Repository navigation
fix(core): prevent indirect prompt injection via build file modifications and untrusted flags - #29250
Conversation
…ions and untrusted flags
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
|
📊 PR Size: size/XL
|
Summary of ChangesHello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request introduces a robust security layer to mitigate indirect prompt injection attacks by tracking untrusted context and enforcing strict confirmation requirements for build-related operations. It adds mechanisms to detect untrusted shell flags and mandates user approval when modifying or executing build configuration files, significantly hardening the workspace against unauthorized modifications and command execution. Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here. Footnotes
|
There was a problem hiding this comment.
Code Review
This pull request introduces build file protection and untrusted context tracking to prevent unauthorized build modifications and command execution with untrusted flags. The reviewer provided critical feedback highlighting several security and architectural vulnerabilities: naive whitespace splitting and command parsing in findUntrustedFlags and isBuildOrTestCommand can be bypassed with quotes or prefixed environment variables; the policy engine's build file protection can be bypassed via MCP filesystem tools; and tracking modified build files using a module-level global Set violates repository rules against global state, risking race conditions in concurrent environments. The reviewer recommended using shell-quote and getCommandRoots for robust command parsing, expanding tool name matching to cover MCP tools, adopting a session-scoped WeakMap for tracking modified files, and suppressing persistent approval options in the UI when modified build files are detected.
Note: Security Review did not run due to the size of the PR.
…d configuration security
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces robust build file protection and untrusted command flag detection to enhance execution security. It adds utilities to identify build files and track untrusted context, ensuring that modifications to build configuration files or execution of commands with untrusted flags always require explicit user confirmation (downgrading to ASK_USER or DENY in non-interactive mode) and suppress persistent approvals. Additionally, it updates the CLI UI to display critical security warnings and prevent truncation of build file diffs. A high-severity issue was identified in packages/core/src/tools/shell.ts where getModifiedBuildFiles() is called without passing the session key (this.context.config), which would cause it to default to the global session key and fail to retrieve modified build files recorded with the active configuration.
Note: Security Review did not run due to the size of the PR.
|
/gemini review |
1 similar comment
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces robust build file protection and untrusted command flag detection mechanisms to prevent malicious code execution. It adds utilities to identify build files and track untrusted context, updates the policy engine to require user confirmation for build file modifications, and enhances the CLI confirmation UI with critical security warnings. The review identified two critical issues: first, getModifiedBuildFiles in the shell tool is called without the session key, causing it to return an empty array and bypass the build file caution warning; second, applyShellHeuristics in the policy engine is missing the shellDirPath argument, which bypasses workspace boundary checks.
Note: Security Review did not run due to the size of the PR.
There was a problem hiding this comment.
Code Review
This pull request introduces robust security features, including Build File Protection and Untrusted Command Flags Detection, to prevent unauthorized modifications to build configurations and execution of untrusted commands. It adds utilities to identify build files and track untrusted context, updates the policy engine to require user confirmation for build file edits, and enhances the CLI to display critical security warnings and suppress persistent approvals. Feedback on the changes highlights a critical bug in shell.ts where getModifiedBuildFiles() is called without the session key, bypassing the caution warning, and a missing dependency (availableTerminalHeight) in a useCallback hook within ToolConfirmationMessage.tsx.
Note: Security Review did not run due to the size of the PR.
… ESLint errors in tracker
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces a robust Build File Protection mechanism and untrusted command flag detection to enhance CLI security. It ensures that modifications to build configuration files (such as Bazel BUILD, package.json, and Makefiles) always require explicit user confirmation, even in automated or YOLO modes. It also tracks build files modified during a session to warn users before executing subsequent build commands, and detects untrusted command flags sourced from external contexts. The review feedback identifies a critical security vulnerability where redirection targets (e.g., shell output redirection) are ignored during token extraction, which could allow arbitrary file writes to bypass detection. Additionally, it is recommended to replace the module-level global regular expression with String.prototype.matchAll() to prevent state leakage and potential race conditions.
Note: Security Review did not run due to the size of the PR.
…matchAll to avoid mutating global RegExp
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces Build File Protection and Untrusted Command Flags Detection to prevent unauthorized build configuration modifications and execution of untrusted command arguments. It adds utilities to identify build files, track untrusted conversation context, and warn users during tool execution. The review feedback highlights critical security bypasses on Windows platforms (due to path normalization issues and backslash escaping in shell parsing) and recommends avoiding module-level global state in the tracker to prevent cross-session data leakage in concurrent environments.
… and mandatory session scoping
There was a problem hiding this comment.
Code Review
This pull request implements a 'Build File Protection' feature to enhance security. It introduces a utility to identify build configuration files (e.g., BUILD, package.json, Dockerfile) and updates the PolicyEngine to require explicit user confirmation (ASK_USER) when these files are modified. Additionally, it adds tracking for modified build files and untrusted command flags during a session, surfacing these as critical security warnings in the UI. The DiffRenderer and colorizeCode components were updated to support disabling truncation for these sensitive diffs, and extensive tests were added to verify the new security policies and warning mechanisms. I have no feedback to provide as there were no review comments.
Note: Security Review did not run due to the size of the PR.
|
✅ 41 tests passed successfully on gemini-3-flash-preview. 🧠 Model Steering GuidanceThis PR modifies files that affect the model's behavior (prompts, tools, or instructions).
This is an automated guidance message triggered by steering logic signatures. |
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces robust security protections for build file modifications and untrusted command flags. It adds policy checks to downgrade build file modifications to user confirmation, tracks modified build files and untrusted flags across the session, and updates the CLI to display critical security warnings and suppress persistent approvals when these risks are detected. Additionally, it disables truncation in the diff renderer for build files to ensure complete visibility. A critical security issue was identified in ShellToolInvocation.getConfirmationDetails where early returns for additional permissions (sandbox expansion) can bypass the newly introduced security checks for untrusted flags and modified build files.
Note: Security Review did not run due to the size of the PR.
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces a robust "Build File Protection" mechanism and untrusted command flag detection to enhance security. It ensures that modifications to build configuration files (such as Bazel BUILD, package.json, Makefile, etc.) or execution of shell commands containing untrusted flags require explicit user confirmation and suppress persistent approvals. Additionally, build file diffs are displayed without truncation in the UI. Feedback on the changes points out a potential security bypass on POSIX platforms due to a mismatch in backslash normalization between shell commands and untrusted texts, and suggests normalizing backslashes to forward slashes before performing substring checks.
Note: Security Review did not run due to the size of the PR.
66d3cb2 to
3bcd206
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request introduces robust security features to protect against unauthorized build file modifications and untrusted command flag execution. It adds utilities to identify build configuration files, updates the PolicyEngine to downgrade modifications of these files to require explicit user confirmation, and tracks modified build files to warn users before executing subsequent build or test commands. Additionally, it detects and warns against executing shell commands containing flags sourced from untrusted conversation history. Feedback on these changes suggests enhancing the untrusted token indexing by splitting on slashes to capture individual path segments and filenames, and improving security warning clarity by capturing both the flag and its untrusted argument when a match is detected.
3bcd206 to
9f9e627
Compare
|
/gemini review |
There was a problem hiding this comment.
Code Review
This pull request implements security enhancements by introducing Build File Protection and Untrusted Flag Detection. It adds utilities to identify build files and track modifications during a session, updates the PolicyEngine to require user confirmation for build file edits and commands using untrusted flags, and improves the UI to display relevant security warnings. Additionally, it introduces a disableTruncation feature for build file diffs to ensure full visibility of changes. I have no feedback to provide.
bfb71fd
Summary
This PR implements robust mechanisms to improve workspace boundary validation (specifically focusing on build configuration files and external command parameters) under restricted workspace mode. It refactors built-in execution paths (including
shell,edit, andwrite_file) to check for command flags or arguments guided by external context tags (such as Google Docs, web fetch, or MCP server responses) and require explicit user confirmation.Details
<untrusted_context>blocks, and verify whether a command contains parameters guided by external input.package.json,Makefile,pyproject.toml,BUILD.bazel) when edited or created. If build configuration changes are detected within the current session, any subsequent build or test command execution (such asnpm run,make,cargo,blaze) is surfaced for explicit user confirmation.ToolConfirmationMessageto display detailed context to the user, highlighting specific parameters or recent build modifications, and explaining the execution options.Related Issues
Related to FixBug-cla-445881265
How to Validate
npm test -w @google/gemini-cli
Pre-Merge Checklist