feat(settings): rtk-wrapped allowlist + .env deny mirrors (audit #11 companion)

The rtk hook no longer auto-allows (audit-bugs branch): rewritten
commands are evaluated natively. Allow rules match the original forms
(grep *, ls *) not the rewritten ones — without explicit rules every
rewrite would fall to the classifier. Added the read-only rtk-wrapped
family, bare + absolute-path forms (the hook emits absolute paths when
PATH lacks the cargo dir): grep, ls, cat, head, tail, wc, diff, git
status/log/diff/show/branch. NOT find (rtk find could carry -exec rm —
native find-deny rules would not match the rtk prefix).
Deny mirrors guard the bypass the allowlist would open on hand-written
'rtk cat .env'-class commands: cat/grep/head/tail × .env, both prefixes.
Residual: exotic quoting may evade the mirrors — second curtain stays
the auto-mode classifier (BDR-004).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016zA3Qh2Q1QpcGXzXxKeDHR
This commit is contained in:
Bastien Chanot
2026-07-02 14:29:53 +02:00
co-authored by Claude Fable 5
parent a0d092ca9f
commit a73dff4edf
+35 -1
View File
@@ -46,6 +46,32 @@
"Bash(tr *)",
"Bash(cut *)",
"Bash(diff *)",
"Bash(rtk grep *)",
"Bash(*/rtk grep *)",
"Bash(rtk ls)",
"Bash(rtk ls *)",
"Bash(*/rtk ls)",
"Bash(*/rtk ls *)",
"Bash(rtk cat *)",
"Bash(*/rtk cat *)",
"Bash(rtk head *)",
"Bash(*/rtk head *)",
"Bash(rtk tail *)",
"Bash(*/rtk tail *)",
"Bash(rtk wc *)",
"Bash(*/rtk wc *)",
"Bash(rtk diff *)",
"Bash(*/rtk diff *)",
"Bash(rtk git status)",
"Bash(*/rtk git status)",
"Bash(rtk git log*)",
"Bash(*/rtk git log*)",
"Bash(rtk git diff*)",
"Bash(*/rtk git diff*)",
"Bash(rtk git show*)",
"Bash(*/rtk git show*)",
"Bash(rtk git branch*)",
"Bash(*/rtk git branch*)",
"Read(**/*.md)",
"Read(**/*.txt)",
"Read(**/*.json)",
@@ -165,7 +191,15 @@
"Bash(xargs * .env*)",
"Bash(tar * .env*)",
"Bash(zip * .env*)",
"Bash(base64 .env*)"
"Bash(base64 .env*)",
"Bash(rtk cat *.env*)",
"Bash(*/rtk cat *.env*)",
"Bash(rtk grep * .env*)",
"Bash(*/rtk grep * .env*)",
"Bash(rtk head *.env*)",
"Bash(*/rtk head *.env*)",
"Bash(rtk tail *.env*)",
"Bash(*/rtk tail *.env*)"
],
"ask": [
"Bash(git push *)",