From 29f4dc7ab494763a62519e9177424111dae381d3 Mon Sep 17 00:00:00 2001 From: bastien Date: Wed, 30 Sep 2026 19:23:27 +0200 Subject: [PATCH] feat(settings): soft-deny global npm installs until the user names the package The literal deny patterns miss spellings such as `npm i -g`. The classifier entry covers every form and asks for a vetting summary (publisher, age, downloads, install scripts, advisories) first. --- CHANGELOG.md | 1 + settings.json | 1 + 2 files changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 371b9df..cd8ffed 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -401,6 +401,7 @@ Format follows [Keep a Changelog](https://keepachangelog.com/). `verification-before-completion` to the verifier gates. ### Security +- `settings.json` `autoMode.soft_deny` gains a "Global npm installs" entry: every spelling of a global install is held until the user names the package in the turn, and Claude states the publisher, age, download volume, install scripts and known advisories first. It covers the forms the literal `deny` patterns miss. - `settings.json` `permissions.deny` now refuses three more spellings of a global npm install (`npm i -g`, `npm install --global`, `npm i --global`): the rule matched `npm install -g` only. Not a complete list: forms with the flag after the package name, such as `npm i -g`, still pass. - **Ten secret-reader deny rules added**: `sed`, `awk`, `cut`, `tr`, `sort`, `uniq`, `diff`, `od`, `xxd`, `strings` against `.env*`. Six of diff --git a/settings.json b/settings.json index c99289a..bc35b4c 100644 --- a/settings.json +++ b/settings.json @@ -469,6 +469,7 @@ "Docker data destruction on this workstation: `docker rm -f` of a container, and `docker run` with a bind mount outside the current working directory or the session temp dir (volume drops, `system prune`, `compose down -v` and `--privileged` are static deny rules and cannot be cleared). Clear only when the user named the container or the mount in this turn.", "Discarding uncommitted work: `git checkout -- ` or `git checkout .`, `git restore` without `--staged`, `git stash pop` onto a dirty tree, or overwriting a modified tracked file with `cp` or `mv`. Git recovers a committed state, not this. Clear only when the user asked to discard those exact changes in this turn.", "Undeclared node packages: `npx `, `pnpm dlx` or `yarn dlx` of a package absent from the manifest and lockfile runs code fetched at call time; `npm install ` or `pnpm add ` adds a dependency the house rule requires naming first. Clear only when the user named the package in this turn.", + "Global npm installs: `npm install -g`, `npm i -g`, `npm add -g`, the `--global` spellings and a flag placed after the package name. A global package runs its install scripts with the user's rights on the whole machine. Before running one, state the package, its publisher, its age and download volume, whether it carries install scripts, and any known advisory. Clear only when the user named the package in this turn.", "Publishing to the 21st.dev public catalog: `21st publish`, `publish-theme`, `publish-template`, `publish-gradient`, `publish-ascii`, `submit` and `resubmit` push a component, theme or template from this machine onto a public listing under the user's account; `21st edit`, `delete`, `withdraw`, `remove-from-catalog` and `21st profile set|upload` change or remove what is already published there. Retrieval and generation (`search`, `logo`, `get`, `add`, `generate`, `iterate`) are ordinary design work and pass. Clear only when the user asked to publish or change that specific item in this turn." ], "hard_deny": [