Skip to content

fix(analyzer): filter license boilerplate from EA3 static findings (#312) - #328

Open
rodboev wants to merge 2 commits into
NVIDIA:mainfrom
rodboev:pr/static-runner-license-ea3
Open

fix(analyzer): filter license boilerplate from EA3 static findings (#312)#328
rodboev wants to merge 2 commits into
NVIDIA:mainfrom
rodboev:pr/static-runner-license-ea3

Conversation

@rodboev

@rodboev rodboev commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

Summary

Static-only scans currently report EA3 Scope Creep findings from Apache-2.0 boilerplate in LICENSE, COPYING, and NOTICE files. This change keeps those files in the scan inventory while filtering the EA3 false positive only where the matched line is recognized license boilerplate in a text-like legal-basename file.

Closes #312

Root cause

The static runner applies EA3 to every cached text-like component. Apache-2.0 contains the phrase not limited to, which matches EA3 even though license text is not skill instruction content. The default LLM path can discard these matches later, but --no-llm reports them directly and sends avoidable findings through the analysis pipeline.

A filename-only suppression cannot be the whole fix: skill filenames are attacker-controlled, so a file named LICENSE.md could hide an excessive-agency instruction from EA3. Suppression therefore also requires the matched line to be recognized license boilerplate, which closes that bypass.

Diff Notes

  • Add delimiter-aware, case-insensitive LICENSE, COPYING, and NOTICE basename handling in static_runner.py.
  • Add content-based license-boilerplate validation: an EA3 finding is suppressed only when the matched line is a canonical license phrase for a recognized license family (Apache-2.0, MIT, BSD).
  • Report EA3 for any legal-basename file whose matched line is not recognized boilerplate; an instruction moved into a license-named file stays detectable.
  • Preserve non-EA3 scanning, inspection-ledger completion, direct analyzer behavior, SKILL.md detection, and ordinary prose detection.
  • Add production-path regressions for legal filename families, filename boundaries, ledger accounting, and direct EA3 behavior, plus the adversarial regression test_license_named_file_with_non_boilerplate_content_reports_ea3.

The suppression behavior follows the reproduction documented in issue 312, including the clarification that the false positive is exposed by --no-llm scans.

Scope

The filter applies only to EA3 matches whose line is recognized license boilerplate inside a text-like legal basename file. License-named files with non-boilerplate content are still reported. Other findings, non-license files, inventory, and report behavior remain unchanged.

Verification

  • python -m pytest tests/nodes/analyzers/test_static_patterns.py tests/nodes/analyzers/test_binary_and_pe3_filtering.py tests/unit/test_patterns_new.py - 393 passed
  • python -m pytest tests/nodes/analyzers/test_static_patterns.py -k "non_boilerplate or embedded_instruction or boilerplate" - adversarial regressions, 11 passed
  • uv run ruff check src/ tests/ - All checks passed
  • uv run ruff format --check src/ tests/ - 157 files already formatted
  • skillspector scan --no-llm --format json - EA3 location.file is ["SKILL.md"] and no LICENSE

@rng1995 rng1995 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Automated SkillSpector Review]

Requesting changes. This suppresses every EA3 finding in any text-like file whose basename resembles LICENSE, COPYING, or NOTICE, without verifying that the matched text is license boilerplate. Skill files remain untrusted regardless of their name, so malicious excessive-agency instructions can be moved into LICENSE.md and bypass EA3 entirely. Please scope suppression to recognized boilerplate content (or otherwise validate legal-file content) and add an adversarial regression showing that non-license instructions in a license-named file remain detectable.

Comment thread src/skillspector/nodes/analyzers/static_runner.py Outdated
NVIDIA#312)

Only suppress an EA3 finding on a text-like legal basename when the matched
line is recognized license boilerplate content, so instructions smuggled into
license-named files stay reported.

Signed-off-by: Rod Boev <rodboev@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

EA3 flags Apache-2.0 LICENSE boilerplate as scope creep (fires on 814/817 skills in one corpus)

2 participants