安全决策报告

backlog

The skill has documented allowed-tools declarations but contains undeclared kubectl/K3s pod execution capabilities that inject base64-encoded Python into Plane's API pod via django-shell, representing significant shadow functionality not covered in SKILL.md.

安装决策优先 来源: ClawHub 扫描时间: 17 小时前
文件 25
IOC 22
越权项 4
发现 6
最直接的威胁证据
高危 文档欺骗
Undeclared K3s/kubectl shell execution

SKILL.md declares 'Bash(python3:*)' only, but plane_create_issue.py and plane_create_entity.py contain create_via_k3s_fallback() which executes kubectl exec to run Python code inside Plane API pods via django-shell. This is shell:ADMIN equivalent access to the Plane infrastructure.

scripts/plane_create_issue.py:303

为什么得出这个结论

2/4 个维度触发
阻止
声明与实际能力

发现 4 项声明之外的能力或越权行为。

复核
隐藏执行与外联

提取到 22 个一般风险产物,需要结合上下文判断。

阻止
攻击链与高危发现

报告包含 0 步攻击链,另有 2 项高危或严重发现。

通过
依赖与供应链卫生

依赖结构存在,但暂未看到明显高危告警。

风险分是怎么被拉高的

Undeclared K3s/kubectl execution +20

SKILL.md declares only Bash(python3:*) but code uses kubectl exec to inject Python into Plane pods — shell:ADMIN equivalent not declared

Base64-encoded script injection +15

Python scripts are base64-encoded and executed inside K8s pods via django-shell; obfuscation vector not documented

Hardcoded Windows paths +10

intake.py and prune_p2p3.py contain hardcoded C:\Users paths exposing system configuration

最关键的证据

高危 文档欺骗

Undeclared K3s/kubectl shell execution

SKILL.md declares 'Bash(python3:*)' only, but plane_create_issue.py and plane_create_entity.py contain create_via_k3s_fallback() which executes kubectl exec to run Python code inside Plane API pods via django-shell. This is shell:ADMIN equivalent access to the Plane infrastructure.

scripts/plane_create_issue.py:303
Declare shell:ADMIN capability and document the K3s fallback mechanism with clear scope boundaries.
高危 代码混淆

Base64-encoded Python injection into K8s pods

The K3s fallback builds Python scripts via f-strings then base64-encodes them before execution via kubectl exec django-shell. This pattern matches high-risk indicator behavior even though the injected code is benign.

scripts/plane_create_issue.py:269
Document base64 usage or consider alternative approaches that don't match obfuscation signatures.
中危 敏感访问

Hardcoded Windows paths leak system configuration

intake.py DEFAULT_FIX_PLAN and prune_p2p3.py target file candidates contain hardcoded C:\Users paths (DAEGUNSOFT) revealing usernames, home directory structure, and development tooling preferences.

scripts/intake.py:22
Remove hardcoded paths; use only environment variables or CLI arguments for file paths.
中危 权限提升

K3s defaults target wrong namespace across clusters

K3s fallback defaults k3s_namespace to 'plane-ce' and workload to 'deploy/plane-api-wl', but the comments admit this is wrong for es6.kr cluster. Missing per-workspace config silently fails or targets wrong deployment.

scripts/plane_create_issue.py:296
Fail loudly if k3s_namespace/k3s_workload are not explicitly configured rather than using wrong defaults.
中危 凭证窃取

Windows registry credential access

intake.py get_api_key() reads DGS_PLANE_API_KEY from Windows registry HKEY_CURRENT_USER\Environment if not in environment variables. Registry access for credentials not declared in SKILL.md.

scripts/intake.py:38
Document credential retrieval from Windows registry or deprecate this fallback in favor of standard environment variable access.
低危 文档欺骗

SKILL.md does not document Plane integration

SKILL.md describes the skill as 'vendor-agnostic' with 'abstract Receiver Contracts', but the actual implementation hardcodes plane.dgs.ai.kr URLs and workspace names. This creates a misleading impression of flexibility.

SKILL.md:62
Document the actual Plane vendor lock-in or make integration truly configurable.

声明能力 vs 实际能力

文件系统 通过
声明 WRITE
→
推断 WRITE
SKILL.md declares Write tool; code modifies fix_plan.md
网络访问 阻止
声明 READ
→
推断 WRITE
plane_create_issue.py:289 - POST to intake API creates issues
命令执行 阻止
声明 WRITE
→
推断 ADMIN
plane_create_issue.py:303-307 - kubectl exec into K8s pods
环境变量 阻止
声明 NONE
→
推断 READ
plane_client.py:140 - reads PLANE_API_KEY, PLANE_HOST, PLANE_WORKSPACE
技能调用 通过
声明 NONE
→
推断 NONE
No skill invocation found
剪贴板 通过
声明 NONE
→
推断 NONE
No clipboard access
浏览器 通过
声明 NONE
→
推断 NONE
No browser automation
数据库 阻止
声明 NONE
→
推断 WRITE
plane_create_issue.py:303-307 - creates Issue records via Django ORM inside Plane pod

可疑产物与外联

中危 外部 URL
https://keepachangelog.com/en/1.0.0/

CHANGELOG.md:5

中危 外部 URL
https://semver.org/spec/v2.0.0.html

CHANGELOG.md:6

中危 外部 URL
https://plane.es6.kr/es6kr/projects/

comment.md:47

中危 外部 URL
https://plane.dgs.ai.kr/dgs/projects/

create.md:109

中危 外部 URL
https://plane.dgs.ai.kr/dgs/browse/

create.md:109

中危 外部 URL
https://plane.dgs.ai.kr/dgs/browse/INFRA-77

create.md:110

中危 外部 URL
https://plane.dgs.ai.kr/api/v1/workspaces/dgs

scripts/intake.py:21

中危 外部 URL
https://plane.dgs.ai.kr/dgs/browse/ES6KR-128

scripts/plane_verify_identifier.py:15

中危 外部 URL
https://plane.dgs.ai.kr

scripts/test_plane_client_browse_url.py:28

中危 外部 URL
https://plane.dgs.ai.kr/dgs/browse/INFRA-62

scripts/test_plane_client_browse_url.py:39

中危 外部 URL
https://plane.example.com

scripts/test_plane_client_intake.py:27

中危 外部 URL
https://plane.dgs.ai.kr/dgs/browse/AIAUTO-176

scripts/test_plane_create_issue_browse_url.py:104

依赖与供应链

包名版本来源漏洞备注
urllib stdlib Python standard library 否 Standard library only, no external dependencies
json stdlib Python standard library 否 Standard library only
subprocess stdlib Python standard library 否 Used for kubectl exec - legitimate K8s tool integration

文件构成

25 个文件 · 6146 行
Python 17 个文件 · 5635 行Markdown 6 个文件 · 485 行Other 1 个文件 · 21 行JSON 1 个文件 · 5 行
需关注文件 · 4
scripts/plane_create_issue.py Python · 709 行
Undeclared K3s/kubectl shell execution · Base64-encoded Python injection into K8s pods · K3s defaults target wrong namespace across clusters
scripts/test_plane_sync.py Python · 513 行
https://plane.example.com/myworkspace/projects/ · http://plane.example.com · https://evil.example
scripts/intake.py Python · 327 行
Hardcoded Windows paths leak system configuration · Windows registry credential access · https://plane.dgs.ai.kr/api/v1/workspaces/dgs
create.md Markdown · 110 行
https://plane.dgs.ai.kr/dgs/projects/ · https://plane.dgs.ai.kr/dgs/browse/ · https://plane.dgs.ai.kr/dgs/browse/INFRA-77
其他文件 · plane_create_entity.py · plane_sync.py · plane_client.py · plane_update_entity.py · plane_bulk_update.py · prune_p2p3.py +2

安全亮点

HTTPS enforcement in plane_create_issue.py refuses non-HTTPS hosts (CWE-319)
Redirect protection via add_unredirected_header prevents credential forwarding to attacker-controlled hosts
Non-HTTPS check in plane_sync.py make_plane_request() with explicit error message
_NoRedirect handler in plane_sync.py blocks redirect-based credential theft
Idempotency guards prevent duplicate issue creation
Comprehensive error handling with specific error messages
Rate limiting with HTTP 429 backoff protects against API abuse
Dry-run modes in sync and prune operations allow safe preview