Summary
Persisted command consent is keyed only by group_name. It does not include repository, package, version, or a digest of the command definition.
Affected code
cmd/consent/consent.go:81 — getConsentKey returns only group and command name
Trigger and impact
If command resolution later selects a same-named command from another repository/package, or an installed package is replaced, that different implementation can inherit the old command's grants until expiry. It may receive credential-related environment values the user approved for a different code identity.
Suggested correction
Bind consent to a stable source identity: repository ID, package identity, command name, and preferably a digest/version of the security-relevant command definition. Invalidate and re-prompt when that identity or its requested capabilities change.
Acceptance criteria
- Same-named commands from different sources cannot share grants.
- Updating or replacing a command invalidates consent when executable identity or requested capabilities change.
- Tests cover source precedence changes, package upgrades, and command replacement.
Summary
Persisted command consent is keyed only by
group_name. It does not include repository, package, version, or a digest of the command definition.Affected code
cmd/consent/consent.go:81—getConsentKeyreturns only group and command nameTrigger and impact
If command resolution later selects a same-named command from another repository/package, or an installed package is replaced, that different implementation can inherit the old command's grants until expiry. It may receive credential-related environment values the user approved for a different code identity.
Suggested correction
Bind consent to a stable source identity: repository ID, package identity, command name, and preferably a digest/version of the security-relevant command definition. Invalidate and re-prompt when that identity or its requested capabilities change.
Acceptance criteria