Skip to content

docs: scan #97 — realiti4/claude-swap (22 findings, 0 real, clean scan) - #136

Merged
elfrost merged 1 commit into
mainfrom
daily/2026-09-07-claude-swap
Sep 7, 2026
Merged

docs: scan #97 — realiti4/claude-swap (22 findings, 0 real, clean scan)#136
elfrost merged 1 commit into
mainfrom
daily/2026-09-07-claude-swap

Conversation

@elfrost

@elfrost elfrost commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Thirty-first clean scan. realiti4/claude-swap at 9a6769a: 22 findings (20 above the medium floor), zero real after curation.

  • Semgrep 55/55 files, 0 skipped, errors empty. Trivy (uv.lock) and pip-audit (pyproject) both clean and agreeing.
  • 5 insecure-file-permissions hits all on chmod 0o700 hardening (active-harm FP); 4 dynamic-urllib on constant URLs; 1 gitleaks High on Claude Code's public OAuth client id; 9 mutable action tags; 1 logger rule on a parameter in scope.
  • Hand sweep: defence inventory (pinned /usr/bin/security + stdin secrets, mkstemp everywhere, env scrubbing, import validation before filenames, export minimisation).
  • One Low hardening note published in full: switcher._write_json is the one writer of eight on write-then-chmod, and four call sites write the live ~/.claude.json into $HOME. Not filed (quality gate false).
  • Not strict-norm (no SECURITY.md, PVR off). Post-only.

Three files: post, index row + counts (95/96 → 97), scan-log bullet + count.

🤖 Generated with Claude Code

…n; hardening note on the one drifted JSON writer)

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@elfrost
elfrost merged commit 6ae8c1c into main Sep 7, 2026
@elfrost
elfrost deleted the daily/2026-09-07-claude-swap branch September 7, 2026 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant