laststance / laststance/git-gpt-commit

🔒 Add input validation for git diff before OpenAI API calls

Open
#65 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement high-priority security
Dominant language
JavaScript
Stars
36
Forks
3
PR merge metrics
No merged PRs in 30d

Description

Problem

Currently, the git diff output is sent directly to the OpenAI API without validation (index.js:103-108). This creates security and cost risks:

  • Security Risk: Could inadvertently send sensitive data (API keys, passwords, tokens) to OpenAI
  • Cost Risk: Large diffs could exceed token limits, causing API errors or unexpected costs
  • User Experience: No warnings when potentially sensitive content is detected

Current Code

const { stdout } = await exec(
  "git diff --cached -- . ':(exclude)*lock.json' ':(exclude)*lock.yaml'"
)
const summary = stdout.trim()
if (summary.length === 0) {
  return null
}
return summary // ⚠️ No validation before sending to OpenAI

Proposed Solution

Add validation with size limits and sensitive data detection:

const MAX_DIFF_SIZE = 10000 // characters
const SENSITIVE_PATTERNS = [
  /api[_-]?key/i,
  /password/i,
  /secret/i,
  /token/i,
  /-----BEGIN [A-Z]+ PRIVATE KEY-----/
]

function validateDiffSafety(diff) {
  // Check size
  if (diff.length > MAX_DIFF_SIZE) {
    throw new Error(
      `Git diff too large (${diff.length} chars). Limit: ${MAX_DIFF_SIZE}\n` +
      'Consider committing in smaller chunks.'
    )
  }

  // Check for sensitive data
  const detectedPatterns = []
  for (const pattern of SENSITIVE_PATTERNS) {
    if (pattern.test(diff)) {
      detectedPatterns.push(pattern.toString())
    }
  }

  if (detectedPatterns.length > 0) {
    console.warn('⚠️  Warning: Potential sensitive data detected in diff:')
    detectedPatterns.forEach(p => console.warn(`   - Pattern: ${p}`))
    console.warn('\nThis content will be sent to OpenAI API.')
    // Could add user confirmation prompt here
  }
}

// In getGitSummary():
const summary = stdout.trim()
if (summary.length === 0) {
  return null
}
validateDiffSafety(summary)
return summary

Benefits

  • ✅ Prevents accidental exposure of sensitive data
  • ✅ Controls OpenAI API costs
  • ✅ Improves user awareness
  • ✅ Configurable limits and patterns

Acceptance Criteria

  • Add size validation for git diff output
  • Add sensitive data pattern detection
  • Display warnings to user when patterns detected
  • Add configuration options for size limits
  • Add tests for validation logic
  • Update documentation

Priority

High - Security and cost implications

Related

Quality analysis report: claudedocs/quality-analysis-report.md section 3.3

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading getGitSummary in index.js around lines 103-108 and the related quality report section in claudedocs/quality-analysis-report.md. Define the validation behavior and configuration scope, then add tests covering size limits and sensitive-pattern warnings; the work is done when the acceptance criteria are met and documentation is updated.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, javascript
Domain
api, cli, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.