summaryrefslogtreecommitdiff
path: root/constrain/vr-only-guard.sh
diff options
context:
space:
mode:
authorGabriel Schneider <[email protected]>2026-07-24 11:39:36 -0300
committerGabriel Schneider <[email protected]>2026-07-30 15:18:55 -0300
commitcb05c363045bf0e7af5858f6d7bc26f026fa9d70 (patch)
treec3e89426ff044ffe339dd3a77e7f3b7115cba636 /constrain/vr-only-guard.sh
downloadnotevi-cb05c363045bf0e7af5858f6d7bc26f026fa9d70.tar.gz
notevi-cb05c363045bf0e7af5858f6d7bc26f026fa9d70.zip
Diffstat (limited to 'constrain/vr-only-guard.sh')
-rwxr-xr-xconstrain/vr-only-guard.sh19
1 files changed, 19 insertions, 0 deletions
diff --git a/constrain/vr-only-guard.sh b/constrain/vr-only-guard.sh
new file mode 100755
index 0000000..0de698f
--- /dev/null
+++ b/constrain/vr-only-guard.sh
@@ -0,0 +1,19 @@
+#!/bin/sh
+# Claude Code PreToolUse hook (matcher: Bash): deny shell commands that read
+# files without going through vr. A guardrail, not a jail — it catches the
+# common readers at command position, not every conceivable bypass.
+cmd=$(jq -r '.tool_input.command // empty')
+
+readers='cat|head|tail|less|more|sed|awk|cut|rg|grep|egrep|fgrep|find|fd|strings|xxd|hexdump|od|tac|nl'
+pattern='(^|[;&|(`]|\$\()[[:space:]]*('$readers')([[:space:]]|$)'
+
+if printf '%s' "$cmd" | grep -qE "$pattern"; then
+ echo "blocked: read/search files only through vr (run 'vr -doc' for usage)" >&2
+ exit 2
+fi
+vcs='jj[[:space:]]+(file[[:space:]]+show|diff)|git[[:space:]]+(show|diff|grep|cat-file|blame|log)'
+if printf '%s' "$cmd" | grep -qE "(^|[;&|(\`])[[:space:]]*($vcs)"; then
+ echo "blocked: use 'vr read -r REV FILE' / 'vr grep -r REV' instead of raw jj/git reads" >&2
+ exit 2
+fi
+exit 0