[Security Review] Daily Security Review — 2026-06-05 #4373
Closed
Replies: 2 comments
|
🔮 The ancient spirits stir, and the smoke test agent has passed through this discussion, leaving a brief omen of presence. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "registry.npmjs.org"See Network Configuration for more information.
|
0 replies
|
This discussion was automatically closed because it expired on 2026-06-12T13:29:48.338Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Context
24273493151concludedsuccesswith a noop — agent ran fully but found no secrets to exfiltrate. Credential isolation held. ✅📊 Executive Summary
Security posture is strong overall. The layered defense-in-depth architecture (iptables DNAT + Squid ACL + capability separation + seccomp + one-shot-token) is working as intended. No critical vulnerabilities found. Four medium and four low findings identified.
--enable-dindonly)🔍 Escape Test Findings
The Secret Digger agent had full AI inference access (
GH_AW_INFERENCE_ACCESS_ERROR: false) and executed successfully, yet emitted only a noop — confirming:unset_sensitive_tokens()(entrypoint.sh:369) + one-shot-token LD_PRELOAD successfully clearedANTHROPIC_API_KEY,GITHUB_TOKEN, etc. from/proc/self/environworkDirprevented readingdocker-compose.ymlsecrets🛡️ Architecture Security Analysis
Network Security ✅ Strong
dstdomain/dstdom_regex). Proxy-unaware tools still caught by DNAT fallback.acl dst_ipv4/dst_ipv6 dstdom_regexblocks direct IP connections (config-generator.ts:124-127).sysctl net.ipv6.conf.all.disable_ipv6=1prevents Happy Eyeballs proxy bypass (setup-iptables.sh:47).Container Security ✅ Strong with caveats
NET_ADMIN. Theawf-iptables-initsidecar (shares network namespace) holds it temporarily, then exits.SYS_CHROOT+SYS_ADMINdropped viacapshbefore user code runs (entrypoint.sh:357).ptrace,process_vm_readv,process_vm_writev,kexec_load,init_module,add_keyall blocked.agent-service.ts:109) — needed for procfs mount, removes LSM layer.unshare+mountallowed in seccomp — see Finding M2.Domain Validation ✅ Strong
validateDomainOrPattern()rejects[\s\0"';#\]` — prevents Squid config injection.*→[a-zA-Z0-9.-]*(character class) — ReDoS-safe.*,*.*) explicitly rejected.--enable-dindmounts Docker socket — full host escape%{Host}>hand%runot JSON-escaped inconfig-generator.ts:97unshareallowed in seccomp; unprivileged user namespaces may re-acquireNET_ADMINunconfinedon agent;mountsyscall also allowed in seccompbrace-expansionCVE GHSA-jxxr-4gwj-5jf2 (CVSS 6.5, CWE-400)api-proxy-logs/,cli-proxy-logs/,mcp-logs/created with0o777(config-writer.ts:120-144)✅ Recommendations
🟠 High
H1 — Gate
--enable-dindwith explicit security acknowledgmentDocker socket mount (
agent-volumes/docker-socket.ts:27) provides full container escape. Add a runtime warning and consider requiring--i-understand-dind-is-unsafeflag.🟡 Medium
M1 — Fix audit JSONL injection (
config-generator.ts:97)%{Host}>hand%ruare embedded in JSON without escaping. Post-process JSONL with a sanitizer or switch to a format that's injection-safe. The code comment acknowledges this risk for User-Agent but applies equally to Host/URL.M2 — Review
unsharein seccomp (seccomp-profile.json)Block
unshareor verifykernel.unprivileged_userns_clone=0on all deployment hosts. Unprivileged user namespaces +unsharecan re-acquireNET_ADMINin a new network namespace.M3 — Create minimal AppArmor profile (
agent-service.ts:107)Replace
apparmor:unconfinedwith a profile that allows onlymount -t procand denies raw sockets, arbitrary device access, and capability manipulation.M4 — Update
brace-expansionRun
npm audit fixto upgrade past5.0.6.🔵 Low
L1 — Reduce log dir permissions from
0o777to0o755; use Docker volume ownership for container write access.L2 — Make IPv6 sysctl disable fatal when ip6tables is also unavailable.
L3 — Add Elasticsearch (9200/9300), Kafka (9092), etcd (2379/2380), LDAP (389/636) to
DANGEROUS_PORTS.L4 — Document one-shot-token + env unset layering in
docs/environment.mdto prevent future regression.📈 Security Metrics
All reactions