Skip to content

Harden rules, add false-positive corpus, sync docs to the live run - #3

Merged
karanb192 merged 3 commits into
mainfrom
hardening
Oct 3, 2026
Merged

karanb192 merged 3 commits into
mainfrom
hardening

Conversation

@karanb192

@karanb192 karanb192 commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • hooks/rules.ts: a private-key-truncated rule for PEM blocks pasted without their END line; the full-block PEM cap raised from 16384 to 65536 body characters; a bounded base64 decode pass in scan() that reports a prefix-shaped token wrapped in base64 as one hit with a -base64 id; keyword boundary, identifier, placeholder and literal-escape guards on the generic rules; placeholder password slots dropped from db-connection-url. 24 secret rules and 7 PII rules.
  • tests/rules.test.ts: fixtures for every change (115 positives, 162 negatives), a full-block-beats-truncated test, a JWT-stays-jwt test, off with -base64 ids, a second 2 MB performance test. Kit: 65 pass, 0 fail.
  • tools/fp-corpus.mjs, tools/fp-corpus-results.md, tools/fp-corpus-labels.json: a reproducible scan of 11 public repositories at pinned commits (42,836 text files); every secret-rule hit labelled by hand. Result after the rule changes: 68 hits, 60 real test keys and vectors, 8 fixtures, 0 false positives.
  • hooks/register.ts: the redact: prefix is dropped from the mod's own log lines and command output, because the engine already prefixes the plugin name (the screen read redact: redact: hid ...).
  • README.md, plugins/redact/README.md, DECISIONS.md, RULES.md, site/index.html: the live interactive run (prompt echo with the placeholder, Write carrying the placeholder, the file on disk holding the real key), a per-surface proof table, precise limitations (the three host bookkeeping records stored as made, tool_use blocks not rewritable), the corpus section, the new rule counts, site tokens aligned to anthropic.com's live CSS, canonical and Open Graph meta tags on the site, and the 1280x640 preview image shipped as site/social-preview.png. Line counts in the README are drift-proof (about 130, under 100).

Details

The three misses and the false-positive causes came from an adversarial pass that reran the rules with Node on crafted inputs and on the public corpus. The engine puts tool_use blocks back as made, so that one is documented rather than fixed. The live run was driven in tmux against a logged-in isolated config; captures are quoted as text in the README with the fake key masked.

Test plan

  • claude plugin validate plugins/redact --strict (passed)
  • CLAUDE_CONFIG_DIR=<isolated> claude plugin test plugins/redact: 65 pass, 0 fail (passed)
  • tsc -p plugins/redact exit 0 (passed)
  • node tools/fp-corpus.mjs reproduces 68 hits, 0 false positives, 0 unreviewed (passed, 9 s with cached repos)

@karanb192
karanb192 merged commit ded05bf into main Oct 3, 2026
1 check passed
@karanb192
karanb192 deleted the hardening branch October 3, 2026 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant