llm-security/hooks
Kjell Tore Guttormsen b6edfa3ceb
refactor(hooks): split two rule names so no download-into-shell literal sits on disk
pre-bash-destructive.mjs held the last three probe (e) hits: the
pipe-to-shell and T8 rule names and one comment. The names are now
concatenated from fragments and the comment is a description; the
string the hook prints is unchanged, and tests/golden/reference-run.json
pins it. Patterns untouched.

Applied by the operator (git apply): the installed plugin's path guard
blocks Edit/Write on this file and asks the user to make the change.

Measured: hook stderr for a pipe-to-shell and a T8 command is
byte-identical before/after (cmp); av-surface a=0 a2=0 b=0 c=0 d=0 e=0;
suite 2269 / 2263 pass / 0 fail / 6 skip, exit 0; golden unchanged
(109/7/4, reference run 61/61).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-22 14:30:32 +02:00
..
scripts refactor(hooks): split two rule names so no download-into-shell literal sits on disk 2026-09-22 14:30:32 +02:00
hooks.json fix(llm-security): hook coverage — pathguard on Edit, trifecta window, pipe-to-shell, provider keys (#9,#10,#12,#13,#11-doc) 2026-07-18 10:36:39 +02:00