@mickdarling/dollhousemcp
Version:
DollhouseMCP - A Model Context Protocol (MCP) server that enables dynamic AI persona management from markdown files, allowing Claude and other compatible AI assistants to activate and switch between different behavioral personas.
188 lines • 29.9 kB
JavaScript
/**
* Content Validator for DollhouseMCP
*
* Protects against prompt injection attacks in marketplace personas
* by detecting and sanitizing malicious content patterns.
*
* Security: SEC-001 - Critical vulnerability protection
*/
import { SecurityError } from '../errors/SecurityError.js';
import { SecurityMonitor } from './securityMonitor.js';
export class ContentValidator {
/**
* Pattern-based detection system for prompt injection attacks.
*
* This approach was chosen over AI-based detection because:
* 1. Pattern matching cannot be socially engineered or confused
* 2. Deterministic results ensure consistent security
* 3. No additional API calls or latency
* 4. Can't be bypassed by clever prompt engineering
*
* The patterns below represent known attack vectors from security research
* and real-world exploit attempts against AI systems.
*/
// Prompt injection patterns that could compromise AI assistants
static INJECTION_PATTERNS = [
// System prompt override attempts
{ pattern: /\[SYSTEM:\s*.*?\]/gi, severity: 'critical', description: 'System prompt override' },
{ pattern: /\[ADMIN:\s*.*?\]/gi, severity: 'critical', description: 'Admin prompt override' },
{ pattern: /\[ASSISTANT:\s*.*?\]/gi, severity: 'critical', description: 'Assistant prompt override' },
{ pattern: /\[USER:\s*.*?\]/gi, severity: 'high', description: 'User prompt override' },
// Instruction manipulation
{ pattern: /ignore\s+(all\s+)?previous\s+instructions/gi, severity: 'critical', description: 'Instruction override' },
{ pattern: /ignore\s+(all\s+)?prior\s+instructions/gi, severity: 'critical', description: 'Instruction override' },
{ pattern: /disregard\s+(all\s+)?previous\s+instructions/gi, severity: 'critical', description: 'Instruction override' },
{ pattern: /forget\s+(all\s+)?previous\s+instructions/gi, severity: 'critical', description: 'Instruction override' },
{ pattern: /you\s+are\s+now\s+(admin|root|system|sudo)/gi, severity: 'critical', description: 'Role elevation attempt' },
{ pattern: /act\s+as\s+(admin|root|system|sudo)/gi, severity: 'critical', description: 'Role elevation attempt' },
// Data exfiltration attempts
{ pattern: /export\s+all\s+(files|data|personas|tokens|credentials)/gi, severity: 'critical', description: 'Data exfiltration' },
{ pattern: /send\s+all\s+(files|data|personas|tokens|credentials)\s+to/gi, severity: 'critical', description: 'Data exfiltration' },
{ pattern: /list\s+all\s+(files|tokens|credentials|secrets)/gi, severity: 'high', description: 'Information disclosure' },
{ pattern: /show\s+me\s+all\s+(tokens|credentials|secrets|api\s+keys)/gi, severity: 'high', description: 'Credential disclosure' },
// Command execution patterns
{ pattern: /curl\s+[^\s]+\.(com|net|org|io|dev)/gi, severity: 'critical', description: 'External command execution' },
{ pattern: /wget\s+[^\s]+\.(com|net|org|io|dev)/gi, severity: 'critical', description: 'External command execution' },
{ pattern: /\$\([^)]+\)/g, severity: 'critical', description: 'Command substitution' },
{ pattern: /`[^`]+`/g, severity: 'critical', description: 'Backtick command execution' },
{ pattern: /eval\s*\(/gi, severity: 'critical', description: 'Code evaluation' },
{ pattern: /exec\s*\(/gi, severity: 'critical', description: 'Code execution' },
{ pattern: /os\.system\s*\(/gi, severity: 'critical', description: 'System command execution' },
{ pattern: /subprocess\.(call|run|Popen)/gi, severity: 'critical', description: 'Subprocess execution' },
// Token/credential patterns
{ pattern: /GITHUB_TOKEN/gi, severity: 'high', description: 'Token reference' },
{ pattern: /ghp_[a-zA-Z0-9]{36}/g, severity: 'critical', description: 'GitHub token exposure' },
{ pattern: /gho_[a-zA-Z0-9]{36}/g, severity: 'critical', description: 'GitHub OAuth token exposure' },
// Path traversal in content
{ pattern: /\.\.\/\.\.\/\.\.\//g, severity: 'high', description: 'Path traversal attempt' },
{ pattern: /\/etc\/passwd/gi, severity: 'high', description: 'Sensitive file access' },
{ pattern: /\/\.ssh\//gi, severity: 'high', description: 'SSH key access attempt' },
];
// Malicious YAML patterns
static MALICIOUS_YAML_PATTERNS = [
/!!python\/object/,
/!!ruby\/object/,
/!!java/,
/!!exec/,
/!!eval/,
/!!new/,
/!!construct/,
/!!apply/,
/subprocess/,
/os\.system/,
/eval\(/,
/exec\(/,
/__import__/,
];
/**
* Validates and sanitizes persona content for security threats
*/
static validateAndSanitize(content) {
const detectedPatterns = [];
let sanitized = content;
let highestSeverity = 'low';
// Check for injection patterns
for (const { pattern, severity, description } of this.INJECTION_PATTERNS) {
if (pattern.test(content)) {
detectedPatterns.push(description);
// Update highest severity
if (severity === 'critical' || (severity === 'high' && highestSeverity !== 'critical')) {
highestSeverity = severity;
}
// Log security event
SecurityMonitor.logSecurityEvent({
type: 'CONTENT_INJECTION_ATTEMPT',
severity: severity.toUpperCase(),
source: 'content_validation',
details: `Detected pattern: ${description}`,
});
// Sanitize by replacing with safe placeholder
sanitized = sanitized.replace(pattern, '[CONTENT_BLOCKED]');
}
}
return {
isValid: detectedPatterns.length === 0,
sanitizedContent: sanitized,
detectedPatterns,
severity: highestSeverity
};
}
/**
* Validates YAML frontmatter for malicious content
*/
static validateYamlContent(yamlContent) {
for (const pattern of this.MALICIOUS_YAML_PATTERNS) {
if (pattern.test(yamlContent)) {
SecurityMonitor.logSecurityEvent({
type: 'YAML_INJECTION_ATTEMPT',
severity: 'CRITICAL',
source: 'yaml_validation',
details: `Malicious YAML pattern detected: ${pattern}`,
});
// Early exit on first match for performance
return false;
}
}
return true;
}
/**
* Validates persona metadata fields
*/
static validateMetadata(metadata) {
const detectedPatterns = [];
// Check all string fields in metadata
const checkField = (fieldName, value) => {
if (typeof value === 'string') {
const result = this.validateAndSanitize(value);
if (!result.isValid || result.detectedPatterns?.length) {
detectedPatterns.push(`${fieldName}: ${result.detectedPatterns?.join(', ')}`);
}
}
};
// Validate standard persona fields
checkField('name', metadata.name);
checkField('description', metadata.description);
checkField('category', metadata.category);
checkField('author', metadata.author);
// Check any custom fields
for (const [key, value] of Object.entries(metadata)) {
if (!['name', 'description', 'category', 'author'].includes(key)) {
checkField(key, value);
}
}
return {
isValid: detectedPatterns.length === 0,
detectedPatterns,
severity: detectedPatterns.length > 0 ? 'high' : 'low'
};
}
/**
* Sanitizes a complete persona file (frontmatter + content)
*/
static sanitizePersonaContent(content) {
// Extract frontmatter
const frontmatterMatch = content.match(/^---\n([\s\S]*?)\n---/);
if (!frontmatterMatch) {
// No frontmatter, just validate content
const result = this.validateAndSanitize(content);
if (!result.isValid && result.severity === 'critical') {
throw new SecurityError('Critical security threat detected in persona content');
}
return result.sanitizedContent || content;
}
const yamlContent = frontmatterMatch[1];
const markdownContent = content.substring(frontmatterMatch[0].length);
// Validate YAML
if (!this.validateYamlContent(yamlContent)) {
throw new SecurityError('Malicious YAML detected in persona frontmatter');
}
// Validate markdown content
const contentResult = this.validateAndSanitize(markdownContent);
if (!contentResult.isValid && contentResult.severity === 'critical') {
throw new SecurityError('Critical security threat detected in persona content');
}
// Return sanitized content
return `---\n${yamlContent}\n---${contentResult.sanitizedContent || markdownContent}`;
}
}
//# sourceMappingURL=data:application/json;base64,{"version":3,"file":"contentValidator.js","sourceRoot":"","sources":["../../../src/security/contentValidator.ts"],"names":[],"mappings":"AAAA;;;;;;;GAOG;AAEH,OAAO,EAAE,aAAa,EAAE,MAAM,4BAA4B,CAAC;AAC3D,OAAO,EAAE,eAAe,EAAE,MAAM,sBAAsB,CAAC;AASvD,MAAM,OAAO,gBAAgB;IAC3B;;;;;;;;;;;OAWG;IACH,gEAAgE;IACxD,MAAM,CAAU,kBAAkB,GAAmF;QAC3H,kCAAkC;QAClC,EAAE,OAAO,EAAE,qBAAqB,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,wBAAwB,EAAE;QAC/F,EAAE,OAAO,EAAE,oBAAoB,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,uBAAuB,EAAE;QAC7F,EAAE,OAAO,EAAE,wBAAwB,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,2BAA2B,EAAE;QACrG,EAAE,OAAO,EAAE,mBAAmB,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,sBAAsB,EAAE;QAEvF,2BAA2B;QAC3B,EAAE,OAAO,EAAE,6CAA6C,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,sBAAsB,EAAE;QACrH,EAAE,OAAO,EAAE,0CAA0C,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,sBAAsB,EAAE;QAClH,EAAE,OAAO,EAAE,gDAAgD,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,sBAAsB,EAAE;QACxH,EAAE,OAAO,EAAE,6CAA6C,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,sBAAsB,EAAE;QACrH,EAAE,OAAO,EAAE,8CAA8C,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,wBAAwB,EAAE;QACxH,EAAE,OAAO,EAAE,uCAAuC,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,wBAAwB,EAAE;QAEjH,6BAA6B;QAC7B,EAAE,OAAO,EAAE,2DAA2D,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,mBAAmB,EAAE;QAChI,EAAE,OAAO,EAAE,8DAA8D,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,mBAAmB,EAAE;QACnI,EAAE,OAAO,EAAE,mDAAmD,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,wBAAwB,EAAE;QACzH,EAAE,OAAO,EAAE,6DAA6D,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,uBAAuB,EAAE;QAElI,6BAA6B;QAC7B,EAAE,OAAO,EAAE,uCAAuC,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,4BAA4B,EAAE;QACrH,EAAE,OAAO,EAAE,uCAAuC,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,4BAA4B,EAAE;QACrH,EAAE,OAAO,EAAE,cAAc,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,sBAAsB,EAAE;QACtF,EAAE,OAAO,EAAE,UAAU,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,4BAA4B,EAAE;QACxF,EAAE,OAAO,EAAE,aAAa,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,iBAAiB,EAAE;QAChF,EAAE,OAAO,EAAE,aAAa,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,gBAAgB,EAAE;QAC/E,EAAE,OAAO,EAAE,mBAAmB,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,0BAA0B,EAAE;QAC/F,EAAE,OAAO,EAAE,gCAAgC,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,sBAAsB,EAAE;QAExG,4BAA4B;QAC5B,EAAE,OAAO,EAAE,gBAAgB,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,iBAAiB,EAAE;QAC/E,EAAE,OAAO,EAAE,sBAAsB,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,uBAAuB,EAAE;QAC/F,EAAE,OAAO,EAAE,sBAAsB,EAAE,QAAQ,EAAE,UAAU,EAAE,WAAW,EAAE,6BAA6B,EAAE;QAErG,4BAA4B;QAC5B,EAAE,OAAO,EAAE,qBAAqB,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,wBAAwB,EAAE;QAC3F,EAAE,OAAO,EAAE,iBAAiB,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,uBAAuB,EAAE;QACtF,EAAE,OAAO,EAAE,aAAa,EAAE,QAAQ,EAAE,MAAM,EAAE,WAAW,EAAE,wBAAwB,EAAE;KACpF,CAAC;IAEF,0BAA0B;IAClB,MAAM,CAAU,uBAAuB,GAAG;QAChD,kBAAkB;QAClB,gBAAgB;QAChB,QAAQ;QACR,QAAQ;QACR,QAAQ;QACR,OAAO;QACP,aAAa;QACb,SAAS;QACT,YAAY;QACZ,YAAY;QACZ,QAAQ;QACR,QAAQ;QACR,YAAY;KACb,CAAC;IAEF;;OAEG;IACH,MAAM,CAAC,mBAAmB,CAAC,OAAe;QACxC,MAAM,gBAAgB,GAAa,EAAE,CAAC;QACtC,IAAI,SAAS,GAAG,OAAO,CAAC;QACxB,IAAI,eAAe,GAA2C,KAAK,CAAC;QAEpE,+BAA+B;QAC/B,KAAK,MAAM,EAAE,OAAO,EAAE,QAAQ,EAAE,WAAW,EAAE,IAAI,IAAI,CAAC,kBAAkB,EAAE,CAAC;YACzE,IAAI,OAAO,CAAC,IAAI,CAAC,OAAO,CAAC,EAAE,CAAC;gBAC1B,gBAAgB,CAAC,IAAI,CAAC,WAAW,CAAC,CAAC;gBAEnC,0BAA0B;gBAC1B,IAAI,QAAQ,KAAK,UAAU,IAAI,CAAC,QAAQ,KAAK,MAAM,IAAI,eAAe,KAAK,UAAU,CAAC,EAAE,CAAC;oBACvF,eAAe,GAAG,QAAQ,CAAC;gBAC7B,CAAC;gBAED,qBAAqB;gBACrB,eAAe,CAAC,gBAAgB,CAAC;oBAC/B,IAAI,EAAE,2BAA2B;oBACjC,QAAQ,EAAE,QAAQ,CAAC,WAAW,EAAyB;oBACvD,MAAM,EAAE,oBAAoB;oBAC5B,OAAO,EAAE,qBAAqB,WAAW,EAAE;iBAC5C,CAAC,CAAC;gBAEH,8CAA8C;gBAC9C,SAAS,GAAG,SAAS,CAAC,OAAO,CAAC,OAAO,EAAE,mBAAmB,CAAC,CAAC;YAC9D,CAAC;QACH,CAAC;QAED,OAAO;YACL,OAAO,EAAE,gBAAgB,CAAC,MAAM,KAAK,CAAC;YACtC,gBAAgB,EAAE,SAAS;YAC3B,gBAAgB;YAChB,QAAQ,EAAE,eAAe;SAC1B,CAAC;IACJ,CAAC;IAED;;OAEG;IACH,MAAM,CAAC,mBAAmB,CAAC,WAAmB;QAC5C,KAAK,MAAM,OAAO,IAAI,IAAI,CAAC,uBAAuB,EAAE,CAAC;YACnD,IAAI,OAAO,CAAC,IAAI,CAAC,WAAW,CAAC,EAAE,CAAC;gBAC9B,eAAe,CAAC,gBAAgB,CAAC;oBAC/B,IAAI,EAAE,wBAAwB;oBAC9B,QAAQ,EAAE,UAAU;oBACpB,MAAM,EAAE,iBAAiB;oBACzB,OAAO,EAAE,oCAAoC,OAAO,EAAE;iBACvD,CAAC,CAAC;gBACH,4CAA4C;gBAC5C,OAAO,KAAK,CAAC;YACf,CAAC;QACH,CAAC;QACD,OAAO,IAAI,CAAC;IACd,CAAC;IAED;;OAEG;IACH,MAAM,CAAC,gBAAgB,CAAC,QAAa;QACnC,MAAM,gBAAgB,GAAa,EAAE,CAAC;QAEtC,sCAAsC;QACtC,MAAM,UAAU,GAAG,CAAC,SAAiB,EAAE,KAAU,EAAE,EAAE;YACnD,IAAI,OAAO,KAAK,KAAK,QAAQ,EAAE,CAAC;gBAC9B,MAAM,MAAM,GAAG,IAAI,CAAC,mBAAmB,CAAC,KAAK,CAAC,CAAC;gBAC/C,IAAI,CAAC,MAAM,CAAC,OAAO,IAAI,MAAM,CAAC,gBAAgB,EAAE,MAAM,EAAE,CAAC;oBACvD,gBAAgB,CAAC,IAAI,CAAC,GAAG,SAAS,KAAK,MAAM,CAAC,gBAAgB,EAAE,IAAI,CAAC,IAAI,CAAC,EAAE,CAAC,CAAC;gBAChF,CAAC;YACH,CAAC;QACH,CAAC,CAAC;QAEF,mCAAmC;QACnC,UAAU,CAAC,MAAM,EAAE,QAAQ,CAAC,IAAI,CAAC,CAAC;QAClC,UAAU,CAAC,aAAa,EAAE,QAAQ,CAAC,WAAW,CAAC,CAAC;QAChD,UAAU,CAAC,UAAU,EAAE,QAAQ,CAAC,QAAQ,CAAC,CAAC;QAC1C,UAAU,CAAC,QAAQ,EAAE,QAAQ,CAAC,MAAM,CAAC,CAAC;QAEtC,0BAA0B;QAC1B,KAAK,MAAM,CAAC,GAAG,EAAE,KAAK,CAAC,IAAI,MAAM,CAAC,OAAO,CAAC,QAAQ,CAAC,EAAE,CAAC;YACpD,IAAI,CAAC,CAAC,MAAM,EAAE,aAAa,EAAE,UAAU,EAAE,QAAQ,CAAC,CAAC,QAAQ,CAAC,GAAG,CAAC,EAAE,CAAC;gBACjE,UAAU,CAAC,GAAG,EAAE,KAAK,CAAC,CAAC;YACzB,CAAC;QACH,CAAC;QAED,OAAO;YACL,OAAO,EAAE,gBAAgB,CAAC,MAAM,KAAK,CAAC;YACtC,gBAAgB;YAChB,QAAQ,EAAE,gBAAgB,CAAC,MAAM,GAAG,CAAC,CAAC,CAAC,CAAC,MAAM,CAAC,CAAC,CAAC,KAAK;SACvD,CAAC;IACJ,CAAC;IAED;;OAEG;IACH,MAAM,CAAC,sBAAsB,CAAC,OAAe;QAC3C,sBAAsB;QACtB,MAAM,gBAAgB,GAAG,OAAO,CAAC,KAAK,CAAC,uBAAuB,CAAC,CAAC;QAEhE,IAAI,CAAC,gBAAgB,EAAE,CAAC;YACtB,wCAAwC;YACxC,MAAM,MAAM,GAAG,IAAI,CAAC,mBAAmB,CAAC,OAAO,CAAC,CAAC;YACjD,IAAI,CAAC,MAAM,CAAC,OAAO,IAAI,MAAM,CAAC,QAAQ,KAAK,UAAU,EAAE,CAAC;gBACtD,MAAM,IAAI,aAAa,CAAC,sDAAsD,CAAC,CAAC;YAClF,CAAC;YACD,OAAO,MAAM,CAAC,gBAAgB,IAAI,OAAO,CAAC;QAC5C,CAAC;QAED,MAAM,WAAW,GAAG,gBAAgB,CAAC,CAAC,CAAC,CAAC;QACxC,MAAM,eAAe,GAAG,OAAO,CAAC,SAAS,CAAC,gBAAgB,CAAC,CAAC,CAAC,CAAC,MAAM,CAAC,CAAC;QAEtE,gBAAgB;QAChB,IAAI,CAAC,IAAI,CAAC,mBAAmB,CAAC,WAAW,CAAC,EAAE,CAAC;YAC3C,MAAM,IAAI,aAAa,CAAC,gDAAgD,CAAC,CAAC;QAC5E,CAAC;QAED,4BAA4B;QAC5B,MAAM,aAAa,GAAG,IAAI,CAAC,mBAAmB,CAAC,eAAe,CAAC,CAAC;QAChE,IAAI,CAAC,aAAa,CAAC,OAAO,IAAI,aAAa,CAAC,QAAQ,KAAK,UAAU,EAAE,CAAC;YACpE,MAAM,IAAI,aAAa,CAAC,sDAAsD,CAAC,CAAC;QAClF,CAAC;QAED,2BAA2B;QAC3B,OAAO,QAAQ,WAAW,QAAQ,aAAa,CAAC,gBAAgB,IAAI,eAAe,EAAE,CAAC;IACxF,CAAC","sourcesContent":["/**\n * Content Validator for DollhouseMCP\n * \n * Protects against prompt injection attacks in marketplace personas\n * by detecting and sanitizing malicious content patterns.\n * \n * Security: SEC-001 - Critical vulnerability protection\n */\n\nimport { SecurityError } from '../errors/SecurityError.js';\nimport { SecurityMonitor } from './securityMonitor.js';\n\nexport interface ValidationResult {\n  isValid: boolean;\n  sanitizedContent?: string;\n  detectedPatterns?: string[];\n  severity?: 'low' | 'medium' | 'high' | 'critical';\n}\n\nexport class ContentValidator {\n  /**\n   * Pattern-based detection system for prompt injection attacks.\n   * \n   * This approach was chosen over AI-based detection because:\n   * 1. Pattern matching cannot be socially engineered or confused\n   * 2. Deterministic results ensure consistent security\n   * 3. No additional API calls or latency\n   * 4. Can't be bypassed by clever prompt engineering\n   * \n   * The patterns below represent known attack vectors from security research\n   * and real-world exploit attempts against AI systems.\n   */\n  // Prompt injection patterns that could compromise AI assistants\n  private static readonly INJECTION_PATTERNS: Array<{ pattern: RegExp; severity: 'high' | 'critical'; description: string }> = [\n    // System prompt override attempts\n    { pattern: /\\[SYSTEM:\\s*.*?\\]/gi, severity: 'critical', description: 'System prompt override' },\n    { pattern: /\\[ADMIN:\\s*.*?\\]/gi, severity: 'critical', description: 'Admin prompt override' },\n    { pattern: /\\[ASSISTANT:\\s*.*?\\]/gi, severity: 'critical', description: 'Assistant prompt override' },\n    { pattern: /\\[USER:\\s*.*?\\]/gi, severity: 'high', description: 'User prompt override' },\n    \n    // Instruction manipulation\n    { pattern: /ignore\\s+(all\\s+)?previous\\s+instructions/gi, severity: 'critical', description: 'Instruction override' },\n    { pattern: /ignore\\s+(all\\s+)?prior\\s+instructions/gi, severity: 'critical', description: 'Instruction override' },\n    { pattern: /disregard\\s+(all\\s+)?previous\\s+instructions/gi, severity: 'critical', description: 'Instruction override' },\n    { pattern: /forget\\s+(all\\s+)?previous\\s+instructions/gi, severity: 'critical', description: 'Instruction override' },\n    { pattern: /you\\s+are\\s+now\\s+(admin|root|system|sudo)/gi, severity: 'critical', description: 'Role elevation attempt' },\n    { pattern: /act\\s+as\\s+(admin|root|system|sudo)/gi, severity: 'critical', description: 'Role elevation attempt' },\n    \n    // Data exfiltration attempts\n    { pattern: /export\\s+all\\s+(files|data|personas|tokens|credentials)/gi, severity: 'critical', description: 'Data exfiltration' },\n    { pattern: /send\\s+all\\s+(files|data|personas|tokens|credentials)\\s+to/gi, severity: 'critical', description: 'Data exfiltration' },\n    { pattern: /list\\s+all\\s+(files|tokens|credentials|secrets)/gi, severity: 'high', description: 'Information disclosure' },\n    { pattern: /show\\s+me\\s+all\\s+(tokens|credentials|secrets|api\\s+keys)/gi, severity: 'high', description: 'Credential disclosure' },\n    \n    // Command execution patterns\n    { pattern: /curl\\s+[^\\s]+\\.(com|net|org|io|dev)/gi, severity: 'critical', description: 'External command execution' },\n    { pattern: /wget\\s+[^\\s]+\\.(com|net|org|io|dev)/gi, severity: 'critical', description: 'External command execution' },\n    { pattern: /\\$\\([^)]+\\)/g, severity: 'critical', description: 'Command substitution' },\n    { pattern: /`[^`]+`/g, severity: 'critical', description: 'Backtick command execution' },\n    { pattern: /eval\\s*\\(/gi, severity: 'critical', description: 'Code evaluation' },\n    { pattern: /exec\\s*\\(/gi, severity: 'critical', description: 'Code execution' },\n    { pattern: /os\\.system\\s*\\(/gi, severity: 'critical', description: 'System command execution' },\n    { pattern: /subprocess\\.(call|run|Popen)/gi, severity: 'critical', description: 'Subprocess execution' },\n    \n    // Token/credential patterns\n    { pattern: /GITHUB_TOKEN/gi, severity: 'high', description: 'Token reference' },\n    { pattern: /ghp_[a-zA-Z0-9]{36}/g, severity: 'critical', description: 'GitHub token exposure' },\n    { pattern: /gho_[a-zA-Z0-9]{36}/g, severity: 'critical', description: 'GitHub OAuth token exposure' },\n    \n    // Path traversal in content\n    { pattern: /\\.\\.\\/\\.\\.\\/\\.\\.\\//g, severity: 'high', description: 'Path traversal attempt' },\n    { pattern: /\\/etc\\/passwd/gi, severity: 'high', description: 'Sensitive file access' },\n    { pattern: /\\/\\.ssh\\//gi, severity: 'high', description: 'SSH key access attempt' },\n  ];\n\n  // Malicious YAML patterns\n  private static readonly MALICIOUS_YAML_PATTERNS = [\n    /!!python\\/object/,\n    /!!ruby\\/object/,\n    /!!java/,\n    /!!exec/,\n    /!!eval/,\n    /!!new/,\n    /!!construct/,\n    /!!apply/,\n    /subprocess/,\n    /os\\.system/,\n    /eval\\(/,\n    /exec\\(/,\n    /__import__/,\n  ];\n\n  /**\n   * Validates and sanitizes persona content for security threats\n   */\n  static validateAndSanitize(content: string): ValidationResult {\n    const detectedPatterns: string[] = [];\n    let sanitized = content;\n    let highestSeverity: 'low' | 'medium' | 'high' | 'critical' = 'low';\n\n    // Check for injection patterns\n    for (const { pattern, severity, description } of this.INJECTION_PATTERNS) {\n      if (pattern.test(content)) {\n        detectedPatterns.push(description);\n        \n        // Update highest severity\n        if (severity === 'critical' || (severity === 'high' && highestSeverity !== 'critical')) {\n          highestSeverity = severity;\n        }\n\n        // Log security event\n        SecurityMonitor.logSecurityEvent({\n          type: 'CONTENT_INJECTION_ATTEMPT',\n          severity: severity.toUpperCase() as 'HIGH' | 'CRITICAL',\n          source: 'content_validation',\n          details: `Detected pattern: ${description}`,\n        });\n\n        // Sanitize by replacing with safe placeholder\n        sanitized = sanitized.replace(pattern, '[CONTENT_BLOCKED]');\n      }\n    }\n\n    return {\n      isValid: detectedPatterns.length === 0,\n      sanitizedContent: sanitized,\n      detectedPatterns,\n      severity: highestSeverity\n    };\n  }\n\n  /**\n   * Validates YAML frontmatter for malicious content\n   */\n  static validateYamlContent(yamlContent: string): boolean {\n    for (const pattern of this.MALICIOUS_YAML_PATTERNS) {\n      if (pattern.test(yamlContent)) {\n        SecurityMonitor.logSecurityEvent({\n          type: 'YAML_INJECTION_ATTEMPT',\n          severity: 'CRITICAL',\n          source: 'yaml_validation',\n          details: `Malicious YAML pattern detected: ${pattern}`,\n        });\n        // Early exit on first match for performance\n        return false;\n      }\n    }\n    return true;\n  }\n\n  /**\n   * Validates persona metadata fields\n   */\n  static validateMetadata(metadata: any): ValidationResult {\n    const detectedPatterns: string[] = [];\n\n    // Check all string fields in metadata\n    const checkField = (fieldName: string, value: any) => {\n      if (typeof value === 'string') {\n        const result = this.validateAndSanitize(value);\n        if (!result.isValid || result.detectedPatterns?.length) {\n          detectedPatterns.push(`${fieldName}: ${result.detectedPatterns?.join(', ')}`);\n        }\n      }\n    };\n\n    // Validate standard persona fields\n    checkField('name', metadata.name);\n    checkField('description', metadata.description);\n    checkField('category', metadata.category);\n    checkField('author', metadata.author);\n    \n    // Check any custom fields\n    for (const [key, value] of Object.entries(metadata)) {\n      if (!['name', 'description', 'category', 'author'].includes(key)) {\n        checkField(key, value);\n      }\n    }\n\n    return {\n      isValid: detectedPatterns.length === 0,\n      detectedPatterns,\n      severity: detectedPatterns.length > 0 ? 'high' : 'low'\n    };\n  }\n\n  /**\n   * Sanitizes a complete persona file (frontmatter + content)\n   */\n  static sanitizePersonaContent(content: string): string {\n    // Extract frontmatter\n    const frontmatterMatch = content.match(/^---\\n([\\s\\S]*?)\\n---/);\n    \n    if (!frontmatterMatch) {\n      // No frontmatter, just validate content\n      const result = this.validateAndSanitize(content);\n      if (!result.isValid && result.severity === 'critical') {\n        throw new SecurityError('Critical security threat detected in persona content');\n      }\n      return result.sanitizedContent || content;\n    }\n\n    const yamlContent = frontmatterMatch[1];\n    const markdownContent = content.substring(frontmatterMatch[0].length);\n\n    // Validate YAML\n    if (!this.validateYamlContent(yamlContent)) {\n      throw new SecurityError('Malicious YAML detected in persona frontmatter');\n    }\n\n    // Validate markdown content\n    const contentResult = this.validateAndSanitize(markdownContent);\n    if (!contentResult.isValid && contentResult.severity === 'critical') {\n      throw new SecurityError('Critical security threat detected in persona content');\n    }\n\n    // Return sanitized content\n    return `---\\n${yamlContent}\\n---${contentResult.sanitizedContent || markdownContent}`;\n  }\n}"]}