blob: 729f4d4b6d3fe8a79da68e8afa6b11a5bb4b146c (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
|
#!/bin/sh
# Claude Code PreToolUse hook (matcher: Bash): deny shell commands that read
# files without going through notevi. A guardrail, not a jail — it catches the
# common readers at command position, not every conceivable bypass.
cmd=$(jq -r '.tool_input.command // empty')
readers='cat|head|tail|less|more|sed|awk|cut|rg|grep|egrep|fgrep|find|fd|strings|xxd|hexdump|od|tac|nl'
pattern='(^|[;&|(`]|\$\()[[:space:]]*('$readers')([[:space:]]|$)'
if printf '%s' "$cmd" | grep -qE "$pattern"; then
echo "blocked: read/search files only through notevi (run 'notevi -doc' for usage)" >&2
exit 2
fi
vcs='jj[[:space:]]+(file[[:space:]]+show|diff)|git[[:space:]]+(show|diff|grep|cat-file|blame|log)'
if printf '%s' "$cmd" | grep -qE "(^|[;&|(\`])[[:space:]]*($vcs)"; then
echo "blocked: use 'notevi read -r REV FILE' / 'notevi grep -r REV' instead of raw jj/git reads" >&2
exit 2
fi
exit 0
|