Expand description
Command safety detection module
Re-exported from vtcode-safety for backward compatibility.
Modules§
- audit
- Audit logging for command safety decisions.
- cache
- Caching layer for command safety decisions.
- command_
db - Command database: comprehensive safe command rules organized by category.
- dangerous_
commands - Detection of dangerous commands that should never be executed.
- safe_
command_ registry - Safe command registry: defines which commands and subcommands are safe to execute.
- shell_
parser - Shell script parser for
bash -lcand similar commands. - unified
- Unified Command Evaluator - Phase 5
Structs§
- Audit
Entry - A single command safety audit entry
- Command
Database - Database of command rules by category
- Evaluation
Result - Complete evaluation result
- Policy
Aware Evaluator - Policy-aware evaluator adapter for backward compatibility with CommandPolicyEvaluator
- Safe
Command Registry - Registry of safe commands and their safe subcommands/options
- Safety
Audit Logger - Audit logger for command safety decisions
- Safety
Decision Cache - Thread-safe cache for command safety decisions
- Unified
Command Evaluator - Unified command evaluator combining policies and safety rules
Enums§
- Evaluation
Reason - Detailed reason for evaluation result
- Safety
Decision - Result of a command safety check
Functions§
- command_
might_ be_ dangerous - Checks if a command appears dangerous to execute. Returns true if the command should be blocked before execution.
- command_
requires_ approval - Returns whether the command crosses an inline-code boundary that must be admitted by an enforceable sandbox or explicit human approval.
- git_
global_ option_ requires_ prompt - Returns whether a git global option can redirect repository, config, or helper lookup and therefore must not be treated as an inspection flag.
- parse_
bash_ lc_ commands - Parses
bash -lc "script"style invocations - shell_
string_ might_ be_ dangerous - Evaluate a shell command string by parsing it into subcommands and checking each with the centralized dangerous-command detector.
- validate_
command_ argv - Validate an explicit argv command without flattening argument boundaries
into shell text. Only an explicit shell
-c/-lcargument is parsed as a script; metacharacters in ordinary argv values remain literal. - validate_
command_ safety - Validates that a command is safe to execute.
- validate_
shell_ script - Validate an explicitly requested shell script through the Bash AST while
retaining legitimate compound-command boundaries. This is distinct from
validate_command_safety, whose raw-string compatibility API rejects unquoted chaining before execution intent is known.