Repository navigation
ci(claude-review): pin the gh pr allows to the reviewed pull request - #1004
Conversation
The Bash(gh pr diff:*), view and comment allows matched any pull request number, so a prompt injection in a reviewed diff could read another pull request or comment on it with the job's pull-requests: write token; the prompt telling Claude not to was the only boundary. Name github.event.pull_request.number in each rule. The :* suffix matches at a word boundary, so 97 does not admit 974, and each part of a compound command is checked separately.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Reviewed commit f652d33; no actionable issues found. |
Summary
The Claude pull-request review (added in #974) lets Claude run three shell commands:
gh pr diff,gh pr viewandgh pr comment. The allow rules accepted any pull request number, so text planted in a reviewed diff could trick Claude into reading another pull request in this repository, or commenting on one, using the job'spull-requests: writetoken. Only the prompt said not to. This pins each rule to the number of the pull request being reviewed, so the tool permissions enforce that limit instead of the prompt.Changes
.github/workflows/claude-review.yml:Bash(gh pr diff:*)becomesBash(gh pr diff ${{ github.event.pull_request.number }}:*), and the same forviewandcomment; the comment explains the scoping.scripts/__tests__/claude-review-workflow.test.mjs: the exact-args assertion expects the pinned rules.Verification
vitest run --config scripts/vitest.config.mjsonclaude-review-workflow.test.mjsandworkflow-publish-permissions.test.mjs: 26 passed. The fullscripts/__tests__suite (54 files) passed on the same change on top of the Add federated Claude PR review #974 branch.:*suffix is equivalent to a trailing*, which requires a space after the prefix, sogh pr diff 97:*does not matchgh pr diff 974; each part of a compound command (&&,;,|) must match a rule on its own.gh pr diff/gh pr commentinvocations are allowed in practice.Related
Refs #974
Review notes
No changeset: CI workflow and repo test only, nothing published.