Skip to content

fix(ingest): inspect unverified OMS bundle contents - #795

Open
yashrajp22 wants to merge 3 commits into
mainfrom
yashraj/scan-unverified-oms-content
Open

yashrajp22 wants to merge 3 commits into
mainfrom
yashraj/scan-unverified-oms-content

Conversation

@yashrajp22

Copy link
Copy Markdown
Collaborator

A skill could forge the shape of an OMS signature bundle and have the whole file excluded from analysis. Recognized bundles now stay in the raw, local, and provider-eligible inputs and follow normal component analysis. Encoded payload interpretation is explicitly marked partial, so an unverified bundle cannot produce a complete/SAFE result.

This change does not validate signatures or claim decoded-payload coverage. Existing base64 detection can now flag genuine OMS bundles too; their shape no longer grants a security exemption. In the sample corpus, those added signals move one previously CAUTION result to DO_NOT_INSTALL. This conservative behavior needs review before merging.

Validation: 728 related tests and Ruff checks passed. Source and a fresh installed wheel matched on forged-wrapper, encoded-only, and real-bundle samples. Both forged-bundle regressions fail with the original ingestion code. All 12 pinned corpus samples matched between source and wheel: five stayed unchanged, while seven OMS-bearing samples gained existing SC3 signals and partial coverage; no earlier findings disappeared. These runs were offline and did not contact an LLM provider.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant