Skip to content

AST-181538: Block agent file edits that introduce hardcoded secrets - #1583

Open
cx-rahul-pidde wants to merge 3 commits into
mainfrom
feature/AST-181538
Open

cx-rahul-pidde wants to merge 3 commits into
mainfrom
feature/AST-181538

Conversation

@cx-rahul-pidde

@cx-rahul-pidde cx-rahul-pidde commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

By submitting this pull request, you agree to the terms within the Checkmarx Code of Conduct. Please review the contributing guidelines for guidance on creating high-quality pull requests.

Description

Blocks an agent file edit when the proposed content introduces a hardcoded secret, for Claude, Cursor, Copilot, Codex, and Gemini. The deny uses the same classify-then-act remediation flow as the other guardrails: a Checkmarx provenance tag, hook-deny header, remediation or ignore only when the user asked or the match is a cited placeholder, a cx scan secrets-realtime re-scan, and a remediation summary. The secret value stays out of the verdict and is passed to ignore through a temp file.

Also bumps ast-cx-hooks to v1.0.10.

Type of Change

  • New feature (non-breaking change which adds functionality)

Related Issues

  • AST-181538

Checklist

  • I have performed a self-review of my code
  • I have added tests that prove my fix is effective or that my feature works
  • I have added necessary documentation (if appropriate)
  • Any dependent changes have been merged and published in downstream modules
  • I have updated the CLI help for new/changed functionality in this PR (if applicable)
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used

Screenshots (if applicable)

Additional Notes

Detection, remediation telemetry, and the session tally use engine Secrets. No ast-cx-hooks source change is required beyond the v1.0.10 module bump.

cx-rahul-pidde and others added 2 commits October 6, 2026 12:21
Scan proposed file content on the write path and deny the edit with remediation, ignore, and false-positive guidance when a new secret is found.

Co-authored-by: Cursor <cursoragent@cursor.com>
Use the classify-then-act remediation flow and provenance tag on secret write denials, and pick up ast-cx-hooks v1.0.10.

Co-authored-by: Cursor <cursoragent@cursor.com>
@cx-rahul-pidde
cx-rahul-pidde requested a review from a team October 6, 2026 06:51
An unmatched or repeated Before string was skipped, so the replacement was never scanned. Fail closed instead of guessing the file content.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant