Skip to content

v5.15.4 - ClawHub skill context-store hardening + HOL scanner CI

Latest

Choose a tag to compare

@Jovancoding Jovancoding released this 29 Sep 16:22

Security

  • ClawHub skill: project-context memory poisoning fixed (scripts/context_manager.py, A.I.G T02). init/update now validate and reject unsafe values before writing, with per-section type checks. Every field and key is scanned for injection and role/prompt-delimiter patterns, with length, depth, count, and size caps. inject blocks on any warning and emits single-line values inside a <project_context type="reference-data"> block that marks them as data, not instructions.

Changed

  • scripts/check_permission.py: docstring and --help describe an advisory local scorer that holds no credentials; --confirm-high-risk help lists PAYMENTS, DATABASE, and FILE_EXPORT.
  • SKILL.md: allowed-tools limits the skill to its six bundled scripts plus Read. Capabilities declare only NETWORK_AI_ENV, no shell, no ports, and no autonomous actions. Unpinned npx commands removed. New Bundled Script Inventory.
  • .clawhubignore excludes Python bytecode caches.

CI

  • New HOL plugin-scanner workflow on every push and PR, using the same gate as the awesome-ai-plugins listing (score >= 80, fail on high, repository policy not trusted). Read-only permissions, SHA-pinned actions.

Tests

  • 3,679 tests across 41 suites; tsc --noEmit clean. Local HOL scan: 95/100, no high findings.

Full changelog: v5.15.3...v5.15.4