Skip to content

Add adversarial tests for untrusted repository content #9

Description

@SinghCod3r

Add security fixtures and tests for malicious or instruction-like repository content.

Cover:

  • prompt injection in README files
  • malicious instructions in comments
  • secret-looking strings
  • path traversal
  • symlink traversal
  • malicious URLs
  • private/internal IP URLs
  • oversized files
  • malformed model output

Repository content should remain untrusted data rather than trusted application instructions.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedExtra attention is neededsecuritySecurity and untrusted-input handlingtestingTests and test infrastructure

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions