Download Latest Version 2.2.1 source code.zip (3.5 MB) Google Add to Preferred Sources
Home / 2.2.1
Name Modified Size InfoDownloads / Week
Parent folder
cel-go-dependencies.json 2026-10-05 4.3 kB
cel-go-helpers.json 2026-10-05 5.1 kB
requirements.txt 2026-10-05 169.4 kB
sbom.cdx.json 2026-10-05 546.2 kB
2.2.1 source code.tar.gz 2026-10-05 2.9 MB
2.2.1 source code.zip 2026-10-05 3.5 MB
README.md 2026-10-05 2.7 kB
Totals: 7 Items   7.2 MB 0

A patch release with a security fix for untrusted archives and Markdown, report-format fixes, and a working Homebrew formula. Upgrading from 2.2.0 is recommended.

Security

  • Bounded TAR extraction and linear-time Markdown parsing (#246, by @ihabler; reported by Koh Jun Sheng).
  • TAR archives used to be expanded with no compression-ratio, size or member-count limit; only ZIP archives had decompression-bomb checks. A 20 KB .tar.gz could expand to 20 MB with no finding. The scanner now copies the TAR payload through a bounded buffer and checks every member before it writes anything. The checks cover member count, declared size, compression ratio, path traversal and links. An archive over a limit raises ARCHIVE_ZIP_BOMB (CRITICAL) and nothing is extracted.
  • Markdown link discovery and inline-pipeline extraction used overlapping greedy regular expressions that ran in quadratic time on crafted input. Both now run in linear time.

Fixes

  • SARIF artifact URIs are valid URI references (#242, by @xujiantop-crypto). Paths are percent-encoded, so #, ?, %, spaces and non-ASCII file names no longer become fragments, queries or the wrong file. Absolute paths are emitted as file: URIs without uriBaseId, as SARIF ยง3.4.4 requires.
  • Markdown reports contain incomplete code fences (#245, by @xujiantop-crypto). A snippet with literal or truncated backtick fences could make renderers treat the remediation text and the findings after it as part of the snippet. Snippets with complete fences are kept as they are; any other snippet is wrapped in a fence longer than its longest backtick run.
  • Homebrew (#243, [#244]). The formula installs with current Homebrew again: brew tap cisco-ai-defense/skill-scanner https://github.com/cisco-ai-defense/skill-scanner && brew install cisco-ai-defense/skill-scanner/skill-scanner. Each release now gets a reproducible formula, and the unused rust build dependency, about 2.3 GB with llvm, is gone.

Behavior changes

  • A TAR archive over the size, ratio or member-count limit is reported as ARCHIVE_ZIP_BOMB (CRITICAL) and is not extracted. Previously it was expanded silently.
  • SARIF artifactLocation.uri values for paths with reserved or non-ASCII characters are now percent-encoded, and absolute paths are file: URIs without uriBaseId. Tools that match SARIF paths as raw strings should decode them.

Detection impact on the development split and a 2,000-skill real-skill sample was unchanged: recall 31.45% to 31.43%, FPR unchanged at 1.05%, and real-skill flag rate unchanged at 6.50%.

Full Changelog: https://github.com/cisco-ai-defense/skill-scanner/compare/2.2.0...2.2.1

Source: README.md, updated 2026-10-05