github / github/spec-kit

[Security hardening] Require explicit opt-in for workflow shell steps

Ouverte
#2,440 10 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
stale
Langage dominant
Python
Étoiles
137k
Forks
12.3k
Merge moyen
2 j 7 h
PR mergées (30 j)
155

Description

## Summary

Workflow `shell` steps currently execute local shell commands from workflow YAML. This is a powerful and useful capability, but catalog-installed or downloaded workflows should make that execution boundary explicit.

## Why

A workflow definition can contain arbitrary shell commands. Users should have a clear prompt or policy gate before a workflow with shell execution runs, especially when the workflow came from a catalog, URL, or third-party source.

## Proposed direction

- Add a workflow-level permission such as `requires.permissions.shell: true`.
- Reject or pause before running shell steps unless the workflow declares the capability and the user opts in.
- Surface the exact command or a summarized command list before execution.
- Keep local/development workflows ergonomic, but make downloaded/catalog workflows visibly executable.

## Acceptance criteria

- Workflows with `type: shell` require an explicit declaration or opt-in.
- Existing bundled workflows without shell steps continue to run unchanged.
- Tests cover shell steps with and without the permission declaration.
- Documentation explains that shell workflows execute local code with user privileges.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.