v2.3.1
This commit is contained in:
+14
-14
@@ -20,6 +20,19 @@ function isPathInsideDir(base: string, target: string): boolean {
|
||||
return rel !== '' && !rel.startsWith('..') && !path.isAbsolute(rel);
|
||||
}
|
||||
|
||||
// Compiled once at module load — never recreated per execution
|
||||
const DANGEROUS_COMMANDS: Array<[RegExp, string]> = [
|
||||
[/rm\s+-rf\s+\//, 'rm -rf /'],
|
||||
[/mkfs/, 'filesystem format'],
|
||||
[/dd\s+if=/, 'disk write'],
|
||||
[/>\s*\/dev\//, 'device write'],
|
||||
[/\bsudo\b/, 'privilege escalation'],
|
||||
[/\bsu\s/, 'user switch'],
|
||||
[/chmod\s+777/, 'world-writable permission'],
|
||||
[/\bcurl\b.*\|.*\bbash\b/, 'curl-pipe-bash'],
|
||||
[/\bwget\b.*-O.*\s*-\s*\|/, 'wget-pipe'],
|
||||
];
|
||||
|
||||
// ── Absolute-path detector ────────────────────────────────────────────────────
|
||||
// Catches commands that contain absolute paths outside the workspace even when
|
||||
// cwd is inside it — e.g. `type C:\Windows\System32\config\SAM`
|
||||
@@ -80,20 +93,7 @@ export async function executeShell(args: ShellToolArgs): Promise<ToolResult> {
|
||||
}
|
||||
}
|
||||
|
||||
// Hardcoded dangerous command patterns
|
||||
const dangerousCommands: Array<[RegExp, string]> = [
|
||||
[/rm\s+-rf\s+\//, 'rm -rf /'],
|
||||
[/mkfs/, 'filesystem format'],
|
||||
[/dd\s+if=/, 'disk write'],
|
||||
[/>\s*\/dev\//, 'device write'],
|
||||
[/\bsudo\b/, 'privilege escalation'],
|
||||
[/\bsu\s/, 'user switch'],
|
||||
[/chmod\s+777/, 'world-writable permission'],
|
||||
[/\bcurl\b.*\|.*\bbash\b/, 'curl-pipe-bash'],
|
||||
[/\bwget\b.*-O.*\s*-\s*\|/, 'wget-pipe'],
|
||||
];
|
||||
|
||||
for (const [pattern, label] of dangerousCommands) {
|
||||
for (const [pattern, label] of DANGEROUS_COMMANDS) {
|
||||
if (pattern.test(args.command)) {
|
||||
log.warn('[shell] Blocked dangerous command:', label);
|
||||
return {
|
||||
|
||||
Reference in New Issue
Block a user