Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

delibae/claude-prism
main @ 674e7c7
3
Fixes
0
CVEs
HIGH
Peak severity
0.0%
Coverage
Highlights
Auth Bypass: 1 prior fix. Scrutinize any change in this area.
apps/desktop/src-tauri/capabilities/default.json: most-fixed (1 issue). Treat as high-risk during review.
2 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Command Injection / Privilege Escalation: Child process spawning with inherited environment variables and global permission bypass allowed arbitrary command execution and privilege escalation.
Auth Bypass: Project directories were opened without re-authorization, allowing unauthorized filesystem access.
Privilege Escalation: Widening capability scope to all windows and adding window creation permissions could let a compromised webview gain elevated control.