github / github/spec-kit

[Security hardening] Require explicit opt-in for workflow shell steps

未关闭
#2,440 10 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
stale
主要语言
Python
星标
137k
派生
12.3k
平均合并
2 天 7 小时
30 天内合并 PR
155

描述

## Summary

Workflow `shell` steps currently execute local shell commands from workflow YAML. This is a powerful and useful capability, but catalog-installed or downloaded workflows should make that execution boundary explicit.

## Why

A workflow definition can contain arbitrary shell commands. Users should have a clear prompt or policy gate before a workflow with shell execution runs, especially when the workflow came from a catalog, URL, or third-party source.

## Proposed direction

- Add a workflow-level permission such as `requires.permissions.shell: true`.
- Reject or pause before running shell steps unless the workflow declares the capability and the user opts in.
- Surface the exact command or a summarized command list before execution.
- Keep local/development workflows ergonomic, but make downloaded/catalog workflows visibly executable.

## Acceptance criteria

- Workflows with `type: shell` require an explicit declaration or opt-in.
- Existing bundled workflows without shell steps continue to run unchanged.
- Tests cover shell steps with and without the permission declaration.
- Documentation explains that shell workflows execute local code with user privileges.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。