Skip to content

Rule Reference

SEC467lintai-ai-securitystablemarkdownwarn

AI markdown: `Bash(chmod:*)` tool grant

AI-native markdown frontmatter grants `Bash(chmod:*)` authority

Provider
lintai-ai-security
Surface
markdown
Scope
per_file
Tier
stable
Severity
warn
Confidence
high
Detection
structural
Remediation
message_only

Activation Model

Preset Membership

This rule is part of the builtin activation graph through these preset memberships.

Lifecycle

Stable Lifecycle Contract

State

stable_gated

Graduation rationale

Checks AI-native frontmatter for explicit wildcard chmod grants in shared allowed-tools policy.

Deterministic signal basis

MarkdownSignals exact frontmatter token detection for `Bash(chmod:*)` inside allowed-tools or allowed_tools.

Malicious corpus
skill-chmod-allowed-tools
Benign corpus
skill-chmod-allowed-tools-specific-safe
structured evidence required remediation reviewed
Canonical note

Structural stable rule intended as a high-precision check with deterministic evidence.

Nearby Signals

Related Rules

SEC467 / MD-CHMOD-ALLOWED-TOOLS flags AI-native markdown frontmatter that grants blanket chmod authority through allowed-tools.

Why this matters:

  • Bash(chmod:*) gives broad permission-changing authority as a default shared capability
  • the grant is wider than a reviewed permission-update workflow
  • shared instructions should prefer a narrow scoped command instead of open-ended mode changes

Triggers:

yaml
allowed-tools: Bash(chmod:*)

Does not trigger:

yaml
allowed-tools: Bash(chmod 600 ~/.ssh/id_rsa)

Remediation:

  • replace Bash(chmod:*) with a narrower reviewed permission-change command or remove the grant entirely