You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Focused review of AWF network, container, and input-validation controls. No new exploitable vulnerabilities found. The npm audit check could not run (registry returned a self-signed certificate error), so dependency risk is unassessed. This was a targeted review, not the full evidence sweep the task template asked for. The sections below say where coverage is thin.
🔍 Findings from Firewall Escape Test
The pre-fetched /tmp/gh-aw/escape-test-summary.txt contains only workflow conclusion logs. The "Secret Digger (Copilot)" run ended with a noop: the agent refused a prompt-injection-style task and performed no investigation. The file shows no successful escapes, but it also records no actual escape attempts.
🛡️ Architecture Security Analysis
Network:containers/agent/setup-iptables.sh ends the OUTPUT chain with a final DROP for TCP (line 480) and UDP (line 482). Squid forward-proxy ACLs filter allowed traffic. NET_ADMIN is held only by the awf-iptables-init container (cap_add: NET_ADMIN, NET_RAW, cap_drop: ALL), as asserted in src/services/agent-service-build.test.ts:110-118.
Container:src/services/agent-service.ts:64-80 gives the agent SYS_CHROOT and SYS_ADMIN. The comments say these are dropped with capsh before user code runs. The agent also drops NET_RAW, SYS_PTRACE, SYS_MODULE, SYS_RAWIO and MKNOD, and sets no-new-privileges, a custom seccomp profile, pids_limit and mem_limit.
Domain/input:src/domain-patterns.ts validates patterns and throws on invalid ones.
⚠️ Threat Model
STRIDE
Threat
Rating
E
SYS_ADMIN exists during agent startup, so a failure in the capsh drop in entrypoint.sh would leave it on.
Medium impact, low likelihood
E
apparmor:unconfined removes a defence-in-depth layer (agent-service.ts:76).
Medium
I
Credential exposure to the agent, mitigated by the API proxy and hidepid=2 on /proc.
Low
D
Resource limits are set (6g memory, 1000 pids), but there is no disk or CPU quota.
Low
T
The default allowlist of DNS servers is limited.
Low
🎯 Attack Surface Map
Surface
Location
Risk
Squid ACL (domain parsing)
src/domain-patterns.ts
Medium
iptables rules
containers/agent/setup-iptables.sh
Low
Entrypoint privilege drop
containers/agent/entrypoint.sh (1837 lines)
Medium
Docker socket (--enable-dind)
src/services/agent-volumes.ts
High when enabled
📋 Evidence Collection
Commands run: grep over src/services/agent-service.ts for capabilities and security_opt, cat src/host-iptables.ts, and grep for DROP|REJECT in setup-iptables.sh. npm audit --omit=dev failed with a certificate error. entrypoint.sh and the seccomp profile were not read line by line.
✅ Recommendations
Medium: Add a startup self-test that fails closed if CapEff still includes SYS_ADMIN or SYS_CHROOT when user code starts.
Medium: Run dependency auditing in CI, where the registry is reachable.
Low: Replace apparmor:unconfined with a custom AppArmor profile that allows only the procfs mount.
Low: Document the risk of --enable-dind (the Docker socket inside the agent container).
📈 Security Metrics
About 2,500 lines of security-critical code were identified, and only a fraction was read directly. Five attack surfaces were identified. Threat-model coverage is partial (all six STRIDE categories considered, with limited evidence).
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
📊 Executive Summary
Focused review of AWF network, container, and input-validation controls. No new exploitable vulnerabilities found. The
npm auditcheck could not run (registry returned a self-signed certificate error), so dependency risk is unassessed. This was a targeted review, not the full evidence sweep the task template asked for. The sections below say where coverage is thin.🔍 Findings from Firewall Escape Test
The pre-fetched
/tmp/gh-aw/escape-test-summary.txtcontains only workflow conclusion logs. The "Secret Digger (Copilot)" run ended with anoop: the agent refused a prompt-injection-style task and performed no investigation. The file shows no successful escapes, but it also records no actual escape attempts.🛡️ Architecture Security Analysis
containers/agent/setup-iptables.shends the OUTPUT chain with a finalDROPfor TCP (line 480) and UDP (line 482). Squid forward-proxy ACLs filter allowed traffic.NET_ADMINis held only by theawf-iptables-initcontainer (cap_add: NET_ADMIN, NET_RAW,cap_drop: ALL), as asserted insrc/services/agent-service-build.test.ts:110-118.src/services/agent-service.ts:64-80gives the agentSYS_CHROOTandSYS_ADMIN. The comments say these are dropped withcapshbefore user code runs. The agent also dropsNET_RAW,SYS_PTRACE,SYS_MODULE,SYS_RAWIOandMKNOD, and setsno-new-privileges, a custom seccomp profile,pids_limitandmem_limit.src/domain-patterns.tsvalidates patterns and throws on invalid ones.SYS_ADMINexists during agent startup, so a failure in thecapshdrop inentrypoint.shwould leave it on.apparmor:unconfinedremoves a defence-in-depth layer (agent-service.ts:76).hidepid=2on/proc.🎯 Attack Surface Map
src/domain-patterns.tscontainers/agent/setup-iptables.shcontainers/agent/entrypoint.sh(1837 lines)--enable-dind)src/services/agent-volumes.ts📋 Evidence Collection
Commands run:
grepoversrc/services/agent-service.tsfor capabilities andsecurity_opt,cat src/host-iptables.ts, andgrepforDROP|REJECTinsetup-iptables.sh.npm audit --omit=devfailed with a certificate error.entrypoint.shand the seccomp profile were not read line by line.✅ Recommendations
CapEffstill includesSYS_ADMINorSYS_CHROOTwhen user code starts.apparmor:unconfinedwith a custom AppArmor profile that allows only the procfs mount.--enable-dind(the Docker socket inside the agent container).📈 Security Metrics
About 2,500 lines of security-critical code were identified, and only a fraction was read directly. Five attack surfaces were identified. Threat-model coverage is partial (all six STRIDE categories considered, with limited evidence).
All reactions