Skip to content

security audit findings and fixes - #2

Merged
sharma-open-source merged 2 commits into
mainfrom
random-test
Jun 26, 2026
Merged

sharma-open-source merged 2 commits into
mainfrom
random-test

Conversation

@sharma-open-source

Copy link
Copy Markdown
Owner

No description provided.

- Added Morse code decoding in the normalization process to prevent whitespace collapse from merging words.
- Implemented visible split-token de-obfuscation to reconstruct keywords split by visible characters, improving detection accuracy.
- Introduced a new function to detect split base64/hex blobs across whitespace, enhancing security against encoded payloads.
- Expanded exfiltration detection to include various URL-bearing channels, improving the robustness of the guard against data leaks.
- Updated the confusables table to include missing Cyrillic and Greek characters, addressing critical bypass vulnerabilities.
- Added tests to validate the new features and ensure existing functionality remains intact.
- Created a SECURITY-AUDIT.md file documenting the security audit findings and proposed solutions for identified vulnerabilities.
@sharma-open-source
sharma-open-source merged commit 08a765a into main Jun 26, 2026
7 checks passed
@sharma-open-source
sharma-open-source deleted the random-test branch June 26, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant