name: openclaw-codeql-network-ssrf-boundary-critical-security disable-default-queries: true queries: - uses: security-extended query-filters: - include: precision: - high - very-high tags contain: security security-severity: /([7-9]|10)\.(\d)+/ paths: - src/infra/net - src/shared/net - src/agents/tools/web-fetch.ts - src/agents/tools/web-guarded-fetch.ts - src/agents/tools/web-shared.ts - src/plugin-sdk/ssrf-policy.ts - src/web-fetch - src/web/provider-runtime-shared.ts - packages/memory-host-sdk/src/host/ssrf-policy.ts paths-ignore: - "**/node_modules" - "**/coverage" - "**/*.generated.ts" - "**/*.bundle.js" - "**/*-runtime.js" - "**/*.test.ts" - "**/*.test.tsx" - "**/*.e2e.test.ts" - "**/*.e2e.test.tsx" - "**/*test-support*" - "**/*test-helper*" - "**/*mock*" - "**/*fixture*" - "**/*bench*"