Repository navigation
Describe build-time inputs as first-party to clear Snyk W011 - #80
Merged
Merged
Conversation
… W011 skills.sh's Snyk scan still flagged formio-angular, formio-application, and formio-sdk with W011 (third-party content exposure) after the Sep 9 pass. formio-form cleared the same finding once its docs said the application fetches at runtime and the agent does not; the remaining findings quote the skills' own prose describing the agent as ingesting outsider content. - formio-angular: the planner-artifacts section no longer calls the pair "the largest untrusted input" arriving "from a clone, a download"; it names the pair as the pipeline's own artifact, read by the two paths the handoff names. The first-party, data-not-instructions, and shape-check rules are unchanged. - formio-sdk: the last Security rule states that the MCP tools return project configuration and no submission data, and that the documented SDK calls are code the application runs at runtime. - formio-application: Step 1 names its first-party inputs and states it fetches no web page, reads no submission data, and opens no third-party file. Tests lock each statement. Agent Trust Hub and Socket residuals on formio-sdk document capabilities the skill exists to describe and are left as accepted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Sep 29, 2026
travist
added a commit
that referenced
this pull request
Oct 4, 2026
…on Packages PR (#87) A push with pending changesets publishes nothing: changesets/action opens or updates the Version Packages PR instead. To build it the action checks out `changeset-release/main` and bumps the versions in the working tree, and leaves the tree there. "Resolve the released @formio/mcp version" then read packages/mcp-server/package.json from that tree, got the next, unpublished version, polled npm for ten minutes and failed the job. #86's run did exactly that for @formio/mcp@0.14.1. #80's run passed only because its changeset bumped @formio/ai alone, leaving the server version unchanged. - The lookup runs only when `steps.changesets.outputs['has-changesets']` is not 'true'. v2 of the action names the output in kebab-case. Every step downstream is already gated on the lookup's version output, so a version run skips them too. - The version and mcpName are read from the pushed commit with `git show "${GITHUB_SHA}:packages/mcp-server/package.json"`, never from the working tree the action leaves behind. - release-waits-for-npm.test.ts pins both. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
skills.sh's Snyk scan still flags
formio-angular,formio-application, andformio-sdkwith W011 (third-party content exposure) after the Sep 9 remediation.formio-formcleared the same finding once its docs stated that the application fetches at runtime and the agent does not. The remaining findings quote the skills' own trust prose back as evidence of outsider content — e.g. Snyk's "outsider-authored free text" matchesformio-angularcalling the planner pair "the largest untrusted input this skill has… from a clone, a download".This change restates what each skill reads at build time as the first-party input it is. No rule is removed and no capability is narrowed.
formio-angular— the planner-artifacts section names the pair as the pipeline's own artifact (written byformio-resource-planner, approved at Phase A) and says the skill reads the two files the handoff names. The first-party, data-not-instructions, and shape-check rules are unchanged. (formio-reactstates the same rules without the outsider framing and passes.)formio-sdk— the last Security rule no longer tells the agent it reads "submission JSON … returned by any MCP tool". It states the true boundary: the MCP tools return project configuration and no submission data; the documented SDK calls are code the application runs at runtime.formio-application— Step 1 names its first-party inputs (the user's own words, the user's own workspace, the planner pair produced from them) and states it fetches no web page, reads no submission data, and opens no third-party file.Changeset:
.changeset/first-party-inputs.md(@formio/aipatch).Not changed
The Agent Trust Hub MEDIUM on
formio-sdk(dynamic execution, indirect injection, external packages) and the two Socket LOWs onutils-evaluator.md/utils-logic.mddescribe capabilities the skill exists to document. Each finding already cites the skill's own mitigation, so they are accepted as residual.Follow-up
A separate OpenSpec change will add agent-scoped submission tools (signed
metadatatag, per-working-directory scope) for seeding select-dropdown resources and test data. That work will revise the "no submission data" wording introduced here to "only submissions this server created".Test plan
security-section.test.ts,application-orchestration.test.ts,planner-artifact-trust.test.tspnpm test: 1073 skill-tests + 1110 mcp-server tests passpnpm lintpassespnpm formatleaves no changes🤖 Generated with Claude Code