Security policy, and a comment reword that stops scanners flagging the leak detector - #1
Conversation
SECURITY.md was missing. It states where to report privately, what the plugin promises (nothing leaves the machine undocumented; the hook cannot cost the user their work), and what is deliberately out of scope - notably the absent lockfile, which exists so Claude Code does not install the build toolchain into every user's plugin cache. The leak detector explained SCREAMING_SNAKE_CASE exclusion by showing an apiKey assignment as a literal. Generic scanners match that literal and report the line as a hardcoded secret - the HOL scanner scored the repo 80/100 on it while submitting to awesome-ai-plugins. The comment now says the same thing in prose. No behaviour change: dist/ is untouched, so the plugin version is unchanged.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour. 📝 WalkthroughWalkthroughThe pull request adds a security policy and clarifies an API key scanner comment. It does not alter exported declarations or runtime behavior. ChangesSecurity updates
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Other 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
CrowdLinker/JevPromptCoach#1 has landed on main: the high-severity hardcoded-secret finding was a match on a comment in the plugin's own leak detector, and SECURITY.md is now present. Empty commit so the sweep rescans the source repository; the catalog entry is unchanged.
Summary
Adds a security policy to the repository and rewords one comment in the leak detector so generic scanners stop reporting it as a hardcoded secret. Both came out of submitting the plugin to awesome-ai-plugins, whose PR gate runs the HOL plugin scanner against this repository.
Changes
SECURITY.md— private reporting via GitHub's Security tab, latest-version-only support, and an explicit scope. In scope: anything that sends prompt text outside the documented paths, defeats redaction, leaks text under metadata-only, or lets the hook block or erase what a developer typed. Out of scope and stated as such: TypeSafe API issues, the absent lockfile, and scanner matches on the leak detector's own descriptions of the patterns it looks for.scripts/check-leaks.mjs— the comment explaining the SCREAMING_SNAKE_CASE exclusion showed an apiKey assignment as a literal. Scanners match the literal and flag the line. It now says the same thing in prose.Notes
dist/is untouched, so the plugin version and.claude-plugin/plugin.jsonare deliberately unchanged.npm test(build, lint, format check, unit tests, leak scan) andnpm run typecheckboth pass; the leak scan runs clean over 65 tracked files.SECURITY.mdto work — worth doing before merge.Summary by CodeRabbit
Documentation
Chores