Skip to content

Scoping: GitHub Actions workflow injection + script-tag SRI checks fall outside ast_guard's language support #265

Description

@jamessoubry

Last two items from the security-guidance gap review (see #261-264 for the same context). Filing separately because these two are not straightforward AST-rule additions like the others — they need a decision, not just implementation.

The gap

security-guidance flags two things ast_guard cannot currently see at all:

  1. github_actions_workflow — untrusted-input command injection in .github/workflows/*.yml (run: echo "${{ github.event.issue.title }}" style). This is YAML content with embedded shell — not one of ast_guard's four supported languages (Rust/Python/JS/TS), and not really "AST of a programming language" in the way the other rules are.
  2. script_src_without_sri — <script src="https://..."> tags missing Subresource Integrity. This is raw HTML, also outside ast_guard's language set.

Options (no strong recommendation yet — a scope decision, not a technical one)

  • (a) Add a lightweight regex check for these two specifically in ast_guard.rs (or a sibling function) that runs on .yml/.yaml under .github/workflows/ and on .html files respectively, bypassing the tree-sitter path entirely for just these two cases. Contradicts the module's whole "AST not regex" premise, but matches what security-guidance itself does (both are regex there too) and these two really are closer to "check this specific known-dangerous string shape" than "distinguish real code from a comment."
  • (b) Add real grammars: tree-sitter-yaml for (1), tree-sitter-html for (2). More consistent with the module's design, more dependency weight, and YAML/HTML AST rules would be a genuinely new query shape neither of us has written yet — bigger lift for two rules.
  • (c) Skip both — leave them to security-guidance's own coverage (it runs anyway, layered independently) and treat this as accepted scope: ast_guard covers programming-language content, not config/markup files. Reasonable if these two are judged low-value relative to the AST rules in ast_guard: add unsafe-deserialization rules (Python) — pickle/marshal/shelve/joblib/pandas/numpy/torch/yaml #261-264.

Reference

~/.claude/plugins/cache/claude-plugins-official/security-guidance/2.0.7/hooks/patterns.py, rules github_actions_workflow, script_src_without_sri.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    backlogIn the backlog queue

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions