Skip to content

ci: add HOL plugin scanner workflow - #80

Merged
ianktoo merged 4 commits into
masterfrom
ci/plugin-scanner
Sep 29, 2026
Merged

ianktoo merged 4 commits into
masterfrom
ci/plugin-scanner

Conversation

@ianktoo

@ianktoo ianktoo commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Adds the HOL plugin scanner that the awesome-ai-plugins catalog uses as its preflight, ahead of submitting DataForge to that catalog.

The catalog runs its own centralized scan on every listed repository, so this workflow is not required for listing. Maintaining it earns the full registry trust score instead of a 10 percent reduction, and keeps the MCP server continuously checked for committed secrets, dangerous command execution, overly broad Actions permissions and unpinned dependencies.

Configuration follows their published guide exactly:

  • triggers on push to master and on pull requests, which is what their validator looks for
  • contents: read only, no repository secrets, persist-credentials: false
  • both actions pinned to immutable commit SHAs rather than mutable tags
  • fails below a score of 80 or on any high severity finding
  • live network probing and SARIF upload stay disabled

Merging this lets us read the first score before the catalog submission goes out.

Runs the scanner used by the awesome-ai-plugins catalog on push and pull
request. Read-only, no secrets, both actions pinned to commit SHAs, fails
below a score of 80 or on any high severity finding.
Clears every finding the HOL plugin scanner raised, which the
awesome-ai-plugins catalog requires to pass at 80 or above with no high
severity findings before a listing can merge.

Pin every third-party action to a commit SHA, staying within the major
version already in use, so a moved tag cannot change what runs in the
publish workflow. Dependabot now tracks those pins monthly.

release-smoke.yml took the version to test from the workflow_run head
branch, which is attacker-influenceable input read in a privileged
context. It reads the version from the checked-out default branch
instead, with the existing PyPI lookup still as the fallback.

The local OpenAI-compatible test used a literal that reads as secret
material to credential scanners. It is a fake key asserted against a
fake server, so renaming it costs nothing.

Add SECURITY.md with private advisory reporting and a scope section
covering credential handling, prompt injection from crawled pages and
the MCP server spending cap and robots.txt refusals.
The credential scanner matches an api_key assigned a string literal
regardless of the value, so the fake key used against the fake server
is bound to a local and interpolated into the assertion instead.
@ianktoo
ianktoo merged commit dd0279b into master Sep 29, 2026
50 checks passed
@ianktoo
ianktoo deleted the ci/plugin-scanner branch September 29, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant