Skip to content

guardrails: secret-pattern-detection blocks a temp-tree Write that block-hook-bypass exempts for Bash #4471

Description

@kyle-sexton

Problem

Since #4394, block-hook-bypass exempts a Bash redirect into a host temp tree when CLAUDE_PROJECT_DIR names a
project root outside that tree. secret-pattern-detection has no matching decline. With a root the scanner clears as
a scope (home, or a folder that is not a git work tree), a Write of a secret to a temp file is blocked while the
same content written with echo … > <same temp path> passes.

Measured on main dbed107 on a Windows host, with a synthetic ghp_ token and target
C:/Users/<user>/AppData/Local/Temp/vetprobe-d1/f.txt:

root Write (secret-pattern-detection) Bash (block-hook-bypass)
$HOME 2 0
/c/srv-nonrepo (not a repo) 2 0

This also falsifies the README's "exempting it gives up no protection" paragraph for the temp default. The other
guardrails Write|Edit gates (hardcoded-path-check, block-windows-drive-tmp) already return 0 on these payloads.

Expected

secret-pattern-detection declines a temp-tree target under the same gate as the Bash temp default, and never more
widely. Membership is decided by physically resolving the target's nearest existing ancestor, not by its spelling
alone. The common (non-temp) path stays fork-free.

Out of scope

  • 8.3 short-name acceptance.
  • Block-message verbosity part 2.
  • Windows CI coverage of block-hook-bypass.test.sh.
  • Narrowing both guards to scratchpad_dir (Option E).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions