Skip to content

fix(permissions): deny safe-read auto-approval for shell redirections - #85

Closed
SeashoreShi wants to merge 1 commit into
cosmicstack-labs:mainfrom
SeashoreShi:fix/safe-read-redirection-bypass
Closed

fix(permissions): deny safe-read auto-approval for shell redirections#85
SeashoreShi wants to merge 1 commit into
cosmicstack-labs:mainfrom
SeashoreShi:fix/safe-read-redirection-bypass

Conversation

@SeashoreShi

@SeashoreShi SeashoreShi commented Jun 29, 2026

Copy link
Copy Markdown

Closing: the same fix (redirection detection in safe-read auto-approval) was merged upstream in #111 (isSafeReadSegment now rejects >, >>, <, <<, &> segments). Our branch is now redundant. Thanks!

@SeashoreShi

Copy link
Copy Markdown
Author

Friendly ping: this security fix (safe-read auto-approval bypass via shell redirection) is still open with a clean mergeable state. The branch is based on an older main — happy to rebase if that would help get it reviewed. Tests pass locally (npm test -- src/capabilities/permissions.test.ts + typecheck).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant