Expand description
Command safety validation.
This module re-exports validate_command_safety from the canonical
command_safety module. All dangerous-command detection, injection
pattern detection, and shell parsing live in command_safety/.
Functionsยง
- validate_
command_ argv - Validate an explicit argv command without flattening argument boundaries
into shell text. Only an explicit shell
-c/-lcargument is parsed as a script; metacharacters in ordinary argv values remain literal. - validate_
command_ safety - Validates that a command is safe to execute.
- validate_
shell_ script - Validate an explicitly requested shell script through the Bash AST while
retaining legitimate compound-command boundaries. This is distinct from
validate_command_safety, whose raw-string compatibility API rejects unquoted chaining before execution intent is known.