Skip to content

Security policy, and a comment reword that stops scanners flagging the leak detector - #1

Merged
prateekkathal merged 1 commit into
mainfrom
chore/security-policy-and-scanner-false-positive
Sep 20, 2026
Merged

prateekkathal merged 1 commit into
mainfrom
chore/security-policy-and-scanner-false-positive

Conversation

@prateekkathal

@prateekkathal prateekkathal commented Sep 20, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds a security policy to the repository and rewords one comment in the leak detector so generic scanners stop reporting it as a hardcoded secret. Both came out of submitting the plugin to awesome-ai-plugins, whose PR gate runs the HOL plugin scanner against this repository.

Changes

  • SECURITY.md — private reporting via GitHub's Security tab, latest-version-only support, and an explicit scope. In scope: anything that sends prompt text outside the documented paths, defeats redaction, leaks text under metadata-only, or lets the hook block or erase what a developer typed. Out of scope and stated as such: TypeSafe API issues, the absent lockfile, and scanner matches on the leak detector's own descriptions of the patterns it looks for.
  • scripts/check-leaks.mjs — the comment explaining the SCREAMING_SNAKE_CASE exclusion showed an apiKey assignment as a literal. Scanners match the literal and flag the line. It now says the same thing in prose.

Notes

  • No behaviour change. dist/ is untouched, so the plugin version and .claude-plugin/plugin.json are deliberately unchanged.
  • npm test (build, lint, format check, unit tests, leak scan) and npm run typecheck both pass; the leak scan runs clean over 65 tracked files.
  • Scanner score on a clean clone goes from 80/100 with one high finding to 95/100 with none. The one remaining finding is the missing lockfile at medium severity, which is intentional and is now documented as out of scope rather than silenced.
  • Private vulnerability reporting needs enabling in the repository's settings for the reporting route in SECURITY.md to work — worth doing before merge.

Summary by CodeRabbit

  • Documentation

    • Added a security policy covering vulnerability reporting, response expectations, supported versions, data leakage, availability issues, prompt handling, network boundaries, redaction, and credential protection.
    • Clarified which security reports are in scope and which are excluded.
  • Chores

    • Clarified secret-scanning guidance to reduce false-positive results without changing runtime behavior.

SECURITY.md was missing. It states where to report privately, what the
plugin promises (nothing leaves the machine undocumented; the hook cannot
cost the user their work), and what is deliberately out of scope - notably
the absent lockfile, which exists so Claude Code does not install the build
toolchain into every user's plugin cache.

The leak detector explained SCREAMING_SNAKE_CASE exclusion by showing an
apiKey assignment as a literal. Generic scanners match that literal and
report the line as a hardcoded secret - the HOL scanner scored the repo
80/100 on it while submitting to awesome-ai-plugins. The comment now says
the same thing in prose. No behaviour change: dist/ is untouched, so the
plugin version is unchanged.
@prateekkathal prateekkathal self-assigned this Sep 20, 2026
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Essentials

Run ID: 2aa663c2-036d-45fb-9b33-7a615bd6d090

📥 Commits

Reviewing files that changed from the base of the PR and between ad487f4 and 4620e87.

📒 Files selected for processing (2)
  • SECURITY.md
  • scripts/check-leaks.mjs

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The pull request adds a security policy and clarifies an API key scanner comment. It does not alter exported declarations or runtime behavior.

Changes

Security updates

Layer / File(s) Summary
Security policy
SECURITY.md
Adds vulnerability-reporting procedures, support and scope boundaries, prompt handling guarantees, network restrictions, redaction behavior, and scanning requirements.
Leak scanner clarification
scripts/check-leaks.mjs
Explains that TYPESAFE_API_KEY is a variable name and avoids a scanner false positive. Runtime behavior is unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately identifies both main changes: the security policy and the scanner-related comment reword. It is specific and concise enough for a pull request title.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@prateekkathal
prateekkathal merged commit ff5ad68 into main Sep 20, 2026
4 checks passed
@prateekkathal
prateekkathal deleted the chore/security-policy-and-scanner-false-positive branch September 20, 2026 00:19
prateekkathal added a commit to prateekkathal/awesome-ai-plugins that referenced this pull request Sep 20, 2026
CrowdLinker/JevPromptCoach#1 has landed on main: the high-severity
hardcoded-secret finding was a match on a comment in the plugin's own leak
detector, and SECURITY.md is now present. Empty commit so the sweep rescans
the source repository; the catalog entry is unchanged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant