fix: resolve 25 pre-publish blockers
- postinstall.mjs: fix alias package detection - migrate-legacy-plugin-entry: dedupe + regression tests - task_system: default consistency across runtime paths - task() contract: consistent tool behavior - runtime model selection, tool cap, stale-task cancellation - recovery sanitization, context-limit gating - Ralph semantic DONE hardening, Atlas fallback persistence - native-skill description/content, skill path traversal guard - publish workflow: platform awaited via reusable workflow job - release: version edits reapplied before commit/tag - JSONC plugin migration: top-level plugin key safety - cold-cache: user fallback models skip disconnected providers - docs/version/release framing updates Verified: bun test (4599 pass), tsc --noEmit clean, bun run build clean
This commit is contained in:
@@ -125,4 +125,28 @@ describe("resolveSkillPathReferences", () => {
|
||||
//#then
|
||||
expect(result).toBe("/skills/frontend/scripts/search.py")
|
||||
})
|
||||
|
||||
it("does not resolve traversal paths that escape the base directory", () => {
|
||||
//#given
|
||||
const content = "Read @data/../../../../etc/passwd before running"
|
||||
const basePath = "/skills/frontend"
|
||||
|
||||
//#when
|
||||
const result = resolveSkillPathReferences(content, basePath)
|
||||
|
||||
//#then
|
||||
expect(result).toBe("Read @data/../../../../etc/passwd before running")
|
||||
})
|
||||
|
||||
it("does not resolve directory traversal with trailing slash", () => {
|
||||
//#given
|
||||
const content = "Inspect @data/../../../secret/"
|
||||
const basePath = "/skills/frontend"
|
||||
|
||||
//#when
|
||||
const result = resolveSkillPathReferences(content, basePath)
|
||||
|
||||
//#then
|
||||
expect(result).toBe("Inspect @data/../../../secret/")
|
||||
})
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user