Requirement 1 denies a GitHub write whose output is discarded or forced to success. Its scan already strips quoted argument values, so a --body that merely mentions a suppression token does not false-deny. It does not strip a heredoc body, so writing that same text through a heredoc does.
Hit twice in one session, both times doing ordinary work
Filing an issue whose body quotes a stderr redirect as prose, written with a heredoc into a file and then passed as --body-file to gh issue create, in one tool call. Denied. The heredoc body is data being written to a file, and the gh call carries no suppression at all.
Editing a pull request body that quotes the two fallback forms, the same shape. Denied for the same reason.
The workaround both times was to split the heredoc into its own tool call, which works and teaches nothing: the agent learns to split commands rather than that the rule has a scope gap.
Why this is worth fixing rather than living with
host-setup/agent-safety/claude/README.md states the bar: "a known false-positive shape is a parser defect to fix, not an accepted cost". This is a known shape now, with two occurrences in one session.
The mechanism already exists in the same file. #1622 added _strip_heredoc_bodies for requirement 7, which removes a heredoc body except one fed to a shell, since that one is the script the shell runs. Requirement 1's scan could take the same treatment, and the shell-fed exception is what keeps a genuinely suppressed write inside a shell-fed heredoc still denied.
Why it is not in #1622
That pull request is about requirements 7 and 8, and this changes what requirement 1 denies. A change to a write-safety rule deserves its own review rather than arriving at the end of a sixteen-commit branch, however small the diff.
A second, smaller thing found the same way
Writing this issue, the outer heredoc terminated early on a nested delimiter inside a fenced code block, which is the same terminator class #1622 fixed in the guard's own reader. Worth knowing that the shape bites an agent authoring documentation about it, not only the parser reading it.
Requirement 1 denies a GitHub write whose output is discarded or forced to success. Its scan already strips quoted argument values, so a
--bodythat merely mentions a suppression token does not false-deny. It does not strip a heredoc body, so writing that same text through a heredoc does.Hit twice in one session, both times doing ordinary work
Filing an issue whose body quotes a stderr redirect as prose, written with a heredoc into a file and then passed as
--body-filetogh issue create, in one tool call. Denied. The heredoc body is data being written to a file, and theghcall carries no suppression at all.Editing a pull request body that quotes the two fallback forms, the same shape. Denied for the same reason.
The workaround both times was to split the heredoc into its own tool call, which works and teaches nothing: the agent learns to split commands rather than that the rule has a scope gap.
Why this is worth fixing rather than living with
host-setup/agent-safety/claude/README.mdstates the bar: "a known false-positive shape is a parser defect to fix, not an accepted cost". This is a known shape now, with two occurrences in one session.The mechanism already exists in the same file. #1622 added
_strip_heredoc_bodiesfor requirement 7, which removes a heredoc body except one fed to a shell, since that one is the script the shell runs. Requirement 1's scan could take the same treatment, and the shell-fed exception is what keeps a genuinely suppressed write inside a shell-fed heredoc still denied.Why it is not in #1622
That pull request is about requirements 7 and 8, and this changes what requirement 1 denies. A change to a write-safety rule deserves its own review rather than arriving at the end of a sixteen-commit branch, however small the diff.
A second, smaller thing found the same way
Writing this issue, the outer heredoc terminated early on a nested delimiter inside a fenced code block, which is the same terminator class #1622 fixed in the guard's own reader. Worth knowing that the shape bites an agent authoring documentation about it, not only the parser reading it.