Problem
From verification of #1 (P3 finding 17 — security reviewer):
Phase 5 PR body 用 unquoted heredoc:
PR_BODY=$(cat <<EOF
Refs #${N}
## Summary
{從 issue title + diagnosis 的 Strategy 摘要}
...
EOF
)
<<EOF(非 <<'EOF')讓 shell 對內容做 variable expansion + command substitution。目前 ${TITLE} / {...} placeholder 是註解性質沒實際插入,但若未來 maintainer 真的把 ${TITLE} 寫進 body,issue title 含 backticks (`rm -rf /`) 或 $(...) 就會 RCE。
Pre-existing — <<EOF 在 v2.40.0 之前就這樣寫;#1 verify 順手 catch。
Type
fix / security defensive (future-proofing)
Why P3 (latent)
- 目前 placeholder 是字面
{...} 不是 ${...},沒實際 expansion
- 但 placeholder 用法看起來像 template,maintainer 容易誤以為可以直接塞
${TITLE}
- 用 quoted heredoc 是純 win-win:預防誤用 + 標示 "這裡的
$ 是字面"
Recommendation
改成 quoted heredoc,然後在外面用 printf 或 envsubst 做 controlled substitution:
TEMPLATE=$(cat <<'EOF'
Refs #__N__
## Summary
__SUMMARY__
## Verification
6-AI cross-model verification PASS。詳見 issue #__N__ 的 Verify comment。
...
EOF
)
PR_BODY=$(echo "$TEMPLATE" | sed -e "s/__N__/$N/g" -e "s/__SUMMARY__/$(escape_sed "$SUMMARY")/g")
或繼續用 expansion-allowed heredoc 但加註釋警告未來 maintainer:
# WARNING: <<EOF (not <<'EOF') — variable expansion happens.
# DO NOT insert untrusted strings (e.g. issue titles) without sanitization.
PR_BODY=$(cat <<EOF
...
EOF
)
Source
Related: #1
Problem
Type
fix / security defensive (future-proofing)
Why P3 (latent)
{...}不是${...},沒實際 expansion${TITLE}$是字面"Recommendation
改成 quoted heredoc,然後在外面用
printf或envsubst做 controlled substitution:或繼續用 expansion-allowed heredoc 但加註釋警告未來 maintainer:
Source
98b7a71(idd-all: 增加 HITL(attended)模式 — direct-commit + 允許 sub-skill AskUserQuestion #1)Related: #1