fix: say a blocked shell call ran none of its chained commands - #170
Merged
ryzizub merged 1 commit intoOct 5, 2026
Conversation
block-cli-workarounds refuses the whole shell call, so a command chained with the blocked one (`edit-a-file && dart test`) never runs either. The deny reason only said to use the MCP tool, so an agent could assume the chained command's side effect happened and carry on without it. Every deny reason from this hook now says the whole call was refused. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
mark-wint
marked this pull request as ready for review
October 2, 2026 14:11
ryzizub
approved these changes
Oct 5, 2026
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
block-cli-workarounds.shrefuses the whole shell call, so a command chained with the blocked one never runs either. The deny reason only said "Use the very_good_cli MCP 'test' tool instead", which doesn't tell the agent that the rest of the call was dropped too.This happened in a real session: an agent ran
python3 <edit pubspec.yaml> && dart testin one call. The hook refused it, the agent switched to the MCPtesttool, and it carried on as if the pubspec edit had gone through. It found the missing dependency 13 minutes later, only because agit diffhappened to show the file unchanged. Across 175 sessions in one repo, the hook fired in 15.Every deny reason from this hook (current, outdated, missing, or unrunnable CLI) now ends with:
hooks/scripts/block-cli-workarounds.sh: adds the sentence to all four deny branches.hooks/scripts/block-cli-workarounds_test.sh: adds four cases, one per CLI status, asserting that a chained command's deny reason says so. They fail againstmain(44 passed, 4 failed) and pass with this change (48 passed).CLAUDE.md: notes the behavior in the hook's description.Type of Change
feat)fix)refactor)docs)ci)chore)🤖 Generated with Claude Code