Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

fix(guardrails): block-root-delete-target judges backticks inside a quoted heredoc body

Open
#6,625 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
68/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
shell
Domain
security

Research direction

Start with plugins/guardrails/hooks/block-root-delete-target.sh and the hook-precision conventions in docs/conventions/hook-precision. Add a stay-quiet regression case for the quoted-heredoc payload, and verify that the unquoted-heredoc case remains refused. Done when both acceptance cases pass.

Written by the indexing model from the issue text.

Description

needs-triage priority: medium

Problem

block-root-delete-target refuses a command whose quoted heredoc body (<<'EOF') contains a backticked rm -rf span. The quoted delimiter makes the body inert text: bash runs no command substitution in it. The guard still lifts the backtick span out as a substitution and judges it.

Seen in practice: gh pr create --body-file - <<'EOF' with a PR body that quoted an example command in Markdown backticks was refused. The workaround was to write the body to a file.

Repro

Payload (stdin to plugins/guardrails/hooks/block-root-delete-target.sh):

{"tool_name":"Bash","tool_input":{"command":"cat <<'EOF'\nnote: `rm -rf /`\nEOF"},"cwd":"/"}

Actual: exit 2, "recursive delete of a filesystem root". Expected: exit 0, because the heredoc delimiter is quoted.

Acceptance

  • A stay-quiet case for the payload above fails before the fix (docs/conventions/hook-precision).
  • An unquoted heredoc (<<EOF) whose body holds `rm -rf /` stays refused, because bash does run that substitution.

Related: #6020, found while working #6542.

Dominant language
Shell
Stars
22
Forks
2
Avg merge
5h 15m
Merged PRs (30d)
833

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from melodic-software/claude-code-plugins

All issues in melodic-software/claude-code-plugins

Similar issues

More Shell/Bash issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.