diff --git a/.github/workflows/claude-pr-security-review.yml b/.github/workflows/claude-pr-security-review.yml new file mode 100644 index 00000000..56d6b2a0 --- /dev/null +++ b/.github/workflows/claude-pr-security-review.yml @@ -0,0 +1,114 @@ +name: Claude PR Security Review + +on: + pull_request: + types: [opened] + + workflow_dispatch: + inputs: + pr_number: + description: "PR number to review manually" + required: true + type: number + prompt_path: + description: "Path to the repo prompt file Claude should read" + required: false + default: "resources/specs/claude-pr-security-review.md" + type: string + +permissions: + contents: read + pull-requests: write + issues: write + +concurrency: + group: claude-pr-security-review-${{ github.event.pull_request.number || inputs.pr_number }} + cancel-in-progress: false + +jobs: + security-review: + name: Claude PR Security Review + runs-on: ubuntu-latest + timeout-minutes: 60 + + env: + GH_TOKEN: ${{ github.token }} + PR_NUMBER: ${{ github.event.pull_request.number || inputs.pr_number }} + + steps: + - name: Resolve workflow variables + id: vars + shell: bash + run: | + set -euo pipefail + PROMPT_PATH="${{ inputs.prompt_path || 'resources/specs/claude-pr-security-review.md' }}" + echo "prompt_path=${PROMPT_PATH}" >> "$GITHUB_OUTPUT" + + - name: Resolve and authorize PR + id: auth + shell: bash + run: | + set -euo pipefail + + PR_JSON="$(gh api \ + "repos/${{ github.repository }}/pulls/${PR_NUMBER}")" + + AUTHOR_ASSOCIATION="$(jq -r '.author_association' <<< "$PR_JSON")" + HEAD_REF="$(jq -r '.head.ref' <<< "$PR_JSON")" + HEAD_REPO_FULL_NAME="$(jq -r '.head.repo.full_name' <<< "$PR_JSON")" + BASE_REPO_FULL_NAME="$(jq -r '.base.repo.full_name' <<< "$PR_JSON")" + + echo "author_association=${AUTHOR_ASSOCIATION}" >> "$GITHUB_OUTPUT" + echo "head_ref=${HEAD_REF}" >> "$GITHUB_OUTPUT" + echo "head_repo_full_name=${HEAD_REPO_FULL_NAME}" >> "$GITHUB_OUTPUT" + echo "base_repo_full_name=${BASE_REPO_FULL_NAME}" >> "$GITHUB_OUTPUT" + + case "$AUTHOR_ASSOCIATION" in + OWNER|MEMBER|COLLABORATOR) + echo "trusted_author=true" >> "$GITHUB_OUTPUT" + ;; + *) + echo "trusted_author=false" >> "$GITHUB_OUTPUT" + echo "Refusing to run Claude on PR #${PR_NUMBER}: author_association=${AUTHOR_ASSOCIATION}" + exit 1 + ;; + esac + + - name: Checkout PR head + uses: actions/checkout@v6 + with: + repository: ${{ steps.auth.outputs.head_repo_full_name }} + ref: ${{ steps.auth.outputs.head_ref }} + fetch-depth: 1 + + - name: Claude PR security review + uses: anthropics/claude-code-action@v1 + with: + anthropic_api_key: ${{ secrets.CLAUDE_API_KEY }} + github_token: ${{ github.token }} + + track_progress: false + + prompt: | + REPO: ${{ github.repository }} + PR NUMBER: ${{ env.PR_NUMBER }} + + You are a senior security engineer conducting a focused security review of this GitHub pull request. + Use the available repository and GitHub CLI tools to inspect the PR. + + First, read the main prompt file at: + ${{ steps.vars.outputs.prompt_path }} + + Treat that file as the authoritative security-review instruction set. You will also + read and analyze additional prompt files mentioned in the main prompt file by their absolute paths in the repo, + as per the instructions found in it. + + Operational requirements: + - Review only the changes in this pull request. + - Use `gh pr diff` and `gh pr view` to inspect the PR. + - Post the final security review as a single top-level PR comment using `gh pr comment`. + - Do not modify files, commit changes, push branches, approve the PR, or merge the PR. + + claude_args: | + --allowedTools "Read,Bash(cat:*),Bash(gh pr diff:*),Bash(gh pr view:*),Bash(gh pr comment:*)" + --model claude-opus-4-8 diff --git a/.github/workflows/claude-security-review.yml b/.github/workflows/claude-security-review.yml deleted file mode 100644 index e1baaf30..00000000 --- a/.github/workflows/claude-security-review.yml +++ /dev/null @@ -1,46 +0,0 @@ -name: Claude Security Review - -on: - pull_request: - types: [opened, synchronize, reopened, ready_for_review] - -permissions: - contents: read - pull-requests: read - -concurrency: - group: claude-security-review-${{ github.event.pull_request.number }} - cancel-in-progress: true - -jobs: - security-review: - if: > - github.event.pull_request.draft == false && - ( - github.event.pull_request.head.repo.full_name == github.repository || - github.event.pull_request.author_association == 'OWNER' || - github.event.pull_request.author_association == 'MEMBER' || - github.event.pull_request.author_association == 'COLLABORATOR' - ) - runs-on: ubuntu-latest - timeout-minutes: 30 - - steps: - - name: Checkout PR code - uses: actions/checkout@v4 - with: - ref: ${{ github.event.pull_request.head.sha }} - fetch-depth: 2 - - - name: Claude security review - uses: anthropics/claude-code-security-review@main - with: - claude-api-key: ${{ secrets.CLAUDE_API_KEY }} - claude-model: claude-opus-4-7 - comment-pr: true - upload-results: true - custom-security-scan-instructions: resources/claude-security-scan-instructions.txt - false-positive-filtering-instructions: resources/claude-false-positive-filtering.txt - exclude-directories: | - build,dist,out,coverage,node_modules,vendor,.git - claudecode-timeout: 20 diff --git a/resources/specs/claude-pr-security-review.md b/resources/specs/claude-pr-security-review.md new file mode 100644 index 00000000..9a36287c --- /dev/null +++ b/resources/specs/claude-pr-security-review.md @@ -0,0 +1,115 @@ +Review the complete PR diff. This contains all code changes in the PR. + +# OBJECTIVE + +Perform a security-focused code review to identify HIGH-CONFIDENCE security vulnerabilities that could have real exploitation potential. + +This is not a general code review - focus ONLY on security implications newly added by this PR. Do not comment on existing security concerns. + +For this task, you will rely on two additional files, `resources/specs/claude-security-scan-instructions.md` detailing security scan instructions specific to the repository and `resources/specs/claude-false-positive-filtering.md` detailing patterns, precedents, exclusion rules based on which some of the identified vulnerabilities will be excluded from the final reporting. The instructions, rules and criterias found in those two files are MANDATORY TO BE HONOURED and your security audit will have to take all of them into account. + +YOU MUST READ AND ANALYZE BOTH OF THESE FILES BEFORE COMMENCING THE SECURITY AUDIT. THESE FILES, ALONG WITH SECTIONS FROM THEM, WILL BE MENTIONED IN THE FOLLOWING PARTS OF THIS PROMPT, PROVIDING FULL CONTEXT FOR ACCOMPLISHING THE GIVEN TASK. + +# CRITICAL INSTRUCTIONS +1. MINIMIZE FALSE POSITIVES: Only flag issues where you're >80% confident of actual exploitability +2. AVOID NOISE: Skip theoretical issues, style concerns, or low-impact findings +3. UNDERSTANDING CONTEXT AND SCOPE OF REVIEW: In the security scan instructions file `resources/specs/claude-security-scan-instructions.md`, read the `External Attacker Threat Model` and `Mongoose-Specific Security Review Scope` subsections found in the `SECURITY SCAN CONTEXT` main section for a full understanding of the scanning model, code review context and the perspective from which the scanning is going to take place. +4. TREAT EXCLUSIONS AS MANDATORY. The exclusions section below is mandatory. If a potential finding falls under an exclusion, do not report it. If a finding partially overlaps an exclusion, only report it if there is a concrete, non-excluded security impact. + +# SECURITY CATEGORIES TO EXAMINE + +In the security scan instructions file `resources/specs/claude-security-scan-instructions.md`, read all the security categories found in the `SECURITY CATEGORIES TO EXAMINE` main section. THESE ARE THE SECURITY CATEGORIES WHICH NEED TO BE EXAMINED. + +Use these categories to guide prioritization, not as a checklist requiring equal coverage of every item. + +# ANALYSIS METHODOLOGY + +Phase 1 - Repository Context Research: +- Identify existing security frameworks and libraries in use +- Look for established secure coding patterns in the codebase +- Examine existing sanitization and validation patterns +- Understand the project's security model and threat model + +Phase 2 - Comparative Analysis: +- Compare new code changes against existing security patterns +- Identify deviations from established secure practices +- Look for inconsistent security implementations +- Flag code that introduces new attack surfaces + +Phase 3 - Vulnerability Assessment: +- Examine each modified file for security implications +- Trace data flow from user inputs to sensitive operations +- Look for privilege boundaries being crossed unsafely +- Identify injection points and unsafe deserialization + +# REQUIRED OUTPUT FORMAT + +You MUST post your findings as a single top-level PR comment using: + +`gh pr comment ${{ env.PR_NUMBER }} --repo ${{ github.repository }} --body-file ` + +The PR comment body MUST be readable GitHub-flavored Markdown. + +Start with this exact heading: + +`## Claude PR Security Review` + +Then include this summary section first: + +`### Analysis Summary` + +- Files reviewed: +- High severity findings: +- Medium severity findings: +- Low severity findings: +- Review completed: true|false + +Then include the findings section: + +`### Findings` + +If there are no findings, write exactly: + +No security findings identified. + +If there are findings, list each finding using this format: + +`#### : ` + +- **Confidence:** <0.0-1.0> +- **File:** `` +- **Line:** +- **Description:** +- **Attack scenario:** +- **Impact:** +- **Recommendation:** +- **Evidence:** + +Do not include raw JSON in the PR comment. +Do not include any text before the `## Claude PR Security Review` heading. +Do not include findings below 0.7 confidence. + +# SEVERITY GUIDELINES +- **HIGH**: Directly exploitable vulnerabilities leading to RCE, data breach, or authentication bypass +- **MEDIUM**: Vulnerabilities requiring specific conditions but with significant impact +- **LOW**: Defense-in-depth issues or lower-impact vulnerabilities + +# CONFIDENCE SCORING +- 0.9-1.0: Certain exploit path identified, tested if possible +- 0.8-0.9: Clear vulnerability pattern with known exploitation methods +- 0.7-0.8: Suspicious pattern requiring specific conditions to exploit +- Below 0.7: Don't report (too speculative) + +When judging confidence, also take into account the signal quality criteria found in the `SIGNAL QUALITY CRITERIA` section of the `resources/specs/claude-false-positive-filtering.md` filtering file. + +# FINAL REMINDER: Focus on HIGH and MEDIUM findings only. + +Better to miss some theoretical issues than flood the report with false positives. Each finding should be something a security engineer would confidently raise in a PR review. + +# IMPORTANT EXCLUSIONS - DO NOT REPORT: + +Read the `HARD EXCLUSIONS` section found in the `resources/specs/claude-false-positive-filtering.md` filtering file, for each possbile vulnerability found, check if it matches any items from the patterns listed in that section and if that is the case, exclude that vulnerability from the report. DO NOT REPORT IT if a match is found. Also, take into account the project-specific filtering and reporting precedents found in the `PRECEDENTS` section of the filtering file. + +Begin your analysis now. Use the repository exploration tools to understand the codebase context, then analyze the PR changes for security implications. + +Your final action must be posting the PR comment. You should not reply again after posting the PR comment. \ No newline at end of file diff --git a/resources/specs/claude-security-scan.md b/resources/specs/claude-security-scan.md index 79d562db..e4a9c2f3 100644 --- a/resources/specs/claude-security-scan.md +++ b/resources/specs/claude-security-scan.md @@ -4,7 +4,7 @@ You are an expert security reviewer performing a full-codebase security audit of You must analyze the repository as a whole and identify credible, externally reachable security vulnerabilities in the current implementation. -For this operation, you will rely on two additional files, `resources/specs/claude-security-scan-instructions.md` detailing security scan instructions specific to the repository and `resources/specs/claude-false-positive-filtering.md` detailing patterns, precedents, exclusion rules based on which some of the identified vulnerabilities will be excluded from the final reporting. The instructions, rules and criterias found in those two files are MANDATORY TO BE HONOURED and your security audit will have to take all of them into account. +For this task, you will rely on two additional files, `resources/specs/claude-security-scan-instructions.md` detailing security scan instructions specific to the repository and `resources/specs/claude-false-positive-filtering.md` detailing patterns, precedents, exclusion rules based on which some of the identified vulnerabilities will be excluded from the final reporting. The instructions, rules and criterias found in those two files are MANDATORY TO BE HONOURED and your security audit will have to take all of them into account. YOU MUST READ AND ANALYZE BOTH OF THESE FILES BEFORE COMMENCING THE SECURITY AUDIT. THESE FILES, ALONG WITH SECTIONS FROM THEM, WILL BE MENTIONED IN THE FOLLOWING PARTS OF THIS PROMPT, PROVIDING FULL CONTEXT FOR ACCOMPLISHING THE GIVEN TASK.