Skip to main content

Module commands

Module commands 

Source
Expand description

Command safety validation.

This module re-exports validate_command_safety from the canonical command_safety module. All dangerous-command detection, injection pattern detection, and shell parsing live in command_safety/.

Functionsยง

validate_command_argv
Validate an explicit argv command without flattening argument boundaries into shell text. Only an explicit shell -c/-lc argument is parsed as a script; metacharacters in ordinary argv values remain literal.
validate_command_safety
Validates that a command is safe to execute.
validate_shell_script
Validate an explicitly requested shell script through the Bash AST while retaining legitimate compound-command boundaries. This is distinct from validate_command_safety, whose raw-string compatibility API rejects unquoted chaining before execution intent is known.