Repository navigation
Dev #6
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dev #6
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,15 +16,15 @@ Before ANY POST / PATCH / PUT / DELETE, you MUST do ALL of the following in your | |
|
|
||
| 1. **Check CLERK_SECRET_KEY** — verify it is set: | ||
| ```bash | ||
| echo $CLERK_SECRET_KEY | head -c 10 | ||
| [[ -n "${CLERK_SECRET_KEY:-}" ]] && echo "CLERK_SECRET_KEY is set" || echo "CLERK_SECRET_KEY is missing" | ||
| ``` | ||
| If empty, stop and ask the user. Do not proceed without a valid key. | ||
| If missing, stop and ask the user. Do not proceed without a valid key. | ||
|
|
||
| 2. **Check CLERK_BAPI_SCOPES** — run: | ||
| 2. **Check CLERK_BAPI_SCOPES (advisory only)** — this is informational only; direct curl requests are not enforced by the script. Write and delete operations use the privileges of CLERK_SECRET_KEY, not CLERK_BAPI_SCOPES. You may run this to inform the user of their current scopes: | ||
| ```bash | ||
| echo $CLERK_BAPI_SCOPES | ||
| echo "${CLERK_BAPI_SCOPES:-none}" | ||
| ``` | ||
| Inspect the output. If scopes are missing or do not include the required write permission, tell the user: *"This is a write operation and your current scopes may not allow it. Rerun with --admin to bypass?"* Do NOT attempt the request and fail — ask first. | ||
| CLERK_BAPI_SCOPES or --admin do not restrict API access through curl. | ||
|
|
||
| 3. **For DELETE requests:** warn explicitly that the action is **IRREVERSIBLE** and list exactly what data will be permanently destroyed (user record, all sessions, all memberships, all associated data). Require explicit confirmation before proceeding. This warning is MANDATORY — never skip it. | ||
|
|
||
|
|
@@ -119,7 +119,7 @@ await clerkClient.users.updateUser(userId, { | |
| ### List users (last 7 days) | ||
|
|
||
| ```bash | ||
| curl -s "https://api.clerk.com/v1/users?limit=100&offset=0&order_by=-created_at&created_at=gt:$(date -d '7 days ago' +%s 2>/dev/null || date -v-7d +%s)000" \ | ||
| curl -s "https://api.clerk.com/v1/users?limit=100&offset=0&order_by=-created_at&created_at_after=$(date -d '7 days ago' +%s 2>/dev/null || date -v-7d +%s)000" \ | ||
| -H "Authorization: Bearer $CLERK_SECRET_KEY" \ | ||
| | python3 -c " | ||
| import sys, json | ||
|
|
@@ -208,21 +208,21 @@ Returns: OrganizationInvitation object | |
|
|
||
| Template for GET requests: | ||
| ```bash | ||
| curl -s "https://api.clerk.com/v1${PATH}${QUERY_STRING}" \ | ||
| curl -s "https://api.clerk.com/v1${API_PATH}${QUERY_STRING}" \ | ||
| -H "Authorization: Bearer $CLERK_SECRET_KEY" | ||
| ``` | ||
|
|
||
| Template for POST/PATCH requests: | ||
| ```bash | ||
| curl -s -X ${METHOD} "https://api.clerk.com/v1${PATH}" \ | ||
| curl -s -X ${METHOD} "https://api.clerk.com/v1${API_PATH}" \ | ||
| -H "Authorization: Bearer $CLERK_SECRET_KEY" \ | ||
| -H "Content-Type: application/json" \ | ||
| -d '${BODY_JSON}' | ||
|
Comment on lines
215
to
220
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
for file in .agents/skills/clerk-backend-api/SKILL.md .claude/skills/clerk-backend-api/SKILL.md; do
echo "=== $file ==="
sed -n '208,224p' "$file"
echo "--- scope references ---"
sed -n '18,32p' "$file"
done
echo "=== shell expansion probe ==="
BODY_JSON='{"name":"example"}'
literal='-d '\''${BODY_JSON}'\'''
expanded="-d \"$BODY_JSON\""
printf 'single-quoted form: %s\n' "$literal"
printf 'double-quoted form: %s\n' "$expanded"Repository: CrAzI-code/Lingua-react-native Length of output: 3314 Use shell expansion for Change 🧰 Tools🪛 SkillSpector (2.5.1)[warning] 53: [E1] External Transmission: Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Remediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted. (Data Exfiltration (E1)) [warning] 53: [E1] External Transmission: Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Remediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted. (Data Exfiltration (E1)) [warning] 149: [E1] External Transmission: Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended. Remediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted. (Data Exfiltration (E1)) [error] 53: [SC2] External Script Fetching: Remote code is downloaded and executed. This bypasses code review and could introduce malicious code. Remediation: Avoid downloading and executing remote scripts. Use trusted packages from PyPI/npm. If remote fetch is required, verify checksums and use HTTPS. (Supply Chain (SC2)) [error] 403: [SC2] External Script Fetching: Remote code is downloaded and executed. This bypasses code review and could introduce malicious code. Remediation: Avoid downloading and executing remote scripts. Use trusted packages from PyPI/npm. If remote fetch is required, verify checksums and use HTTPS. (Supply Chain (SC2)) 📍 Affects 2 files
🤖 Prompt for AI Agents |
||
| ``` | ||
|
|
||
| Template for DELETE requests: | ||
| ```bash | ||
| curl -s -X DELETE "https://api.clerk.com/v1${PATH}" \ | ||
| curl -s -X DELETE "https://api.clerk.com/v1${API_PATH}" \ | ||
| -H "Authorization: Bearer $CLERK_SECRET_KEY" | ||
| ``` | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: CrAzI-code/Lingua-react-native
Length of output: 12360
🏁 Script executed:
Repository: CrAzI-code/Lingua-react-native
Length of output: 19049
🏁 Script executed:
Repository: CrAzI-code/Lingua-react-native
Length of output: 848
🏁 Script executed:
Repository: CrAzI-code/Lingua-react-native
Length of output: 712
Make scope enforcement consistent across both skill copies.
CLERK_BAPI_SCOPESis advisory for directcurl, but the Rules section,--admin,execute-request.sh, and evaluation 4 treat it as mandatory. Align these references in both files:.agents/skills/clerk-backend-api/SKILL.md.claude/skills/clerk-backend-api/SKILL.md🧰 Tools
🪛 SkillSpector (2.5.1)
[warning] 53: [E1] External Transmission: Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Remediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
(Data Exfiltration (E1))
[warning] 53: [E1] External Transmission: Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Remediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
(Data Exfiltration (E1))
[warning] 149: [E1] External Transmission: Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Remediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
(Data Exfiltration (E1))
[error] 53: [SC2] External Script Fetching: Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
Remediation: Avoid downloading and executing remote scripts. Use trusted packages from PyPI/npm. If remote fetch is required, verify checksums and use HTTPS.
(Supply Chain (SC2))
[error] 403: [SC2] External Script Fetching: Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
Remediation: Avoid downloading and executing remote scripts. Use trusted packages from PyPI/npm. If remote fetch is required, verify checksums and use HTTPS.
(Supply Chain (SC2))
📍 Affects 2 files
.agents/skills/clerk-backend-api/SKILL.md#L23-L27(this comment).claude/skills/clerk-backend-api/SKILL.md#L23-L27🤖 Prompt for AI Agents