Skip to main content

Module command_safety

Module command_safety 

Source
Expand description

Command safety detection module

Re-exported from vtcode-safety for backward compatibility.

Modules§

audit
Audit logging for command safety decisions.
cache
Caching layer for command safety decisions.
command_db
Command database: comprehensive safe command rules organized by category.
dangerous_commands
Detection of dangerous commands that should never be executed.
safe_command_registry
Safe command registry: defines which commands and subcommands are safe to execute.
shell_parser
Shell script parser for bash -lc and similar commands.
unified
Unified Command Evaluator - Phase 5

Structs§

AuditEntry
A single command safety audit entry
CommandDatabase
Database of command rules by category
EvaluationResult
Complete evaluation result
PolicyAwareEvaluator
Policy-aware evaluator adapter for backward compatibility with CommandPolicyEvaluator
SafeCommandRegistry
Registry of safe commands and their safe subcommands/options
SafetyAuditLogger
Audit logger for command safety decisions
SafetyDecisionCache
Thread-safe cache for command safety decisions
UnifiedCommandEvaluator
Unified command evaluator combining policies and safety rules

Enums§

EvaluationReason
Detailed reason for evaluation result
SafetyDecision
Result of a command safety check

Functions§

command_might_be_dangerous
Checks if a command appears dangerous to execute. Returns true if the command should be blocked before execution.
command_requires_approval
Returns whether the command crosses an inline-code boundary that must be admitted by an enforceable sandbox or explicit human approval.
git_global_option_requires_prompt
Returns whether a git global option can redirect repository, config, or helper lookup and therefore must not be treated as an inspection flag.
parse_bash_lc_commands
Parses bash -lc "script" style invocations
shell_string_might_be_dangerous
Evaluate a shell command string by parsing it into subcommands and checking each with the centralized dangerous-command detector.
validate_command_argv
Validate an explicit argv command without flattening argument boundaries into shell text. Only an explicit shell -c/-lc argument is parsed as a script; metacharacters in ordinary argv values remain literal.
validate_command_safety
Validates that a command is safe to execute.
validate_shell_script
Validate an explicitly requested shell script through the Bash AST while retaining legitimate compound-command boundaries. This is distinct from validate_command_safety, whose raw-string compatibility API rejects unquoted chaining before execution intent is known.