ci: add HOL plugin scanner workflow - #80
Merged
Merged
Conversation
Runs the scanner used by the awesome-ai-plugins catalog on push and pull request. Read-only, no secrets, both actions pinned to commit SHAs, fails below a score of 80 or on any high severity finding.
Clears every finding the HOL plugin scanner raised, which the awesome-ai-plugins catalog requires to pass at 80 or above with no high severity findings before a listing can merge. Pin every third-party action to a commit SHA, staying within the major version already in use, so a moved tag cannot change what runs in the publish workflow. Dependabot now tracks those pins monthly. release-smoke.yml took the version to test from the workflow_run head branch, which is attacker-influenceable input read in a privileged context. It reads the version from the checked-out default branch instead, with the existing PyPI lookup still as the fallback. The local OpenAI-compatible test used a literal that reads as secret material to credential scanners. It is a fake key asserted against a fake server, so renaming it costs nothing. Add SECURITY.md with private advisory reporting and a scope section covering credential handling, prompt injection from crawled pages and the MCP server spending cap and robots.txt refusals.
The credential scanner matches an api_key assigned a string literal regardless of the value, so the fake key used against the fake server is bound to a local and interpolated into the assertion instead.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the HOL plugin scanner that the awesome-ai-plugins catalog uses as its preflight, ahead of submitting DataForge to that catalog.
The catalog runs its own centralized scan on every listed repository, so this workflow is not required for listing. Maintaining it earns the full registry trust score instead of a 10 percent reduction, and keeps the MCP server continuously checked for committed secrets, dangerous command execution, overly broad Actions permissions and unpinned dependencies.
Configuration follows their published guide exactly:
contents: readonly, no repository secrets,persist-credentials: falseMerging this lets us read the first score before the catalog submission goes out.