Skip to content

Keep PowerShell embedded-shell analysis and SC8 runtime exhaustion fail-closed #711

Description

@SyuanTsai

Summary

This proposal covers two bounded static-analysis paths in SkillSpector: PowerShell code that invokes or embeds shell commands, and SC8's shipped-bytecode scan budget. If either path cannot finish or prove the supported syntax it is examining, the scan must retain an incomplete ledger result rather than report the affected content as clean.

PowerShell shell projection

static_patterns_tool_misuse.has_bounded_parse_exhaustion analyzes shell commands embedded in PowerShell source and Markdown powershell fences. PowerShell comments, closed here-strings, and inert quoted text should not be mistaken for shell commands. Supported executable payloads passed through bash/sh -c, Invoke-Expression, script-block creation, and call operators must retain the existing bounded shell checks and source locations.

Projection is deliberately conservative. Unclosed strings, here-strings or fences; unresolved dynamic calls; unsupported nested command syntax; and companion context that cannot be proven must remain STATIC_PARSE_LIMIT and make the public analysis partial. For ForEach-Object -Parallel, the fixed companion binding must be tied to the exact loaded source and established before the parallel call. A matching assignment after the call is not proof that the call used that companion and must remain partial.

SC8 shipped-bytecode budget

The shipped-bytecode pass needs two independent limits: its five-second active-processing allowance and the enclosing workflow's monotonic wall deadline. Time spent waiting while sibling work proceeds must not consume the active-processing allowance. The workflow wall deadline remains a hard bound, and a standalone SC8 pass remains wall-clock bounded. Exhausting either bound records runtime_limit and leaves the scan incomplete; it must never turn skipped work into a clean result.

Related work and scope

Regression coverage

The candidate adds or extends checks for PowerShell literals and nested executable payloads, dynamic or unclosed PowerShell contexts, Markdown fence completeness and original line offsets, exact companion identity/order (including assignment-after-call), and SC8 active time versus workflow wall time. Depth, output, and CLI completeness reporting remain covered.

Please advise whether the PowerShell portion should follow PR #627, be added to #694, or remain a separate issue. The local candidate has not passed every contribution gate yet; its complete test and review results will be reported with a PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions