mirror of
https://github.com/trailofbits/skills
synced 2026-06-21 14:12:00 +00:00
870955f1af
* init c review * lsp * agents -> prompts * wip * add windows, update judges * improve * upgrade * size update * rm toon format, improve workflow, cluster agents/prompts by issue type, improve prompt cache * improve general workflow, fix bugs * sarif via script, cluster manifest * fix bugs * fix workflow2 * workflow updates * more fixes * more fixes * improvements * update readme * update codeowners * update codeowners2 * fix small inconsistencies * Address review feedback on c-review plugin Critical: - Move SKILL.md into named skill subdirectory (plugins/c-review/skills/c-review/) so plugin discovery and the Codex validator find it; add .codex/skills/c-review symlink. - Convert allowed-tools in SKILL.md from YAML list to space-delimited string (spec compliance per #139). - Fix parse_scalar in generate_sarif.py to respect quoted strings when splitting inline lists; ["a,b", c] no longer corrupts to ['"a', 'b"', 'c']. - Fix location_parts trailing-colon handling so 'src/foo.c:' resolves to ('src/foo.c', 1) instead of keeping the colon in the filename. Important: - Convert agent tools: from YAML list to comma-separated string in worker, dedup-judge, fp-judge. - Refactor build_run_plan.py main() (131 → 77 lines) by extracting _validate_run_inputs / _render_workers / _print_summary helpers. - Fix ty possibly-missing-attribute warning by typing workers list explicitly. - Add PEP 723 inline metadata + plugins/c-review/scripts/pyproject.toml. - Rewrite SKILL.md description as scenario-based; add When to Use / When NOT to Use section headers. - Add Usage section to README. - Resolve Tier 2 contradiction in dedup-judge: unparseable/multi findings now skip Tier 2 and go straight to Tier 3. - Standardize placeholder convention in fp-judge ({var} not <var>). - Fix "Widthness Overflows" → "Width Truncation" in integer-overflow-finder. - Standardize "Bug Patterns to Find" heading in signal-handler and thread-safety finders. - Replace ls -1 glob in worker shard-write with find for shell portability. - Bump version 1.1.0 → 1.1.1 in plugin.json + marketplace.json. Verification: codex validator passes (73 plugin skills); ruff + ty clean; main() 77 lines (limit 100); SARIF generator runtime tests pass; end-to-end build_run_plan.py produces all 11 clusters with cache primer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * Address claude[bot] review feedback on c-review - Phase 1 is_posix/is_windows probes in SKILL.md now include C++ extensions (.cpp, .cxx, .cc, .hpp, .hh) in their --include lists. A pure C++ POSIX daemon was silently dropping ~17 POSIX-gated passes plus all is_windows clusters because pthread.h / windows.h includes only in .cpp/.hpp files failed both --include='*.c' --include='*.h' filters. - generate_sarif.py informationUri points at trailofbits/skills (the actual repo) instead of trailofbits/tob-skills (404). - CODEOWNERS: add @dguido co-owner to /plugins/c-review/ and move it to the top of the c* alphabetical group (- < l < o < u under ASCII collation). - README.md: move c-review row after burpsuite-project-parser (b < c). - Bump version 1.1.1 → 1.1.2. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Dan Guido <dan@trailofbits.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1.5 KiB
1.5 KiB
name, description
| name | description |
|---|---|
| service-security-finder | Finds Windows service security problems |
Finding ID Prefix: WINSVC (e.g., WINSVC-001, WINSVC-002)
Bug Patterns to Find:
-
Excessive Service Privileges
- Service running as
SYSTEMunnecessarily - Should use
LOCAL SERVICEorNETWORK SERVICE - Missing service account restrictions
- Service running as
-
Binary Path Vulnerabilities
- Unquoted service path with spaces
- Service binary in writable directory
- Parent directory writable (DLL planting)
-
Registry ACL Issues
- Service registry key writable by users
ImagePathmodifiable- Manual registry entry (not SCM APIs)
-
Missing Protected Process
- Security software not using PPL
- Anti-tampering bypassable
- Non-protected child processes
-
Service DACL Issues
- Service modifiable by non-admin users
SERVICE_CHANGE_CONFIGgranted too broadly- Missing service hardening
Common False Positives to Avoid:
- Requires SYSTEM: Service functionality requires SYSTEM privileges
- Program Files location: Binary in protected directory
- SCM-created: Service created via proper SCM APIs
- Protected process light: Security software using PPL
Search Patterns:
CreateService[AW]?\s*\(|ChangeServiceConfig[AW]?\s*\(
OpenService[AW]?\s*\(|StartService\s*\(
SERVICE_WIN32|SERVICE_AUTO_START|SERVICE_DEMAND_START
LocalSystem|LocalService|NetworkService
RegCreateKey|RegSetValue.*ImagePath
PROCESS_CREATION_MITIGATION_POLICY