Document safe parsing for preToolUse.toolArgs when it is a JSON-encoded string
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Documentación
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Área
- documentation, security
Línea de trabajo
Empieza por la referencia de Hooks y su sección sobre la carga útil de preToolUse. Documenta que toolArgs puede ser una cadena codificada en JSON y, después, añade ejemplos seguros de análisis en Bash y Python que gestionen valores no válidos o que no sean objetos; se considera terminado cuando quienes escriben hooks pueden inspeccionar de forma fiable campos como command, path o url.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
The Hooks reference documents preToolUse.toolArgs as unknown, but does not show how hook authors should safely parse it.
In actual Copilot CLI hook invocations I tested, toolArgs arrived as a JSON-encoded string rather than a parsed object. That may be valid under the current unknown contract, but it is easy for hook authors to assume object-style access and accidentally write hooks that fail to inspect tool arguments.
Because hook failures are fail-open, this is a security footgun for policy-enforcing hooks.
Observed behavior
For preToolUse, the documentation shows the camelCase payload shape as:
{
sessionId: string;
timestamp: number;
cwd: string;
toolName: string;
toolArgs: unknown;
}
In tested CLI/App-backed hook invocations, the payload effectively behaved like:
{
"toolName": "bash",
"toolArgs": "{\"command\":\"echo hello\"}"
}
rather than:
{
"toolName": "bash",
"toolArgs": {
"command": "echo hello"
}
}
I am not claiming the string form is invalid. Since the schema says unknown, this may be intentional or implementation-defined. The problem is that the docs do not tell hook authors how to handle it safely.
Why this matters
Security hooks commonly inspect fields like:
.toolArgs.command
.toolArgs.path
.toolArgs.url
If toolArgs is a JSON-encoded string, this kind of access does not work as expected. Depending on the script and shell settings, the hook may fail, emit invalid output, or skip the intended check.
Since hook failures are fail-open, a parsing mistake can silently bypass a security policy.
Request
Please document the expected handling for toolArgs and provide safe parsing examples.
At minimum, the docs should say something like:
toolArgsisunknownand may be a JSON-encoded string. Hook scripts should check its runtime type and parse it before inspecting tool arguments.
A Bash example would help:
INPUT="$(cat)"
TOOL_ARGS_JSON="$(
jq -c '
(.toolArgs // .tool_args // .tool_input // {}) as $args
| if ($args | type) == "string" then ($args | fromjson? // {}) else $args end
' <<< "$INPUT"
)"
COMMAND="$(jq -r '.command // ""' <<< "$TOOL_ARGS_JSON")"
Python example:
import json
import sys
payload = json.load(sys.stdin)
tool_args = payload.get("toolArgs", payload.get("tool_input", {}))
if isinstance(tool_args, str):
try:
tool_args = json.loads(tool_args)
except json.JSONDecodeError:
tool_args = {}
if not isinstance(tool_args, dict):
tool_args = {}
command = tool_args.get("command", "")
Expected improvement
This would make hook authoring safer, especially for security-focused preToolUse hooks, and reduce the chance of fail-open bypasses caused by incorrect assumptions about the runtime type of toolArgs.
- Lenguaje dominante
- Shell
- Estrellas
- 11.2k
- Forks
- 1.9k
- Merge medio
- 14 h 16 min
- PR fusionados (30 d)
- 6
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/copilot-cli
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4848 ·
-
area:agents area:mcp
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4729 ·
-
area:sessions
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/copilot-cli#4712 ·
-
triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
github/copilot-cli#4638 ·
-
Expose large_output_file_path on TaskShellProgress so clients can read complete shell-task output Abiertoarea:tools
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
github/copilot-cli#4630 · 1 comentario ·
Todos los issues de github/copilot-cli
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
danielmiessler/LifeOS#2218 ·
-
docs(agents): strengthen the no-backslash-escaped-backticks rule with an issue-creation example Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 92/100
-
technical-debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
ll7/robot_sf_ll7#9560 ·
-
Update ghgrab to 2.1.0 Abiertopackage-update
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
oSoWoSo/vOid_Community_repOsitory#148 · 1 comentario ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100