Document safe parsing for preToolUse.toolArgs when it is a JSON-encoded string

Abierto Apto para principiantes
#3,349 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
68/100
Tipo de issue
Documentación
Claridad
Bastante claro
Estado de actividad
Tranquilo
Stack tecnológico
python, shell

Línea de trabajo

Empieza por la referencia de Hooks y su sección sobre la carga útil de preToolUse. Documenta que toolArgs puede ser una cadena codificada en JSON y, después, añade ejemplos seguros de análisis en Bash y Python que gestionen valores no válidos o que no sean objetos; se considera terminado cuando quienes escriben hooks pueden inspeccionar de forma fiable campos como command, path o url.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

area:plugins

Summary

The Hooks reference documents preToolUse.toolArgs as unknown, but does not show how hook authors should safely parse it.

In actual Copilot CLI hook invocations I tested, toolArgs arrived as a JSON-encoded string rather than a parsed object. That may be valid under the current unknown contract, but it is easy for hook authors to assume object-style access and accidentally write hooks that fail to inspect tool arguments.

Because hook failures are fail-open, this is a security footgun for policy-enforcing hooks.

Observed behavior

For preToolUse, the documentation shows the camelCase payload shape as:

{
    sessionId: string;
    timestamp: number;
    cwd: string;
    toolName: string;
    toolArgs: unknown;
}

In tested CLI/App-backed hook invocations, the payload effectively behaved like:

{
  "toolName": "bash",
  "toolArgs": "{\"command\":\"echo hello\"}"
}

rather than:

{
  "toolName": "bash",
  "toolArgs": {
    "command": "echo hello"
  }
}

I am not claiming the string form is invalid. Since the schema says unknown, this may be intentional or implementation-defined. The problem is that the docs do not tell hook authors how to handle it safely.

Why this matters

Security hooks commonly inspect fields like:

.toolArgs.command
.toolArgs.path
.toolArgs.url

If toolArgs is a JSON-encoded string, this kind of access does not work as expected. Depending on the script and shell settings, the hook may fail, emit invalid output, or skip the intended check.

Since hook failures are fail-open, a parsing mistake can silently bypass a security policy.

Request

Please document the expected handling for toolArgs and provide safe parsing examples.

At minimum, the docs should say something like:

toolArgs is unknown and may be a JSON-encoded string. Hook scripts should check its runtime type and parse it before inspecting tool arguments.

A Bash example would help:

INPUT="$(cat)"

TOOL_ARGS_JSON="$(
  jq -c '
    (.toolArgs // .tool_args // .tool_input // {}) as $args
    | if ($args | type) == "string" then ($args | fromjson? // {}) else $args end
  ' <<< "$INPUT"
)"

COMMAND="$(jq -r '.command // ""' <<< "$TOOL_ARGS_JSON")"

Python example:

import json
import sys

payload = json.load(sys.stdin)
tool_args = payload.get("toolArgs", payload.get("tool_input", {}))

if isinstance(tool_args, str):
    try:
        tool_args = json.loads(tool_args)
    except json.JSONDecodeError:
        tool_args = {}

if not isinstance(tool_args, dict):
    tool_args = {}

command = tool_args.get("command", "")

Expected improvement

This would make hook authoring safer, especially for security-focused preToolUse hooks, and reduce the chance of fail-open bypasses caused by incorrect assumptions about the runtime type of toolArgs.

Lenguaje dominante
Shell
Estrellas
11.2k
Forks
1.9k
Merge medio
14 h 16 min
PR fusionados (30 d)
6

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/copilot-cli

Todos los issues de github/copilot-cli

Issues similares

Más issues de Shell/Bash

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.