mirror of
https://github.com/trailofbits/skills.git
synced 2026-09-14 14:28:48 +08:00
Fix allowed-tools to use spec-compliant space-delimited strings (#139)
* Fix `allowed-tools` to use spec-compliant space-delimited strings Per the agentskills.io specification, `allowed-tools` must be a single string of space-delimited patterns, not a YAML list. Converted all 23 SKILL.md files from the `- Item` list format to the correct `"Item1 Item2"` string format. Also updated the frontmatter examples in CLAUDE.md and the workflow-skill-design skill template to match. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Fix remaining allowed-tools format in firebase-apk-scanner and workflow-skill-design docs - Convert firebase-apk-scanner from comma-separated to space-delimited - Update anti-patterns.md and tool-assignment-guide.md examples from YAML lists to space-delimited strings - Remove unnecessary quotes from SKILL.md template placeholder Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Cover commands, new SKILL.md files, and fix template placeholder Extends the previous spec-compliance fixes: * Convert command frontmatter (commands/*.md) — per Claude Code docs, command files use the same frontmatter as skills, so the same space-delimited rule applies. * Convert three SKILL.md files added since the original PR: mutation-testing, trailmark-structural, trailmark-summary. * Fix the placeholder in the workflow-skill-design template. The previous "[minimum tools needed, space-delimited]" was YAML flow-sequence syntax, which parses as a list — the opposite of what the placeholder claims. Replaced with a concrete-looking space-delimited example plus a comment. Zeroize-audit agent files still use `allowed-tools:` in YAML list form. They are intentionally excluded: per the project's own docs (workflow-skill-design references), agents declare tools with `tools:` (not `allowed-tools:`). Fixing those requires changing the field name as well as the format and is out of scope for this PR. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * zeroize-audit agents: switch allowed-tools to tools Subagents declare their tool allowlist via `tools:` (comma-separated), not `allowed-tools:` — see Claude Code's subagent docs and this repo's own designing-workflow-skills/SKILL.md:47: > Skills use `allowed-tools:` in frontmatter. Agents use `tools:` > in frontmatter. Before this change, the zeroize-audit agents declared their tool list under `allowed-tools:`, which Claude Code does not read for subagents. The field was effectively a no-op; the spawned agents had no tool restriction enforced. Renames the field on all 11 agents to `tools:` and reformats the YAML list as comma-separated to match the documented format and existing agents elsewhere in the repo (e.g. function-analyzer.md, spec-compliance-checker.md). Tool sets are unchanged. Behavior change: tools now actually constrain what each spawned agent can call. The lists are the ones the original author intended. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * skill-improver: convert command allowed-tools to space-delimited The two command files in plugins/skill-improver/commands/ still used the JSON flow-array format (`allowed-tools: ["..."]`), which the rest of this PR converted everywhere else. Convert them to the spec-compliant space-delimited string form for consistency. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Dan Guido <dan@trailofbits.com>
This commit is contained in:
@@ -2,12 +2,7 @@
|
||||
name: 0-preflight
|
||||
description: "Performs preflight validation, config merging, TU enumeration, and work directory setup for zeroize-audit. Produces merged-config.yaml, preflight.json, and orchestrator-state.json."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
tools: Read, Grep, Glob, Write, Bash
|
||||
---
|
||||
|
||||
# 0-preflight
|
||||
|
||||
@@ -2,16 +2,7 @@
|
||||
name: 1-mcp-resolver
|
||||
description: "Resolves symbol definitions, types, and cross-file references using Serena MCP for zeroize-audit. Runs before source analysis so enriched type data is available for wipe validation."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
- mcp__serena__activate_project
|
||||
- mcp__serena__find_symbol
|
||||
- mcp__serena__find_referencing_symbols
|
||||
- mcp__serena__get_symbols_overview
|
||||
tools: Read, Grep, Glob, Write, Bash, mcp__serena__activate_project, mcp__serena__find_symbol, mcp__serena__find_referencing_symbols, mcp__serena__get_symbols_overview
|
||||
---
|
||||
|
||||
# 1-mcp-resolver
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 2-source-analyzer
|
||||
description: "Identifies sensitive objects, detects wipe calls, validates correctness, and performs data-flow/heap analysis for zeroize-audit. Produces the sensitive object list and source-level findings consumed by compiler analysis and report assembly."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
tools: Read, Grep, Glob, Write, Bash
|
||||
---
|
||||
|
||||
# 2-source-analyzer
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 2b-rust-source-analyzer
|
||||
description: "Performs source-level zeroization analysis for Rust crates in zeroize-audit. Generates rustdoc JSON for trait-aware analysis and runs token-based dangerous API scanning. Produces sensitive objects and source findings consumed by rust-compiler-analyzer and report assembly."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
tools: Read, Grep, Glob, Write, Bash
|
||||
---
|
||||
|
||||
# 2b-rust-source-analyzer
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 3-tu-compiler-analyzer
|
||||
description: "Performs per-TU compiler-level analysis (IR diff, assembly, semantic IR, CFG) for zeroize-audit. One instance runs per translation unit, enabling parallel execution across TUs."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
tools: Read, Grep, Glob, Write, Bash
|
||||
---
|
||||
|
||||
# 3-tu-compiler-analyzer
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 3b-rust-compiler-analyzer
|
||||
description: "Performs crate-level MIR and LLVM IR analysis for Rust in zeroize-audit. A single instance runs per crate (unlike 3-tu-compiler-analyzer which runs one per C/C++ TU). Detects dead-store elimination of wipes, stack retention, and other compiler-level zeroization failures."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
tools: Read, Grep, Glob, Write, Bash
|
||||
---
|
||||
|
||||
# 3b-rust-compiler-analyzer
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 4-report-assembler
|
||||
description: "Collects all findings from source and compiler analysis, applies supersessions and confidence gates, normalizes IDs, and produces a comprehensive markdown report with structured JSON for downstream tools. Supports dual-mode invocation: interim (findings.json only) and final (merge PoC results, produce final-report.md)."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Write
|
||||
- Bash
|
||||
tools: Read, Grep, Glob, Write, Bash
|
||||
---
|
||||
|
||||
# 4-report-assembler
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 5-poc-generator
|
||||
description: "Crafts bespoke proof-of-concept programs demonstrating that zeroize-audit findings are exploitable. Reads source code and finding details to generate tailored PoCs — each PoC is individually written, not templated. Each PoC exits 0 if the secret persists or 1 if wiped. Mandatory for every finding."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Write
|
||||
- Bash
|
||||
- Grep
|
||||
- Glob
|
||||
tools: Read, Write, Bash, Grep, Glob
|
||||
---
|
||||
|
||||
# 5-poc-generator
|
||||
|
||||
@@ -2,11 +2,7 @@
|
||||
name: 5b-poc-validator
|
||||
description: "Compiles and runs all PoCs for zeroize-audit findings. Produces poc_validation_results.json consumed by the verification agent and the orchestrator."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Write
|
||||
- Bash
|
||||
- Grep
|
||||
tools: Read, Write, Bash, Grep
|
||||
---
|
||||
|
||||
# 5b-poc-validator
|
||||
|
||||
@@ -2,11 +2,7 @@
|
||||
name: 5c-poc-verifier
|
||||
description: "Verifies that each zeroize-audit PoC actually proves the vulnerability it claims to demonstrate. Reads PoC source code, finding details, and original source to check alignment between the PoC and the finding. Produces poc_verification.json consumed by the orchestrator."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Write
|
||||
- Grep
|
||||
- Glob
|
||||
tools: Read, Write, Grep, Glob
|
||||
---
|
||||
|
||||
# 5c-poc-verifier
|
||||
|
||||
@@ -2,12 +2,7 @@
|
||||
name: 6-test-generator
|
||||
description: "Generates runtime validation test harnesses (C tests, MSAN, Valgrind targets) for confirmed zeroize-audit findings. Produces a Makefile for automated test execution."
|
||||
model: inherit
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Write
|
||||
- Bash
|
||||
- Grep
|
||||
- Glob
|
||||
tools: Read, Write, Bash, Grep, Glob
|
||||
---
|
||||
|
||||
# 6-test-generator
|
||||
|
||||
@@ -1,18 +1,7 @@
|
||||
---
|
||||
name: zeroize-audit
|
||||
description: "Detects missing zeroization of sensitive data in source code and identifies zeroization removed by compiler optimizations, with assembly-level analysis, and control-flow verification. Use for auditing C/C++/Rust code handling secrets, keys, passwords, or other sensitive data."
|
||||
allowed-tools:
|
||||
- Read
|
||||
- Grep
|
||||
- Glob
|
||||
- Bash
|
||||
- Write
|
||||
- Task
|
||||
- AskUserQuestion
|
||||
- mcp__serena__activate_project
|
||||
- mcp__serena__find_symbol
|
||||
- mcp__serena__find_referencing_symbols
|
||||
- mcp__serena__get_symbols_overview
|
||||
allowed-tools: Read Grep Glob Bash Write Task AskUserQuestion mcp__serena__activate_project mcp__serena__find_symbol mcp__serena__find_referencing_symbols mcp__serena__get_symbols_overview
|
||||
---
|
||||
|
||||
# zeroize-audit — Claude Skill
|
||||
|
||||
Reference in New Issue
Block a user