...[truncated 1794 chars]- Remediation
View remediation
