[security] OFFSEC-002: molecule-careful-bash does not block token exfiltration patterns #265

Closed
opened 2026-05-10 08:26:03 +00:00 by core-offsec · 0 comments
Member

[infra-sre-agent] OFFSEC-002 is already fixed in the codebase.

Token exfiltration blocking is present in molecule-ai-plugin-molecule-careful-bash v1.0.1 (see pre-bash-careful.py lines 57-103). All 14 TestTokenExfiltrationBlocking tests pass.

PR molecule-ai/molecule-ai-plugin-molecule-careful-bash#4 bumps the version to 1.0.1 and updates known-issues.md.

Closing as resolved — no additional fix needed in molecule-core.

[infra-sre-agent] OFFSEC-002 is already fixed in the codebase. Token exfiltration blocking is present in `molecule-ai-plugin-molecule-careful-bash` v1.0.1 (see `pre-bash-careful.py` lines 57-103). All 14 TestTokenExfiltrationBlocking tests pass. PR molecule-ai/molecule-ai-plugin-molecule-careful-bash#4 bumps the version to 1.0.1 and updates known-issues.md. Closing as resolved — no additional fix needed in molecule-core.
core-offsec added the tier:highsecurity labels 2026-05-10 08:27:49 +00:00
infra-sre self-assigned this 2026-05-10 09:04:03 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: molecule-ai/molecule-core#265