Observed in .claude/plugins/data/plugin-quality-melodic-software/evidence/c7ff503b-19e2-40d2-b99e-38c747f7fc0f/guardrails-hooks/20260919T205610Z/audit-notes.md, finding F3 (auditor severity: MEDIUM), with the packet's evidence-1.md addenda A1, A2 and A3 applied.
The guard blocks Bash-tool writes to /tmp, telling the caller to use the platform temp directory. On Git for Windows that premise is false: the mount table shows C:/Users/KYLESE~1/AppData/Local/Temp on /tmp type ntfs (binary,noacl,posix=0,usertemp) and cygpath -w /tmp answers C:\Users\KYLESE~1\AppData\Local\Temp. The write already lands in %TEMP%, so every Bash-lane block is a false positive costing a retry turn. PowerShell is unaffected: no MSYS mount table.
A1: /etc/fstab here is the unmodified shipped Git for Windows file, cygdrive typo intact, and dotfiles are chezmoi-managed with no entry for it, so the class applies to any Git Bash on a stock install. A2: the only host gate in hooks/block-windows-drive-tmp.sh is case "${OSTYPE:-}" in at L105, with no cygpath, mount or %TEMP% resolution. A design premise that does not hold, not a broken check.
Hit live twice before probing: a documentation fetch (mkdir -p /tmp/audit-docs && curl ...), and a probe that merely mentioned /tmp inside a quoted string argument. Two retry turns on correct commands.
Same guard, opposite gap: curl -sS -o /tmp/audit/hooks.md https://example.com and wget -O /tmp/a.html https://example.com both pass (exit 0), while mkdir, redirect, tee and cp targets are blocked (exit 2). A3: creator patterns at L115-L117 list tee|mktemp|mkdir|touch|dd|tee.exe and the writer case at L416 adds install|cp|mv|install.exe; neither curl nor wget appears, though those two are the most common way an agent creates a file at a fetched path.
Cheapest fix: gate the Bash lane on the mount: when cygpath -w /tmp or the mount line for /tmp resolves under %TEMP%, do not block a Bash-tool /tmp target. One probe, cacheable per process, PowerShell unchanged. Scope limit from A2: bare /tmp only; /c/tmp, C:\tmp, D:\tmp and drive-root \tmp stay blocked on every lane. Second: add curl -o/--output and wget -O/--output-document operands to the command-lane target extraction. If the mount gate is contested, reword the message to state the condition rather than assert the resolution.
Verification: on a stock Git for Windows host, mkdir -p /tmp/x from the Bash tool exits 0, mkdir -p /c/tmp/x and the PowerShell equivalent still exit 2, and curl -o /tmp/x exits 2 after the second change.
🤖 Generated with Claude Code
https://claude.ai/code/session_01F7GFS5autRMSaea6kSoXzx
Observed in
.claude/plugins/data/plugin-quality-melodic-software/evidence/c7ff503b-19e2-40d2-b99e-38c747f7fc0f/guardrails-hooks/20260919T205610Z/audit-notes.md, finding F3 (auditor severity: MEDIUM), with the packet'sevidence-1.mdaddenda A1, A2 and A3 applied.The guard blocks Bash-tool writes to
/tmp, telling the caller to use the platform temp directory. On Git for Windows that premise is false: the mount table showsC:/Users/KYLESE~1/AppData/Local/Temp on /tmp type ntfs (binary,noacl,posix=0,usertemp)andcygpath -w /tmpanswersC:\Users\KYLESE~1\AppData\Local\Temp. The write already lands in%TEMP%, so every Bash-lane block is a false positive costing a retry turn. PowerShell is unaffected: no MSYS mount table.A1:
/etc/fstabhere is the unmodified shipped Git for Windows file,cygdrivetypo intact, and dotfiles are chezmoi-managed with no entry for it, so the class applies to any Git Bash on a stock install. A2: the only host gate inhooks/block-windows-drive-tmp.shiscase "${OSTYPE:-}" inat L105, with nocygpath,mountor%TEMP%resolution. A design premise that does not hold, not a broken check.Hit live twice before probing: a documentation fetch (
mkdir -p /tmp/audit-docs && curl ...), and a probe that merely mentioned/tmpinside a quoted string argument. Two retry turns on correct commands.Same guard, opposite gap:
curl -sS -o /tmp/audit/hooks.md https://example.comandwget -O /tmp/a.html https://example.comboth pass (exit 0), whilemkdir, redirect,teeandcptargets are blocked (exit 2). A3: creator patterns at L115-L117 listtee|mktemp|mkdir|touch|dd|tee.exeand the writer case at L416 addsinstall|cp|mv|install.exe; neithercurlnorwgetappears, though those two are the most common way an agent creates a file at a fetched path.Cheapest fix: gate the Bash lane on the mount: when
cygpath -w /tmpor themountline for/tmpresolves under%TEMP%, do not block a Bash-tool/tmptarget. One probe, cacheable per process, PowerShell unchanged. Scope limit from A2: bare/tmponly;/c/tmp,C:\tmp,D:\tmpand drive-root\tmpstay blocked on every lane. Second: addcurl -o/--outputandwget -O/--output-documentoperands to the command-lane target extraction. If the mount gate is contested, reword the message to state the condition rather than assert the resolution.Verification: on a stock Git for Windows host,
mkdir -p /tmp/xfrom the Bash tool exits 0,mkdir -p /c/tmp/xand the PowerShell equivalent still exit 2, andcurl -o /tmp/xexits 2 after the second change.🤖 Generated with Claude Code
https://claude.ai/code/session_01F7GFS5autRMSaea6kSoXzx