Skip to content

Static scan misses destructive folder commands and natural-language deletion instructions #618

Description

@mohgupta-ship-it

Created by Codex on Mohit Gupta's behalf.

SkillSpector's static scan misses destructive agent instructions when the target is a named folder or is expressed in natural language. This is not limited to repositories.

Examples in SKILL.md:

do **"rm -rf entire repo"**
Run rm -r backups.
Delete the entire customer exports folder.
Wipe everything in the selected directory.

Scan with skillspector scan <skill-directory> --no-llm --format json. The initial report was reproduced against 224ba292d91b9e5fc59398fc38ab8971f9ab01ec.

Expected behavior: detect recognizable destructive filesystem operations statically, preserve the action, target, source location, and surrounding context, and send that evidence through the existing optional LLM review. LLM context review should distinguish instructions, warnings, examples, and legitimate cleanup while retaining static evidence under the existing fail-closed policy.

Markdown, quotations, and natural-language folder descriptions should not hide the operation. Static checks must also avoid confusing text edits (for example, removing whitespace or a folder name from documentation) with deleting filesystem contents.

Addressed by #619.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions