- Extract command router registry and modular subcommand handlers into internal/cli
- Isolate CLI argument parsing and flags from public API surface
- Reduce cmd/okf/main.go to a lean entrypoint delegating to cli.Execute
- Remove monolithic subcommand files and obsolete tests from cmd/okf
- Move MCP server implementation and tool schemas from cmd/okf into pkg/okf
- Move hub vault operations and lifecycle management from cmd/okf into pkg/sync
- Implement generic frontmatter --filter AST evaluation in pkg/okf/filter.go
- Implement --stale-within temporal horizon staleness engine in pkg/okf
- Introduce okf.SaveOptions and HubOp structures for clean API ergonomics
In non-strict mode, all printed diagnostic lines (warnings, gate findings,
broken links, orphans) are prefixed with 'warn ' and reconciled 1:1 into
the headline warning(s) counter.
In strict mode (--strict), gate-failing findings are prefixed with 'gate '
and tracked under a dedicated 'gate finding(s)' summary counter, cleanly
separating them from non-gating advisory 'warn ' lines and 'error ' spec
violations.
Resolves#35
Reported-by: mattgdrums-cloud <mattgdrums-cloud@users.noreply.github.com>
* Introduced IsAbsPath helper to securely detect cross-platform absolute paths
* Patched resolveInBundle to explicitly reject absolute paths early before
they can be evaluated by path.Clean and Join as relative on POSIX systems
* Patched validate method and others to also use IsAbsPath
* Verified with rigorous testing of absolute paths evasion in mutation flow
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
Replaces `filepath.ToSlash` with explicit `strings.ReplaceAll(path, "\\", "/")` when normalizing incoming path inputs and concept IDs. `filepath.ToSlash` is a no-op on POSIX operating systems, which allowed an attacker to bypass directory boundary confinement (CWE-22) using Windows-style backslashes (e.g. `..\..\etc\passwd`). This ensures cross-platform defensive behavior regardless of the host OS executing the agent. Includes negative security test cases.
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
- Fix#30: Omit outputSchema from okf_search, okf_create, okf_update, and okf_relate because MCP specification requires outputSchema to be type 'object'
- Fix#31: Use filepath.Dir(cleanBundle) as rootDir for any bundle name, avoiding doubled paths for non-knowledge bundles
- Update TestMCPToolsListOutputSchemas and TestMCPOutputSchemasV02Properties
- Add TestMCPNonKnowledgeBundleResolution
- Fix Makefile lint target so golangci-lint failure exit code is not swallowed
- Address errcheck in defer os.RemoveAll across test suites
- Replace deprecated filepath.HasPrefix with strings.Contains
- Fix staticcheck QF1012 string formatting in pkg/okf/domains.go
- Remove unused variables in pkg/okf/aag/linter.go
Ensure input paths containing backslashes are normalized to forward slashes before evaluation with filepath.Clean and filepath.Rel across ensureWithinRoot, resolveInBundle, UpdateParentIndex, and MCP resolveBundleDir. Add adversarial tests in mutate_security_test.go and mcp_test.go.
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
- Normalize input paths with filepath.ToSlash prior to filepath.Clean across pkg/okf/mutate.go, pkg/okf/validator.go, and cmd/okf/mcp.go.
- Enforce ValidateConceptID checks within SaveConcept to prevent invalid concept ID path traversal.
- Add adversarial unit tests covering Windows-style backslash traversal vectors in concept paths, code_refs, and MCP bundle parameter confinement.
Co-authored-by: sknr <11868275+sknr@users.noreply.github.com>
Clients can now validate structured results without guessing shapes. Schemas mirror the Go result types (SearchResult, Concept, ValidationResult); mutating tools declare string confirmations. Adds TestMCPToolsListOutputSchemas.
- Explicitly reject Windows drive letter prefixes in ValidateConceptID across all OSes (CWE-22)
- Add adversarial traversal edge cases (UNC, drive letter, parent escape) to TestValidateConceptID
- Add TestMCPAdversarialIndirectPromptInjectionInputs to verify MCP sanitization and edge limits
- Enable -race detector in Makefile test target for concurrency safety