Skip to content

P2 false positives on benign standalone header comments (complete, top-of-file, danger-free) #677

Description

@Yoseph-Zuskin

Problem

SkillSpector reports P2 prompt-injection on benign standalone header
comments: license headers (<!-- Copyright (c) 2026 Example Corp. SPDX-License-Identifier: Apache-2.0 ... -->), get-started pointers,
and dependency declarations in complete top-of-file comments that
carry no override or exfiltration signal. These are distinct from
#37's reported spans (matches running past --> into <style>
blocks), which come from the unbounded .*? in the P2 comment
regex and are out of scope here.

Proposed scope

Exempt a P2 comment match only when it is one complete comment near
the top of the file (or directly after closed frontmatter), at most
300 characters, danger-free, and every fragment fully matches an
anchored license-line form or a per-key metadata grammar. Spanning,
partial, and multi-comment matches keep firing (fail-closed).

Acceptance

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions