Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

fix(approval): document classifier as UX gate; add high-signal patterns

4 months ago

e471e00
Authored
mweinbach6/9/2026, 6:18:53 PM
Clarify in code that classifyCommandDetailed is a "should we ask the human?"
gate, NOT a security boundary — the OS sandbox confines every bash invocation
regardless of the verdict. This prevents future reliance on these regexes for
safety. (Verified several previously-suspected bypasses — eval/bash -c/\rm/$RM/
find -exec rm/git clean -fd — are already caught because the whole string is
scanned.)

Add tight, low-false-positive patterns for destructive commands that carry no
literal rm token: find -delete, shred, mkfs, raw-disk redirects, broader
pipe-to-interpreter (dash/fish/ksh/python/etc.), and review-level recursive
chmod/chown and truncate. Adds a dedicated classifier test.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

Parent3949a15

2 files changed
  • src/utils/approval.ts+24−1
  • test/approval.classify.test.ts+88−0