Skip to content

Suspicious commands are routing via secrets pipeline #1038

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
lukehinds opened this issue Feb 13, 2025 · 3 comments · Fixed by #1151
Closed

Suspicious commands are routing via secrets pipeline #1038

lukehinds opened this issue Feb 13, 2025 · 3 comments · Fixed by #1151
Assignees
Labels

Comments

@lukehinds
Copy link
Contributor

Describe the issue

Whenever a suspicious command is discovered, CodeGate alerts it as a secret, it should have its own messsage?

Image

Steps to Reproduce

Use launchctl load -w /System/Library/LaunchDaemons/com.hidden.daemon.plist in a prompt

Operating System

Microsoft Windows (Intel)

IDE and Version

N/A

Extension and Version

N/A

Provider

Anthropic

Model

N/A

Codegate version

0.1.19 / main

Logs

No response

Additional Context

No response

@jhrozek
Copy link
Contributor

jhrozek commented Feb 17, 2025

Move to backlog, we should discuss whether we want all snippets to be evaluated or just those that are executed by tools @therealnb @poppysec @lukehinds

@therealnb
Copy link
Contributor

I didn't see your previous comment. Been working on other things.

I made #1151 which seems to improve things a lot. We can discuss whether or not to merge.

@therealnb
Copy link
Contributor

@jhrozek @lukehinds - this got merged. It is probably ok for a trial, but not super accurate yet. Let me know if you think I should disable this again...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants