Detector લાઇબ્રેરીRepository config execution

Repository config execution

Checkout એક program નું નામ આપે છે.

સામાન્ય tool call પાછળ છુપાઈ શકે એવી executable configuration શોધો.

સમસ્યા જુઓ. Finding સમજો.

કૅપ્શન સાથે અંગ્રેજી વર્ણન.

તે કઈ રીતે અવગણાઈ જાય છે

Agent સામાન્ય development command ચલાવે છે. પણ repository configuration પોતાના code તરફ નિર્દેશ કરે છે. માત્ર દૃશ્ય tool name સમીક્ષવાથી, નીચે જે થાય છે તે બદલતી configuration ચૂકી શકાય.

Checkout Git ને working tree ના hooks તરફ, command-valued settings configure કરવા, અથવા folder ખોલ્યે run થતા editor tasks configure કરી શકે. Workspace ને source code ના passive collection ગણો તે પહેલાં આ files સમીક્ષ લાયક છે.

ClawMetry શું detect કરે છે

ClawMetry supported workspace configuration ને execution-related settings માટે scan કરે છે. noise ઘટાડવા known good command shapes ઉપયોગ કરીને, relevant key અથવા configuration source report કરે છે. આ detector checkout ખુદ વાંચે છે, agent tool stream પર આધાર ન રાખી.

Finding બદલી નાખતો તફાવત

Triggering ઉદાહરણ

hooksPath = .githooks

Critical તારણ

Quiet સરખામણી

Default .git/hooks path

આ detector માટે કોઈ finding નહીં.

ચકાસાયેલ ઉદાહરણ Git hooks ને working tree માં shipped directory તરફ નિર્દેશ કરે છે અને critical finding ઉત્પન્ન કરે છે. Default Git hooks directory તરફ hooks path શાંત રહે છે. Finding configuration ઓળખે છે, recorded execution નહીં.

Detector result તપાસો
{
  "kind": "repo_config_exec",
  "severity": "critical",
  "evidence": {
    "keys": [
      "core.hookspath"
    ],
    "hits": [
      {
        "key": "core.hookspath",
        "command": ".githooks",
        "line": 2,
        "manager": null
      }
    ],
    "config": ".git/config",
    "observed": "repository_config"
  }
}
Inputs અને સંપૂર્ણ results ડાઉનલોડ કરો (JSON)
ઉદાહરણ કઈ રીતે તપાસ્યું

આ ઉદાહરણો authored event data અથવા disposable configuration files સાથે published detector નું મૂલ્યાંકન કરે છે. Videos તે behaviors દર્શાવે છે. તે live agents અથવા product interface ના recordings નથી. ઉદાહરણોમાં કોઈ command execute કરવામાં આવ્યો ન હતો.

Result આ inputs માટે behavior સ્થાપિત કરે છે. તે runtime ingestion, prevention અથવા real compromise સ્થાપિત કરતું નથી. Pinned source contract તપાસો.

આગળ શું તપાસવું

Setting, referenced files અને checkout ના origin ની તપાસ કરો. સામાન્ય development operations ચાલુ કરતા પહેલા, આ programs અપેક્ષિત છે કે નહીં નક્કી કરો. જો tool પહેલેથી ચાલ્યો હોય, machine પર ઉપલબ્ધ પુરાવા ઉપયોગ કરી અલગ તેની અસરો તપાસો.

  1. config key તપાસો
  2. referenced code સમીક્ષો
  3. repository origin ચકાસો

આ signal શું સ્થાપિત કરે છે

Scanner configuration report કરે છે, execution નહીં. Configured program ચાલ્યો હતો અથવા author ને harm ઇરાદો હતો તે સાબિત કરતો નથી.

મહત્વના ક્ષણો દૃશ્યમાન રાખો.

Agent પ્રવૃત્તિ follow કરો, findings તપાસો અને નક્કી કરો કે શું તમારું ધ્યાન જોઈએ.