4 months ago
e471e00Clarify in code that classifyCommandDetailed is a "should we ask the human?" gate, NOT a security boundary — the OS sandbox confines every bash invocation regardless of the verdict. This prevents future reliance on these regexes for safety. (Verified several previously-suspected bypasses — eval/bash -c/\rm/$RM/ find -exec rm/git clean -fd — are already caught because the whole string is scanned.) Add tight, low-false-positive patterns for destructive commands that carry no literal rm token: find -delete, shred, mkfs, raw-disk redirects, broader pipe-to-interpreter (dash/fish/ksh/python/etc.), and review-level recursive chmod/chown and truncate. Adds a dedicated classifier test. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Parent3949a15