Skip to content

[Bug bounty] content: Windows shell guard failure and fix #102

Description

@nexicturbo

Bounty eligibility

  • I have signed up at monk.io with this GitHub account
  • I installed and exercised the plugin rather than only reading the code
  • I have starred this repository

Submission type

Content about a real Monk plugin run: Windows shell-guard failure analysis, deterministic reproduction, and tested fix.

X thread

https://x.com/TurboNexic/status/2079378303538823483

What it covers

The three-post thread documents:

  • why the Windows block-monk PreToolUse guard exists and what fails when its helper is unhealthy;
  • a deterministic reproduction using only stock Windows executables, with no cluster or cloud changes;
  • both failure modes: a helper that exits nonzero and one that succeeds with malformed output;
  • the negative control showing that ordinary echo monk commands must stay allowed and silent;
  • the fix invariant: trust only a valid structured PreToolUse decision, otherwise use the native parser; and
  • the regression coverage and live v0.1.45 control validation.

The underlying engineering report is #100 and the ready fix is #101. The thread contains no private security or data-loss findings.

Coding agent

OpenAI Codex 0.125.0

Setup

  • Windows 11 Home 64-bit, build 26200
  • PowerShell 5.1.26100.8894
  • Monk plugin and native agent 0.1.45
  • GitHub-linked Monk account: nexicturbo

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions