Skip to content

feat(scanner): reject plugin browser-profile stores - #1150

Draft
seonghobae wants to merge 3 commits into
feat/claude-plugin-hidden-executable-1099from
feat/claude-plugin-browser-profile-1099
Draft

seonghobae wants to merge 3 commits into
feat/claude-plugin-hidden-executable-1099from
feat/claude-plugin-browser-profile-1099

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Current repair boundary — 2026-09-12

Successor of #1146 / issue #1099. Does not Close those. Does not steal G-06 #1133, #1145 eval, or #1146 hidden-executable unique delta. Docker sockets stay claude-plugin-docker-socket.

Unique delta

Fail closed on host browser profile stores (claude-plugin-browser-profile-access):

  • hook copy of Google/Chrome Cookies fails admission
  • Firefox cookies.sqlite, Chromium Login Data, and %LOCALAPPDATA%\Google\Chrome fail admission
  • a plugin.json command string that names Chrome Cookies fails admission
  • README documentation of those paths is not this finding
  • a bare Firefox product name stays browser_profile_access inventory, not this finding
  • /var/run/docker.sock stays claude-plugin-docker-socket
  • feat(scanner): reject hidden undeclared plugin executables #1146 hidden undeclared executables stay that class
  • snippets omit secrets and raw bidi

#1146 remains owner of hidden undeclared executable/config surfaces.

Test plan

  • RED then GREEN (tests/test_claude_plugin_browser_profile.py)
  • Detector statement coverage 1444/1444 with plugin suites on Python 3.13
  • Exact-head Checks on this head
  • Keep Draft until current-head gates are GREEN

Relates to #1099. Relates to #1146.

RED contract for host Chrome/Firefox profile stores on hook and
manifest surfaces. README text and a bare Firefox word stay
inventory. Relates to #1099.
Fail closed when a hook or manifest names a host Chrome, Chromium, or
Firefox profile store. Bare product names stay inventory. Relates to
#1099.
@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Refresh the single-writer gap baseline from live exact-head evidence:
Draft #1150 on #1146, concurrent #1148 sentinel, and G-06 #1133
exact-head coverage SUCCESS. Relates to #1099.

Copy link
Copy Markdown
Contributor Author

Stacked successor Draft #1151 (feat/claude-plugin-deceptive-description-1099 @ 822ca12f1d8b55ae81f7feb882cc6f3073587256) adds claude-plugin-deceptive-description only. It does not Close #1099 or #1150. Browser-profile access stays this PR. Inventory remains evidence, not permission.

seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 15:28 UTC records Draft #1151 `822ca12` on #1150 and
  Draft #1152 `255cfd8` on #1133.
- `_scan_file` emits poll analyzer findings once per (rule_id, file).
- Deceptive read-only descriptions fail closed when inventory shows
  write or egress.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- G-06 emission waited on #1133 exact-head coverage SUCCESS.

Tests:
- documentation-only; evidence lives on #1151 (1560/1560) and #1152
  (417/417 analyzer statements)
seonghobae added a commit that referenced this pull request Sep 7, 2026
Summary:
- Snapshot 2026-09-07 23:23 UTC records Draft #1171 `9370a0d` stacked on #1170.
- Host cookie/token stores beyond browser profiles fail closed.
- Remaining leftover: deep directory recursion, Cosign/GPG, deployment-write.

Rationale:
- #999 is the single writer of the product-technical gap baseline.
- Do not Close #1099, #1170, #1150, or #1137.

Tests:
- documentation-only; detector evidence lives on #1171 (2505/2505)
@seonghobae seonghobae added enhancement New feature or request priority: medium Normal-priority or P2 work labels Sep 8, 2026 — with ChatGPT Codex Connector
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium Normal-priority or P2 work

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant