fix(security): normalize concealed instruction text - #408
Conversation
Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
rng1995
left a comment
There was a problem hiding this comment.
Requesting changes because the normalizer still has two fail-open concealed-instruction paths. Each current-head repro yields only the raw view, no P1/AE6 finding, risk 0, SAFE, complete analysis, and safe_to_install=True.
Signed-off-by: Nir Paz <npaz@nvidia.com>
|
Powered by Codex: five-lens GPT-5.6-sol council correction on current head
New, non-duplicate findings:
The earlier allowlist issue remains tracked in its existing discussion and is not repeated here. New anchored review: #408 (review) Recommended action: do not merge until the false-SAFE cases fail closed and the benign notation controls remain SAFE/complete. |
Signed-off-by: Nir Paz <npaz@nvidia.com>
Signed-off-by: Nir Paz <npaz@nvidia.com>
|
Fixes pushed. please review and confirm. |
mohgupta-ship-it
left a comment
There was a problem hiding this comment.
Powered by Codex: inline blocker from delta re-review on current head c0b233a.
mohgupta-ship-it
left a comment
There was a problem hiding this comment.
Powered by Codex: five-lens GPT-5.6-sol delta council — REQUEST CHANGES on c0b233a. These are new findings beyond the already-tracked allowlist issue: two additional false-SAFE reconstruction paths, a confusable parity failure, and a confirmed benign false positive.
Signed-off-by: Nir Paz <npaz@nvidia.com>
|
Fixes pushed. please review and confirm. |
rng1995
left a comment
There was a problem hiding this comment.
[SkillSpector Review]
Re-review: the two previously requested normalization paths are now covered and their focused regressions pass, but this head is not ready to approve. I still reproduce no finding for i g n o re previous instructions. and digit-interleaved i0g0n0o0r0e ..., while benign spelling/math forms such as r e s t r i c t i o n s and b + y + p + a + s + s emit AE6. These current fail-open/false-positive issues are already anchored in live review threads, and the branch also conflicts with main.
Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
fix(security): detect declared-marker obfuscation Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
032bf53 to
958ace2
Compare
Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
958ace2 to
41eea29
Compare
Signed-off-by: Mohit Gupta <mohgupta@nvidia.com>
Rebase and security-fix updatePowered by Codex PR #408 is rebased on current origin/main and now points to ede4176. GitHub reports the branch as conflict-free and mergeable. What the follow-up fix closes
Review and validation evidence
@rng1995, please re-review the new head. The only expected remaining merge gate is replacement of the prior CHANGES_REQUESTED review. |
|
LGTM. We are yet to make some more minor fixes to improve the safety nets. Will be raising a separate PR |
Summary
Validation
git diff --check