Repository navigation
I feel that git-guardrails-claude-code isn't safe enough
#983
DavidSchuldenfrei
started this conversation in
Ideas
Replies: 1 comment
|
Spot-on observation regarding indirect execution via batch files. Simple string/command checks miss file-write payloads. A deterministic pre-execution layer needs to inspect the script buffer content before shell execution to catch wrapped commands. We handle this by evaluating the generated file payload against deterministic risk rules before passing sign-off back to the runner. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Although
git-guardrails-claude-codeblocks destructive Claude commands, it could still be bypassed easily.The agent could write the dangerous commands in a batch file, and then run the batch file. The dangerous commands would then be run without being invoked directly by the agent.
Because of this risk, I copy all the issues locally under a
.scratchfolder, commit them in my repo, and run the agent without any access to the remote git. It can only modify files which I mounted in the docker environment (inspired by sancastle). When the agent exits, I check what changes were made locally, and I push back to the remote branch (after deleting the scratch files).All reactions