boostsecurityio / boostsecurityio/lotp

[LOTP] Add kibit

Open
#59 0 comments 0 reactions 0 assignees View on GitHub
idea
Dominant language
HTML
Stars
164
Forks
14
PR merge metrics
No merged PRs in 30d

Description

# Description of the LOTP tool

`lein kibit` is a SAST tool which allow RCE via comments. [Kibit evaluates and runs code it parses with no option to disable it #235
](https://github.com/clj-commons/kibit/issues/235) and [DEF CON 29 - Rotem Bar - Abusing SAST tools When scanners do more than just scanning](https://youtu.be/Jl-CU6G4Ofc?feature=shared&t=635).

It might have been fixed: [Fixes and clean up #260
](https://github.com/clj-commons/kibit/pull/260)

# Real-world example
It doesn't seem to be very popular: https://github.com/search?q=path%3A.github%2Fworkflows%2F+kibit&type=code

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reviewing how existing LOTP tool entries are represented in the repository and how additions are documented. Confirm whether kibit and its RCE issue are still relevant, then add the tool using the repository's established format and verify that the resulting entry identifies the security concern and references the upstream issue.

Written by the indexing model from the issue text.

Assessment

Tech stack
clojure
Domain
security
Issue type
Feature
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.