You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Last two items from the security-guidance gap review (see #261-264 for the same context). Filing separately because these two are not straightforward AST-rule additions like the others — they need a decision, not just implementation.
The gap
security-guidance flags two things ast_guard cannot currently see at all:
github_actions_workflow — untrusted-input command injection in .github/workflows/*.yml (run: echo "${{ github.event.issue.title }}" style). This is YAML content with embedded shell — not one of ast_guard's four supported languages (Rust/Python/JS/TS), and not really "AST of a programming language" in the way the other rules are.
script_src_without_sri — <script src="https://..."> tags missing Subresource Integrity. This is raw HTML, also outside ast_guard's language set.
Options (no strong recommendation yet — a scope decision, not a technical one)
(a) Add a lightweight regex check for these two specifically in ast_guard.rs (or a sibling function) that runs on .yml/.yaml under .github/workflows/ and on .html files respectively, bypassing the tree-sitter path entirely for just these two cases. Contradicts the module's whole "AST not regex" premise, but matches what security-guidance itself does (both are regex there too) and these two really are closer to "check this specific known-dangerous string shape" than "distinguish real code from a comment."
(b) Add real grammars: tree-sitter-yaml for (1), tree-sitter-html for (2). More consistent with the module's design, more dependency weight, and YAML/HTML AST rules would be a genuinely new query shape neither of us has written yet — bigger lift for two rules.
Last two items from the security-guidance gap review (see #261-264 for the same context). Filing separately because these two are not straightforward AST-rule additions like the others — they need a decision, not just implementation.
The gap
security-guidance flags two things ast_guard cannot currently see at all:
github_actions_workflow— untrusted-input command injection in.github/workflows/*.yml(run: echo "${{ github.event.issue.title }}"style). This is YAML content with embedded shell — not one of ast_guard's four supported languages (Rust/Python/JS/TS), and not really "AST of a programming language" in the way the other rules are.script_src_without_sri—<script src="https://...">tags missing Subresource Integrity. This is raw HTML, also outside ast_guard's language set.Options (no strong recommendation yet — a scope decision, not a technical one)
ast_guard.rs(or a sibling function) that runs on.yml/.yamlunder.github/workflows/and on.htmlfiles respectively, bypassing the tree-sitter path entirely for just these two cases. Contradicts the module's whole "AST not regex" premise, but matches what security-guidance itself does (both are regex there too) and these two really are closer to "check this specific known-dangerous string shape" than "distinguish real code from a comment."tree-sitter-yamlfor (1),tree-sitter-htmlfor (2). More consistent with the module's design, more dependency weight, and YAML/HTML AST rules would be a genuinely new query shape neither of us has written yet — bigger lift for two rules.Reference
~/.claude/plugins/cache/claude-plugins-official/security-guidance/2.0.7/hooks/patterns.py, rulesgithub_actions_workflow,script_src_without_sri.