T09 · Insecure Skill Coding Practices
- Location
clawsec-monitor.py:570- Finding
Traffic signatures can evade detection across stream boundaries
- Content
View full analysis
None: scanned = 0 try: while chunk := await src.read(4096): if scanned < self.max_scan: text = chunk.decode("utf-8", errors="replace") for t in scan(text, direction, dest=dest, max_bytes=self.max_scan, proto=proto): await emit(t) scanned += len(chunk) dst.write(chunk) await dst.drain() ``` The same independent-chunk scanning design is used for the HTTPS MITM inbound path: ```python async def _transport_pipe_inspect(self, src: asyncio.StreamReader, dst_transport, direction: str, dest: str) -> None: """Inspect then write to raw TLS transport (MITM inbound path).""" scanned = 0 try: while chunk := await src.read(4096): if scanned < self.max_scan: text = chunk.decode("utf-8", errors="replace") for t in scan(text, direction, dest=dest, max_bytes=self.max_scan, proto="https"): await emit(t) scanned += len(chunk) dst_transport.write(chunk) ``` The gateway proxy also scans each read independently: ```python async def _pipe(self, src: asyncio.StreamReader, dst: asyncio.StreamWriter, direction: str) -> None: try: while chunk := await src.read(4096): text = chunk.decode("utf-8", errors="replace") for t in scan(text, direction, max_bytes=self.max_scan, proto ...[truncated 2096 chars]- Remediation
View remediation
