Skip to content

audit-security has broken checks, and security docs drifted from reality #325

Description

@hyochan

Summary

Two related problems from #318 / #319: the /audit-security skill silently passes checks it never ran, and several security documents state things that are not true of the current repository.

Found while verifying the merged result. The audit tooling problem matters most — a check that looks green without running is worse than no check.

/audit-security: broken steps

Step 6 — the injection scan is a silent no-op on macOS. It uses \s inside awk, which BSD/BWK awk does not support. It matches nothing and reports clean regardless of input. Every maintainer on macOS gets a false pass.

Step 8 — the URL check reports false failures. The sed cleanup misses a trailing single quote, so 10 of 12 URLs report a bogus 404. Real breakage would be invisible in the noise.

Step 3/5 — determinism check is self-defeating. Step 3 tells the maintainer to regenerate into the same directory that step 5 then diffs against, so the comparison can pass trivially.

Also worth fixing while there: step 6's permissions grep under-reports what it finds.

Documentation drift

Claim Reality
SECURITY.md: "Every supported component release carries a CycloneDX SBOM" 7 of 9 latest component releases have none — see #323
security/README.md: gh api .../dependency-graph/sbom returns "0 packages" It returns HTTP 404. The conclusion (the graph is empty) is right; the command shown is wrong
security/README.md: "Nothing else needs to change" when adding a releasable component Wrong — TAG_PREFIXES is a second hardcoded list that must also learn the new tag
security/README.md: /audit-security re-checks all three known gaps It checks one
security/openchain.md: MAINTAINERS.md missing (4.1.2) It exists and predates the document
security/openchain.md: per-package LICENSE files a known gap 12 of 13 packages have one
security/SBOM.md: "The name always equals the published package's own name" False for apple (openiap-apple vs published openiap)
security/SBOM.md: consumer verification snippet Omits --repo, so it fails outside a clone
security/SBOM.md: worked reproduction recipe Fails on the only release it names

Docs site

  • compliance.tsx's CRA deadline row contradicts Article 14 and the repo's own CRA.md table. The final-report deadline does not run from awareness.
  • overview.tsx presents OpenIAP's internal SLA as the statutory CRA deadlines, contradicting the explicit disclaimer in SECURITY.md.
  • overview.tsx attributes release-state audits to "merge to main"; they run on every pull request.

Suggested approach

  1. Fix the three broken /audit-security steps first — they are what would have caught most of the rest.
  2. Add a regression check for the skill itself, so a command that silently matches nothing fails loudly.
  3. Correct the documentation claims. Several are counts that were true when written; prefer a described property or a command that prints the live number.

Verified correct (no action)

For the record, adversarial verification confirmed these are fine: SBOM schema validity, provenance attestation and tag binding, determinism, absence of secrets and local paths, the component/tag table, licence exception handling, CRA legal claims in CRA.md, internal links, docs routes, and test-coverage claims. 18 further candidate findings were raised and refuted during verification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    🐛 bugSomething isn't working📖 documentationImprovements or additions to documentation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions