Skip to content

Requirement 1 false-denies a GitHub write whose heredoc body merely quotes a suppression token #1628

Description

@ptr727

Requirement 1 denies a GitHub write whose output is discarded or forced to success. Its scan already strips quoted argument values, so a --body that merely mentions a suppression token does not false-deny. It does not strip a heredoc body, so writing that same text through a heredoc does.

Hit twice in one session, both times doing ordinary work

Filing an issue whose body quotes a stderr redirect as prose, written with a heredoc into a file and then passed as --body-file to gh issue create, in one tool call. Denied. The heredoc body is data being written to a file, and the gh call carries no suppression at all.

Editing a pull request body that quotes the two fallback forms, the same shape. Denied for the same reason.

The workaround both times was to split the heredoc into its own tool call, which works and teaches nothing: the agent learns to split commands rather than that the rule has a scope gap.

Why this is worth fixing rather than living with

host-setup/agent-safety/claude/README.md states the bar: "a known false-positive shape is a parser defect to fix, not an accepted cost". This is a known shape now, with two occurrences in one session.

The mechanism already exists in the same file. #1622 added _strip_heredoc_bodies for requirement 7, which removes a heredoc body except one fed to a shell, since that one is the script the shell runs. Requirement 1's scan could take the same treatment, and the shell-fed exception is what keeps a genuinely suppressed write inside a shell-fed heredoc still denied.

Why it is not in #1622

That pull request is about requirements 7 and 8, and this changes what requirement 1 denies. A change to a write-safety rule deserves its own review rather than arriving at the end of a sixteen-commit branch, however small the diff.

A second, smaller thing found the same way

Writing this issue, the outer heredoc terminated early on a nested delimiter inside a fenced code block, which is the same terminator class #1622 fixed in the guard's own reader. Worth knowing that the shape bites an agent authoring documentation about it, not only the parser reading it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agentsAgents instructions

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions