feat(security): deceptive_ui_guard v2 — render diff, zone weighting, allowlists (#314) - #327
Conversation
|
Thanks for the substantial v2 work @tusharjamunkar, zones, allowlists, taxonomy, corpus, and bundle tests look strong and match #314 well. Before merge, please address:
Optional: dedupe or cross-link Once these are address, happy to re-review and merge if CI is green. Well done <3 |
a711159 to
93dd9ba
Compare
|
@rosspeili Thanks for the review and kind words! All requested items have been addressed:
All GitHub Actions CI checks (Python 3.10, 3.11, 3.12, CodeQL, wheel-smoke) are passing green! |
|
LGTM @tusharjamunkar, merged. <3 |
Move v0.2.0 entry to Changed, add skill history row for merge commit 9d1152c, and sync catalog version column in docs/skills/README.md.
Resolves #314
Summary of Changes
Upgrades security/deceptive_ui_guard to version 0.2.0:
DOM Zone Classification & Severity Multipliers:
avigation (0.75x), and general (1.0x).
Curated Knowledge Base Allowlists:
Expanded Deceptive UI Taxonomy:
ag_loop).
Optional Playwright Render Lane:
ender_mode=auto|force) to expose elements rendered with zero dimensions or zero opacity via external stylesheets. Lazy-imported with zero dependency overhead when
ender_mode=off (default).
23 Golden HTML Test Corpus:
ender_css_hidden, ake_urgency).
Documentation & Validation:
Verification