Skip to content

Describe build-time inputs as first-party to clear Snyk W011 - #80

Merged
travist merged 1 commit into
mainfrom
resolve-skills-warnings
Sep 29, 2026
Merged

travist merged 1 commit into
mainfrom
resolve-skills-warnings

Conversation

@travist

@travist travist commented Sep 29, 2026

Copy link
Copy Markdown
Member

Summary

skills.sh's Snyk scan still flags formio-angular, formio-application, and formio-sdk with W011 (third-party content exposure) after the Sep 9 remediation. formio-form cleared the same finding once its docs stated that the application fetches at runtime and the agent does not. The remaining findings quote the skills' own trust prose back as evidence of outsider content — e.g. Snyk's "outsider-authored free text" matches formio-angular calling the planner pair "the largest untrusted input this skill has… from a clone, a download".

This change restates what each skill reads at build time as the first-party input it is. No rule is removed and no capability is narrowed.

  • formio-angular — the planner-artifacts section names the pair as the pipeline's own artifact (written by formio-resource-planner, approved at Phase A) and says the skill reads the two files the handoff names. The first-party, data-not-instructions, and shape-check rules are unchanged. (formio-react states the same rules without the outsider framing and passes.)
  • formio-sdk — the last Security rule no longer tells the agent it reads "submission JSON … returned by any MCP tool". It states the true boundary: the MCP tools return project configuration and no submission data; the documented SDK calls are code the application runs at runtime.
  • formio-application — Step 1 names its first-party inputs (the user's own words, the user's own workspace, the planner pair produced from them) and states it fetches no web page, reads no submission data, and opens no third-party file.

Changeset: .changeset/first-party-inputs.md (@formio/ai patch).

Not changed

The Agent Trust Hub MEDIUM on formio-sdk (dynamic execution, indirect injection, external packages) and the two Socket LOWs on utils-evaluator.md / utils-logic.md describe capabilities the skill exists to document. Each finding already cites the skill's own mitigation, so they are accepted as residual.

Follow-up

A separate OpenSpec change will add agent-scoped submission tools (signed metadata tag, per-working-directory scope) for seeding select-dropdown resources and test data. That work will revise the "no submission data" wording introduced here to "only submissions this server created".

Test plan

  • New assertions written first and confirmed failing: security-section.test.ts, application-orchestration.test.ts, planner-artifact-trust.test.ts
  • pnpm test: 1073 skill-tests + 1110 mcp-server tests pass
  • pnpm lint passes
  • pnpm format leaves no changes
  • Re-check the skills.sh Snyk pages for the three skills after the release re-scan (the scanners are model-based, so clearing is not guaranteed)

🤖 Generated with Claude Code

… W011

skills.sh's Snyk scan still flagged formio-angular, formio-application, and
formio-sdk with W011 (third-party content exposure) after the Sep 9 pass.
formio-form cleared the same finding once its docs said the application
fetches at runtime and the agent does not; the remaining findings quote the
skills' own prose describing the agent as ingesting outsider content.

- formio-angular: the planner-artifacts section no longer calls the pair
  "the largest untrusted input" arriving "from a clone, a download"; it
  names the pair as the pipeline's own artifact, read by the two paths the
  handoff names. The first-party, data-not-instructions, and shape-check
  rules are unchanged.
- formio-sdk: the last Security rule states that the MCP tools return
  project configuration and no submission data, and that the documented SDK
  calls are code the application runs at runtime.
- formio-application: Step 1 names its first-party inputs and states it
  fetches no web page, reads no submission data, and opens no third-party
  file.

Tests lock each statement. Agent Trust Hub and Socket residuals on
formio-sdk document capabilities the skill exists to describe and are left
as accepted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@travist
travist merged commit ebd8ceb into main Sep 29, 2026
1 check passed
travist added a commit that referenced this pull request Oct 4, 2026
…on Packages PR (#87)

A push with pending changesets publishes nothing: changesets/action opens or
updates the Version Packages PR instead. To build it the action checks out
`changeset-release/main` and bumps the versions in the working tree, and leaves
the tree there. "Resolve the released @formio/mcp version" then read
packages/mcp-server/package.json from that tree, got the next, unpublished
version, polled npm for ten minutes and failed the job. #86's run did exactly
that for @formio/mcp@0.14.1. #80's run passed only because its changeset
bumped @formio/ai alone, leaving the server version unchanged.

- The lookup runs only when `steps.changesets.outputs['has-changesets']` is
  not 'true'. v2 of the action names the output in kebab-case. Every step
  downstream is already gated on the lookup's version output, so a version run
  skips them too.
- The version and mcpName are read from the pushed commit with
  `git show "${GITHUB_SHA}:packages/mcp-server/package.json"`, never from the
  working tree the action leaves behind.
- release-waits-for-npm.test.ts pins both.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant