From cb05c363045bf0e7af5858f6d7bc26f026fa9d70 Mon Sep 17 00:00:00 2001 From: Gabriel Schneider Date: Fri, 24 Jul 2026 11:39:36 -0300 Subject: --- constrain/vr-only-guard.sh | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100755 constrain/vr-only-guard.sh (limited to 'constrain/vr-only-guard.sh') diff --git a/constrain/vr-only-guard.sh b/constrain/vr-only-guard.sh new file mode 100755 index 0000000..0de698f --- /dev/null +++ b/constrain/vr-only-guard.sh @@ -0,0 +1,19 @@ +#!/bin/sh +# Claude Code PreToolUse hook (matcher: Bash): deny shell commands that read +# files without going through vr. A guardrail, not a jail — it catches the +# common readers at command position, not every conceivable bypass. +cmd=$(jq -r '.tool_input.command // empty') + +readers='cat|head|tail|less|more|sed|awk|cut|rg|grep|egrep|fgrep|find|fd|strings|xxd|hexdump|od|tac|nl' +pattern='(^|[;&|(`]|\$\()[[:space:]]*('$readers')([[:space:]]|$)' + +if printf '%s' "$cmd" | grep -qE "$pattern"; then + echo "blocked: read/search files only through vr (run 'vr -doc' for usage)" >&2 + exit 2 +fi +vcs='jj[[:space:]]+(file[[:space:]]+show|diff)|git[[:space:]]+(show|diff|grep|cat-file|blame|log)' +if printf '%s' "$cmd" | grep -qE "(^|[;&|(\`])[[:space:]]*($vcs)"; then + echo "blocked: use 'vr read -r REV FILE' / 'vr grep -r REV' instead of raw jj/git reads" >&2 + exit 2 +fi +exit 0 -- cgit v1.3