検証: ptufは本当にバイパス耐性があるか — 難読化した危険コマンドを投げて実測した
00:01:17 ・ source: https://zenn.dev/mskbhd/articles/lab-041-ptuf
Transcript
hostenToday we test ptuf, a security filter for AI coding agents, against obfuscated dangerous commands.
guestja今日は、AIコーディングエージェント用のセキュリティフィルタ「ptuf」を、難読化した危険コマンドで実際にテストしました。
hostenThe key finding: ptuf really is stronger than grep at catching shell tricks like spaces, quotes, and flag reordering.
guestja主な発見は、ptufがスペース・クォート・フラグ順のような難読化には本当に強く、素朴なgrepでは逃げる変種をちゃんと止めたということです。
hostenHowever, it has limits: command substitution like `$(echo rm)` and variable expansion `$X` slip through undetected.
guestjaただし制限もあります。コマンド置換 `$(echo rm)` や変数展開 `$X` は静的解析なので実行時に確定する値は追えず、素通りしてしまいます。
hostenThe author himself got blocked three times while testing—proof that ptuf actually works as a real guard.
guestja著者自身もテスト中に3回ブロックされました。これはptufが実際に機能する本物のガードレールであることを示しています。
hostenThe lesson: use ptuf as one layer in defense-in-depth, not as your only security wall.
guestja結論は、ptufを多層防御の一枚として使うべきで、それだけが唯一の砦にはできないということです。