fix(guardrails): block-root-delete-target judges backticks inside a quoted heredoc body
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 68/100
Research direction
Start with plugins/guardrails/hooks/block-root-delete-target.sh and the hook-precision conventions in docs/conventions/hook-precision. Add a stay-quiet regression case for the quoted-heredoc payload, and verify that the unquoted-heredoc case remains refused. Done when both acceptance cases pass.
Written by the indexing model from the issue text.
Description
Problem
block-root-delete-target refuses a command whose quoted heredoc body (<<'EOF') contains a backticked rm -rf span. The quoted delimiter makes the body inert text: bash runs no command substitution in it. The guard still lifts the backtick span out as a substitution and judges it.
Seen in practice: gh pr create --body-file - <<'EOF' with a PR body that quoted an example command in Markdown backticks was refused. The workaround was to write the body to a file.
Repro
Payload (stdin to plugins/guardrails/hooks/block-root-delete-target.sh):
{"tool_name":"Bash","tool_input":{"command":"cat <<'EOF'\nnote: `rm -rf /`\nEOF"},"cwd":"/"}
Actual: exit 2, "recursive delete of a filesystem root". Expected: exit 0, because the heredoc delimiter is quoted.
Acceptance
- A stay-quiet case for the payload above fails before the fix (docs/conventions/hook-precision).
- An unquoted heredoc (
<<EOF) whose body holds`rm -rf /`stays refused, because bash does run that substitution.
Related: #6020, found while working #6542.
- Dominant language
- Shell
- Stars
- 22
- Forks
- 2
- Avg merge
- 5h 15m
- Merged PRs (30d)
- 833
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from melodic-software/claude-code-plugins
-
good first issue needs-triage priority: medium
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
melodic-software/claude-code-plugins#6631 · 1 comment ·
Maintainers usually reply within 1 day
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
melodic-software/claude-code-plugins#6547 ·
Maintainers usually reply within 1 day
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
melodic-software/claude-code-plugins#6535 ·
Maintainers usually reply within 1 day
-
test_comment_census.py: SccArgv flag-shaped-filename test errors on Windows (#!/bin/sh scc shim)Opengood first issue needs-triage priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
melodic-software/claude-code-plugins#6532 · 1 comment ·
Maintainers usually reply within 1 day
-
good first issue needs-triage priority: low
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
melodic-software/claude-code-plugins#6390 · 1 comment ·
Maintainers usually reply within 1 day
All issues in melodic-software/claude-code-plugins
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
influxdata/openapi#660 ·
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
Maintainers usually reply within 3 days
-
`check_java_version()` fails when Java path contains spaces (Windows / Git Bash, `C:\Program Files`)Open
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
egoist/mygo#175 · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day