Skip to content

Update security-guidance plugin - #62592

Merged
mhegazy merged 1 commit into
anthropics:mainfrom
mhegazy:readme-fix
May 26, 2026
Merged

mhegazy merged 1 commit into
anthropics:mainfrom
mhegazy:readme-fix

Conversation

@mhegazy

@mhegazy mhegazy commented May 26, 2026

Copy link
Copy Markdown
Contributor

One change to README.md

@mhegazy
mhegazy requested a review from sarahdeaton May 26, 2026 20:21
@mhegazy
mhegazy enabled auto-merge May 26, 2026 20:21
@marjan-ahmed

marjan-ahmed commented Oct 1, 2026 •

Copy link
Copy Markdown

Hi @mhegazy, I have a small follow-up fix for security-guidance on my fork. This repository restricts PR creation to collaborators. Could you or another collaborator open a PR from marjan-ahmed/claude-code:security-guidance/bounded-guidance-read into anthropics/claude-code:main?

Compare link

Proposed title: security-guidance: bound guidance reads by characters. The focused tests pass; the comparison notes the tested whitespace edge case where results diverge.

What I Contribute?

The contribution is a one-line memory-hardening change: _load_guidance now reads at most 8,192 characters from each guidance file, instead of loading the entire file before truncating. On the 512 MiB benchmark, peak traced memory went from 1,073,756,442 bytes to 36,678 bytes, and runtime from about 2.9 seconds to 0.23 seconds; the returned output remained 8,192 characters.

Measured edge case:

a long whitespace prefix can change output. The first tested divergence was 50 leading spaces, and the maximum measured loss was 8,192 characters when the first 8,192 characters were whitespace. The change does not bound the separate config or session-state reads

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants