Skip to content

Close three safety gaps, tidy two phrases, prepare 0.4.0 - #5

Merged
Sym-jay merged 1 commit into
mainfrom
safety-and-release
Oct 5, 2026
Merged

Sym-jay merged 1 commit into
mainfrom
safety-and-release

Conversation

@Sym-jay

@Sym-jay Sym-jay commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Safety check: three gaps closed

Each of these used to run with no warning:

Command Now
mv ~ /tmp/x, sudo mv /etc /tmp/old "moves a system-wide or home folder…"
x=rm; $x -rf /, cmd=reboot && sudo $cmd Caught by expanding variables set earlier on the same line
python3 -c "shutil.rmtree('/')", perl -e 'unlink …', node -e "fs.rmSync(…)" "runs a small program that deletes files or folders"
python3 -c "os.system('rm -rf ~')" Quoted strings in inline code are checked as shell commands

These are still not flagged: mv notes.txt ~, $EDITOR notes.txt (the variable is unknown, so there's nothing to judge), python3 -c "print(1+1)", a list's .remove(), and python3 -m http.server.

Phrases

  • "what's my ip" now uses hostname -I, so it works offline. "what's my public ip" still uses curl ifconfig.me.
  • Removed "check disk speed", which ran sudo hdparm on a disk.

Release prep

  • Version is now 0.4.0 in pyproject.toml and clishe.sh, and the changelog entry is dated.
  • Added demo.tape. Run vhs demo.tape on Linux to record demo.gif for the README. It uses temporary config and data folders and needs no AI provider.

Tests

23 new safety cases (dangerous and safe). All 429 pytest tests pass locally. Shell tests need bash 4+, so CI runs them.

🤖 Generated with Claude Code

- Safety: flag mv of home/system folders, command names hidden in a
  variable set on the same line (x=rm; $x -rf /), and inline interpreter
  code (python -c, perl -e, ruby -e, node -e, php -r) that deletes files
  or runs a risky shell command.
- "what's my ip" answers offline with hostname -I; drop the
  "check disk speed" phrase that ran sudo hdparm.
- Bump to 0.4.0 and date the changelog.
- Add demo.tape for recording the README GIF with VHS.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Sym-jay
Sym-jay merged commit 0a7820f into main Oct 5, 2026
3 checks passed
@Sym-jay
Sym-jay deleted the safety-and-release branch October 5, 2026 05:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants