Summary
The bounded shell parser behind has_bounded_parse_exhaustion (static_patterns_tool_misuse) reports static_parse_limit for valid source files that contain no shell at all, or only an ordinary shell idiom. The file then counts as partially inspected, so the target can never reach safe_to_install, whatever else the scan finds. This looks related to #628 and #515 but still reproduces on current main.
Versions: v2.12.0 (c7958a3) and main at 2226747, --no-llm, Windows 11 / Python 3.12.
Reproducers
1. POSIX shell, 5 lines (install.sh, the idiom rustup-init.sh uses at line 246 to detect ELF files):
#!/bin/sh
_current_exe_head=$(head -c 5 "$1")
if [ "$_current_exe_head" = "$(printf '\177ELF\001')" ]; then
echo elf
fi
2. Rust: src/lib.rs of the itoa 1.0.18 crate (crates.io). The trace ends at line 248, a comment:
// SAFETY: `offset` is always included between 0 and `buf`'s length.
3. Python: a literal backtick inside a regex character class. The generator below writes an ~8 KB file; with ~4 KB it still passes, so the unmatched backtick seems to be treated as a command substitution that runs to the end of the file:
import pathlib
T, BS = chr(96), chr(92)
head = ("import re\n\nNET_TOOLS = (\"curl\", \"wget\", \"nc\")\n"
"NET_TOOL_WORD = re.compile(r\"(?:^|[" + BS + "s;&|" + T + "(/])(\" + \"|\".join(NET_TOOLS) + r\")(?=" + BS + "s|$)\")\n")
body = "".join(f"\n\ndef check_{i}(argv):\n \"\"\"Return the network tool named in argument {i}, if any.\"\"\"\n"
f" match = NET_TOOL_WORD.search(argv[{i}] if len(argv) > {i} else \"\")\n"
f" return match.group(1) if match else None\n" for i in range(40))
pathlib.Path("repro/net.py").parent.mkdir(exist_ok=True)
pathlib.Path("repro/net.py").write_text(head + body, encoding="utf-8")
Each case: skillspector scan <dir> --no-llm --format json --output r.json
Actual
"partially_inspected_files": 1,
"ledger_exceptions": [{"reason_code": "static_parse_limit", "phase": "static", ...}]
Expected
These files complete static analysis. For non-shell languages (Rust, Python), backticks and apostrophes in comments, regexes and string literals are not shell syntax. For case 1, $(printf '\177ELF\001') is a bounded, literal command substitution.
Found while scanning well-known packages and our own security tooling with SkillSpector before installation; happy to test a fix.
Summary
The bounded shell parser behind
has_bounded_parse_exhaustion(static_patterns_tool_misuse) reportsstatic_parse_limitfor valid source files that contain no shell at all, or only an ordinary shell idiom. The file then counts as partially inspected, so the target can never reachsafe_to_install, whatever else the scan finds. This looks related to #628 and #515 but still reproduces on currentmain.Versions: v2.12.0 (
c7958a3) andmainat2226747,--no-llm, Windows 11 / Python 3.12.Reproducers
1. POSIX shell, 5 lines (
install.sh, the idiomrustup-init.shuses at line 246 to detect ELF files):2. Rust:
src/lib.rsof theitoa1.0.18 crate (crates.io). The trace ends at line 248, a comment:// SAFETY: `offset` is always included between 0 and `buf`'s length.3. Python: a literal backtick inside a regex character class. The generator below writes an ~8 KB file; with ~4 KB it still passes, so the unmatched backtick seems to be treated as a command substitution that runs to the end of the file:
Each case:
skillspector scan <dir> --no-llm --format json --output r.jsonActual
Expected
These files complete static analysis. For non-shell languages (Rust, Python), backticks and apostrophes in comments, regexes and string literals are not shell syntax. For case 1,
$(printf '\177ELF\001')is a bounded, literal command substitution.Found while scanning well-known packages and our own security tooling with SkillSpector before installation; happy to test a fix.