This commit is contained in:
kim
2026-05-02 23:15:25 +09:00
parent ec53a112b4
commit 83eb31f121
62 changed files with 1465 additions and 453 deletions
+14 -14
View File
@@ -20,6 +20,19 @@ function isPathInsideDir(base: string, target: string): boolean {
return rel !== '' && !rel.startsWith('..') && !path.isAbsolute(rel);
}
// Compiled once at module load — never recreated per execution
const DANGEROUS_COMMANDS: Array<[RegExp, string]> = [
[/rm\s+-rf\s+\//, 'rm -rf /'],
[/mkfs/, 'filesystem format'],
[/dd\s+if=/, 'disk write'],
[/>\s*\/dev\//, 'device write'],
[/\bsudo\b/, 'privilege escalation'],
[/\bsu\s/, 'user switch'],
[/chmod\s+777/, 'world-writable permission'],
[/\bcurl\b.*\|.*\bbash\b/, 'curl-pipe-bash'],
[/\bwget\b.*-O.*\s*-\s*\|/, 'wget-pipe'],
];
// ── Absolute-path detector ────────────────────────────────────────────────────
// Catches commands that contain absolute paths outside the workspace even when
// cwd is inside it — e.g. `type C:\Windows\System32\config\SAM`
@@ -80,20 +93,7 @@ export async function executeShell(args: ShellToolArgs): Promise<ToolResult> {
}
}
// Hardcoded dangerous command patterns
const dangerousCommands: Array<[RegExp, string]> = [
[/rm\s+-rf\s+\//, 'rm -rf /'],
[/mkfs/, 'filesystem format'],
[/dd\s+if=/, 'disk write'],
[/>\s*\/dev\//, 'device write'],
[/\bsudo\b/, 'privilege escalation'],
[/\bsu\s/, 'user switch'],
[/chmod\s+777/, 'world-writable permission'],
[/\bcurl\b.*\|.*\bbash\b/, 'curl-pipe-bash'],
[/\bwget\b.*-O.*\s*-\s*\|/, 'wget-pipe'],
];
for (const [pattern, label] of dangerousCommands) {
for (const [pattern, label] of DANGEROUS_COMMANDS) {
if (pattern.test(args.command)) {
log.warn('[shell] Blocked dangerous command:', label);
return {