feat(settings): rtk-wrapped allowlist + .env deny mirrors (audit #11 companion)
The rtk hook no longer auto-allows (audit-bugs branch): rewritten commands are evaluated natively. Allow rules match the original forms (grep *, ls *) not the rewritten ones — without explicit rules every rewrite would fall to the classifier. Added the read-only rtk-wrapped family, bare + absolute-path forms (the hook emits absolute paths when PATH lacks the cargo dir): grep, ls, cat, head, tail, wc, diff, git status/log/diff/show/branch. NOT find (rtk find could carry -exec rm — native find-deny rules would not match the rtk prefix). Deny mirrors guard the bypass the allowlist would open on hand-written 'rtk cat .env'-class commands: cat/grep/head/tail × .env, both prefixes. Residual: exotic quoting may evade the mirrors — second curtain stays the auto-mode classifier (BDR-004). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
This commit is contained in:
co-authored by
Claude Fable 5
parent
a0d092ca9f
commit
a73dff4edf
+35
-1
@@ -46,6 +46,32 @@
|
|||||||
"Bash(tr *)",
|
"Bash(tr *)",
|
||||||
"Bash(cut *)",
|
"Bash(cut *)",
|
||||||
"Bash(diff *)",
|
"Bash(diff *)",
|
||||||
|
"Bash(rtk grep *)",
|
||||||
|
"Bash(*/rtk grep *)",
|
||||||
|
"Bash(rtk ls)",
|
||||||
|
"Bash(rtk ls *)",
|
||||||
|
"Bash(*/rtk ls)",
|
||||||
|
"Bash(*/rtk ls *)",
|
||||||
|
"Bash(rtk cat *)",
|
||||||
|
"Bash(*/rtk cat *)",
|
||||||
|
"Bash(rtk head *)",
|
||||||
|
"Bash(*/rtk head *)",
|
||||||
|
"Bash(rtk tail *)",
|
||||||
|
"Bash(*/rtk tail *)",
|
||||||
|
"Bash(rtk wc *)",
|
||||||
|
"Bash(*/rtk wc *)",
|
||||||
|
"Bash(rtk diff *)",
|
||||||
|
"Bash(*/rtk diff *)",
|
||||||
|
"Bash(rtk git status)",
|
||||||
|
"Bash(*/rtk git status)",
|
||||||
|
"Bash(rtk git log*)",
|
||||||
|
"Bash(*/rtk git log*)",
|
||||||
|
"Bash(rtk git diff*)",
|
||||||
|
"Bash(*/rtk git diff*)",
|
||||||
|
"Bash(rtk git show*)",
|
||||||
|
"Bash(*/rtk git show*)",
|
||||||
|
"Bash(rtk git branch*)",
|
||||||
|
"Bash(*/rtk git branch*)",
|
||||||
"Read(**/*.md)",
|
"Read(**/*.md)",
|
||||||
"Read(**/*.txt)",
|
"Read(**/*.txt)",
|
||||||
"Read(**/*.json)",
|
"Read(**/*.json)",
|
||||||
@@ -165,7 +191,15 @@
|
|||||||
"Bash(xargs * .env*)",
|
"Bash(xargs * .env*)",
|
||||||
"Bash(tar * .env*)",
|
"Bash(tar * .env*)",
|
||||||
"Bash(zip * .env*)",
|
"Bash(zip * .env*)",
|
||||||
"Bash(base64 .env*)"
|
"Bash(base64 .env*)",
|
||||||
|
"Bash(rtk cat *.env*)",
|
||||||
|
"Bash(*/rtk cat *.env*)",
|
||||||
|
"Bash(rtk grep * .env*)",
|
||||||
|
"Bash(*/rtk grep * .env*)",
|
||||||
|
"Bash(rtk head *.env*)",
|
||||||
|
"Bash(*/rtk head *.env*)",
|
||||||
|
"Bash(rtk tail *.env*)",
|
||||||
|
"Bash(*/rtk tail *.env*)"
|
||||||
],
|
],
|
||||||
"ask": [
|
"ask": [
|
||||||
"Bash(git push *)",
|
"Bash(git push *)",
|
||||||
|
|||||||
Reference in New Issue
Block a user