Skip to content

guardrails: all guards run after a block, and the README does not document the PowerShell over-blocks #4236

Description

@kyle-sexton

Problem

Session: Windows 11, Claude Code 2.1.278, auto mode, guardrails 0.35.0, PowerShell lane.

Root cause

Traced by reading the installed source; not executed (the audit session's Bash tool was blocked by another plugin, so nothing was profiled and packet integrity is ungradable).

F5. The dispatcher runs every guard after a block.

  • run-guards.sh lines 367-393: run_from sources every remaining guard after one exits 2. The code only raises RC (lines 346-347) and never stops early.
  • On the PowerShell lane, 8 guards run, and the ps-command.sh library is sourced once per event (lines 126-131). That is 2300+ lines of bash parsed on every PowerShell call.
  • RUN_GUARDS_PROFILE=1 (lines 340-345) is the built-in way to measure. Not run.

F6. README gap.

Related: #3508, #3623 (hook performance).

Proposed fix

Cheapest first:

  1. README, block-hook-bypass section: & $var script arg1 arg2 (a call through a variable followed by two or more positionals with at least one bare word) is blocked as a file write. Rewrite it as & 'C:/literal/path.exe' script args, or put a flag first.
  2. README, PowerShell sink section: a foreach { git ... } loop is refused by the git guards regardless of verb. Unroll it into flat git -C <path> ...; statements.
  3. Profile the allow path with RUN_GUARDS_PROFILE=1 on a Windows host to confirm or refute the per-call cost.
  4. Stop after the first block. This removes duplicate denial paragraphs and saves time on the block path. Weigh it against losing all reasons in one denial.

Acceptance criteria

  • README's block-hook-bypass section documents the & $var positional rule and the literal-path rewrite.
  • README's PowerShell sink section documents the {} / () git refusal and the unrolled-statement rewrite.
  • A command blocked by two guards produces at most one full-length denial paragraph.
  • A RUN_GUARDS_PROFILE=1 measurement of the PowerShell allow path on Windows is recorded in the issue or the README.

Found by /plugin-quality:audit (run 20260919T170952Z).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.priority: lowNice-to-have, cosmetic, or speculative; opportunistic.status: readyTriaged, unblocked, and fully specified; eligible to pick up.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions