From a73dff4edfcf52d3d067c2147fb4ba5a3b18f8f9 Mon Sep 17 00:00:00 2001 From: Bastien Chanot Date: Thu, 2 Jul 2026 14:29:53 +0200 Subject: [PATCH] feat(settings): rtk-wrapped allowlist + .env deny mirrors (audit #11 companion) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The rtk hook no longer auto-allows (audit-bugs branch): rewritten commands are evaluated natively. Allow rules match the original forms (grep *, ls *) not the rewritten ones — without explicit rules every rewrite would fall to the classifier. Added the read-only rtk-wrapped family, bare + absolute-path forms (the hook emits absolute paths when PATH lacks the cargo dir): grep, ls, cat, head, tail, wc, diff, git status/log/diff/show/branch. NOT find (rtk find could carry -exec rm — native find-deny rules would not match the rtk prefix). Deny mirrors guard the bypass the allowlist would open on hand-written 'rtk cat .env'-class commands: cat/grep/head/tail × .env, both prefixes. Residual: exotic quoting may evade the mirrors — second curtain stays the auto-mode classifier (BDR-004). Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR --- settings.json | 36 +++++++++++++++++++++++++++++++++++- 1 file changed, 35 insertions(+), 1 deletion(-) diff --git a/settings.json b/settings.json index cba2210..238b37f 100644 --- a/settings.json +++ b/settings.json @@ -46,6 +46,32 @@ "Bash(tr *)", "Bash(cut *)", "Bash(diff *)", + "Bash(rtk grep *)", + "Bash(*/rtk grep *)", + "Bash(rtk ls)", + "Bash(rtk ls *)", + "Bash(*/rtk ls)", + "Bash(*/rtk ls *)", + "Bash(rtk cat *)", + "Bash(*/rtk cat *)", + "Bash(rtk head *)", + "Bash(*/rtk head *)", + "Bash(rtk tail *)", + "Bash(*/rtk tail *)", + "Bash(rtk wc *)", + "Bash(*/rtk wc *)", + "Bash(rtk diff *)", + "Bash(*/rtk diff *)", + "Bash(rtk git status)", + "Bash(*/rtk git status)", + "Bash(rtk git log*)", + "Bash(*/rtk git log*)", + "Bash(rtk git diff*)", + "Bash(*/rtk git diff*)", + "Bash(rtk git show*)", + "Bash(*/rtk git show*)", + "Bash(rtk git branch*)", + "Bash(*/rtk git branch*)", "Read(**/*.md)", "Read(**/*.txt)", "Read(**/*.json)", @@ -165,7 +191,15 @@ "Bash(xargs * .env*)", "Bash(tar * .env*)", "Bash(zip * .env*)", - "Bash(base64 .env*)" + "Bash(base64 .env*)", + "Bash(rtk cat *.env*)", + "Bash(*/rtk cat *.env*)", + "Bash(rtk grep * .env*)", + "Bash(*/rtk grep * .env*)", + "Bash(rtk head *.env*)", + "Bash(*/rtk head *.env*)", + "Bash(rtk tail *.env*)", + "Bash(*/rtk tail *.env*)" ], "ask": [ "Bash(git push *)",