Skip to content
This repository was archived by the owner on Oct 4, 2026. It is now read-only.

feat: implement security hardening (env sanitization, sh-c bypass, resource limits) - #83

Merged
zenyr merged 3 commits into
feature/security-hardeningfrom
feature/security-hardening-env-sanitization
Oct 25, 2025
Merged

zenyr merged 3 commits into
feature/security-hardeningfrom
feature/security-hardening-env-sanitization

Conversation

@zenyr

@zenyr zenyr commented Oct 25, 2025 •

Copy link
Copy Markdown
Owner

Summary

Implemented comprehensive security hardening measures for the MCP PTY system to prevent various attack vectors and resource exhaustion scenarios.

Changes Made

Environment Variable Sanitization

  • Added sanitization to remove dangerous environment variables like `LD_PRELOAD`, `DYLD_INSERT_LIBRARIES`, etc.
  • Applied to all PTY spawn operations to prevent library injection attacks

Sh -c Bypass Prevention

  • Enhanced command validation with recursive AST parsing for `sh -c` arguments
  • Prevents bypass attacks like `sh -c "rm -rf /"`

Resource Limits

  • PTY Count Limit: Maximum 10 PTYs per session to prevent resource exhaustion
  • Execution Timeout: Activity-based timeout for PTY processes to prevent hanging

Testing

  • Added comprehensive tests for all security features
  • All tests pass with proper validation

Impact

  • Security: Prevents environment injection, command bypass, and DoS attacks
  • Stability: Limits resource usage to maintain system stability
  • Compatibility: Backward compatible security enhancements

AgentLog

See docs/agentlogs/032-security-hardening-implementation.md

Agent Identity: Grok Code Fast 1

zenyr added 2 commits October 25, 2025 19:57
…source limits)

- Add environment variable sanitization to remove dangerous vars (LD_PRELOAD, etc.)
- Implement recursive AST validation for sh -c arguments to prevent bypass attacks
- Add PTY count limit per session (10 max) to prevent resource exhaustion
- Add execution timeout for PTY processes with activity-based reset
- Add comprehensive tests for all security features
- Add comprehensive agentlog documenting all security measures
- Minor style fixes: import reordering, test cleanup
@zenyr
zenyr changed the base branch from develop to feature/security-hardening October 25, 2025 10:59
@zenyr

zenyr commented Oct 25, 2025

Copy link
Copy Markdown
Owner Author

Agent: Claude Sonnet 4.5

PATH removal breaks basic shell functionality. All commands (ls, git, echo) require absolute paths without PATH, defeating PTY's purpose.

Recommendation: Remove PATH from DANGEROUS_ENV_VARS. Command validation via validateCommandAST already blocks malicious patterns. Keep other 8 vars (LD_PRELOAD, DYLD_*, PYTHONPATH, etc.) for library injection protection.

- "CLASSPATH", // Java
- "PATH", // Potentially dangerous if manipulated
+ "CLASSPATH",

If PATH manipulation is a concern, add validation logic instead of blanket removal.

- Remove PATH from DANGEROUS_ENV_VARS as it breaks basic commands like ls
- Rely on existing validateCommandAST for security instead
- Maintains usability while preventing library injection attacks
@zenyr
zenyr merged commit 4638008 into feature/security-hardening Oct 25, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant