Skip to content

guardrails: secret-pattern-detection never scans NotebookEdit cell source #4478

Description

@kyle-sexton

Observed

plugins/guardrails/hooks/secret-pattern-detection.sh never scans a NotebookEdit call. A
NotebookEdit payload whose tool_input.new_source carries a GitHub PAT-shaped token returns
exit 0, both from the hook alone and through the run-guards.sh dispatcher row that hooks.json
wires to Write|Edit|MultiEdit|NotebookEdit. A Write of the same content to the same path
returns exit 2.

Cause

The hook takes its target from .tool_input.file_path only and exits 0 when that is empty. A
NotebookEdit call sends notebook_path instead (Agent SDK TypeScript reference,
NotebookEditInput: notebook_path, cell_id, new_source, cell_type, edit_mode). The suite
did not catch it because its notebook_json test helper builds a NotebookEdit payload with a
file_path key that Claude Code never sends.

Same omission elsewhere

hardcoded-path-check.sh reads the same fields and has the same gap (a notebook_path payload
with a machine path in new_source returns 0; the helper's file_path shape returns 2).

Ask

Scan NotebookEdit cell source the way Write/Edit content is scanned, with the same scope,
allowlist, and temp-tree decline, and pin real-shape cases.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions