v5.15.4 - ClawHub skill context-store hardening + HOL scanner CI
ClawHub skill: project-context memory poisoning fixed (scripts/contextmanager.py, A.I.G T02). init/update now validate and reject unsafe values before writing, with per-section type checks. Every field and key is scanned
Security
- ClawHub skill: project-context memory poisoning fixed (
scripts/context_manager.py, A.I.G T02).init/updatenow validate and reject unsafe values before writing, with per-section type checks. Every field and key is scanned for injection and role/prompt-delimiter patterns, with length, depth, count, and size caps.injectblocks on any warning and emits single-line values inside a<project_context type="reference-data">block that marks them as data, not instructions.
Changed
scripts/check_permission.py: docstring and--helpdescribe an advisory local scorer that holds no credentials;--confirm-high-riskhelp lists PAYMENTS, DATABASE, and FILE_EXPORT.SKILL.md:allowed-toolslimits the skill to its six bundled scripts plusRead. Capabilities declare onlyNETWORK_AI_ENV, no shell, no ports, and no autonomous actions. Unpinnednpxcommands removed. New Bundled Script Inventory..clawhubignoreexcludes Python bytecode caches.
CI
- New HOL plugin-scanner workflow on every push and PR, using the same gate as the awesome-ai-plugins listing (score >= 80, fail on high, repository policy not trusted). Read-only permissions, SHA-pinned actions.
Tests
- 3,679 tests across 41 suites;
tsc --noEmitclean. Local HOL scan: 95/100, no high findings.
Full changelog: https://github.com/Jovancoding/Network-AI/compare/v5.15.3...v5.15.4