aboutsummaryrefslogtreecommitdiffstats
path: root/.agents/skills/hook-development/examples/validate-bash.sh
diff options
context:
space:
mode:
authorsillylaird <sillyfanboy@gmail.com>2026-09-03 00:33:59 +0000
committersillylaird <sillyfanboy@gmail.com>2026-09-03 00:33:59 +0000
commit898b52edcb47bcb3e9d6106e74ca73e74ea01e70 (patch)
tree85c6ee5ad58b860144551184d4cf86b560c62b91 /.agents/skills/hook-development/examples/validate-bash.sh
downloadwww-898b52edcb47bcb3e9d6106e74ca73e74ea01e70.tar.gz
www-898b52edcb47bcb3e9d6106e74ca73e74ea01e70.zip
import live www.sillylaird.ca webrootHEADmain
Diffstat (limited to '.agents/skills/hook-development/examples/validate-bash.sh')
-rw-r--r--.agents/skills/hook-development/examples/validate-bash.sh43
1 files changed, 43 insertions, 0 deletions
diff --git a/.agents/skills/hook-development/examples/validate-bash.sh b/.agents/skills/hook-development/examples/validate-bash.sh
new file mode 100644
index 0000000..e364324
--- /dev/null
+++ b/.agents/skills/hook-development/examples/validate-bash.sh
@@ -0,0 +1,43 @@
+#!/bin/bash
+# Example PreToolUse hook for validating Bash commands
+# This script demonstrates bash command validation patterns
+
+set -euo pipefail
+
+# Read input from stdin
+input=$(cat)
+
+# Extract command
+command=$(echo "$input" | jq -r '.tool_input.command // empty')
+
+# Validate command exists
+if [ -z "$command" ]; then
+ echo '{"continue": true}' # No command to validate
+ exit 0
+fi
+
+# Check for obviously safe commands (quick approval)
+if [[ "$command" =~ ^(ls|pwd|echo|date|whoami)(\s|$) ]]; then
+ exit 0
+fi
+
+# Check for destructive operations
+if [[ "$command" == *"rm -rf"* ]] || [[ "$command" == *"rm -fr"* ]]; then
+ echo '{"hookSpecificOutput": {"permissionDecision": "deny"}, "systemMessage": "Dangerous command detected: rm -rf"}' >&2
+ exit 2
+fi
+
+# Check for other dangerous commands
+if [[ "$command" == *"dd if="* ]] || [[ "$command" == *"mkfs"* ]] || [[ "$command" == *"> /dev/"* ]]; then
+ echo '{"hookSpecificOutput": {"permissionDecision": "deny"}, "systemMessage": "Dangerous system operation detected"}' >&2
+ exit 2
+fi
+
+# Check for privilege escalation
+if [[ "$command" == sudo* ]] || [[ "$command" == su* ]]; then
+ echo '{"hookSpecificOutput": {"permissionDecision": "ask"}, "systemMessage": "Command requires elevated privileges"}' >&2
+ exit 2
+fi
+
+# Approve the operation
+exit 0