Skip to content

gave the dangerous-command guard an owner-approved bypass prefix (DANGEROUS_GUARD_BYPASS=1) like GITIGNORE_GUARD_BYPASS - #1043

Merged
notque merged 1 commit into
mainfrom
fix/dangerous-guard-bypass-prefix
Oct 3, 2026
Merged

notque merged 1 commit into
mainfrom
fix/dangerous-guard-bypass-prefix

Conversation

@notque

@notque notque commented Oct 3, 2026

Copy link
Copy Markdown
Owner

Owner request: add a command-prefix bypass to the dangerous-command guard, like the other bypass hooks.

  • DANGEROUS_GUARD_BYPASS=1 <cmd> at the start of a command skips the guard and prints an audit line to stderr.
  • Mid-command prefixes and other values stay blocked. The deny message does not name the bypass, so agents still ask the owner first.
  • The existing env-var check is unchanged. It is read from the hook's own environment, which an agent's command cannot reach.
  • Tests: 5 new (allowed, audit line, mid-command blocked, wrong value blocked, deny text). Hook suites: 676 passed. ruff check and format clean.

Co-authored-by: Claude Opus 5.5 noreply@anthropic.com

…GEROUS_GUARD_BYPASS=1) like GITIGNORE_GUARD_BYPASS, with an audit line and not named in the deny message

The existing DANGEROUS_GUARD_BYPASS env var is read from the hook's own environment, which an agent's command cannot set, so an owner-approved one-off (for example dropping a leftover schema) had no path. The prefix works only at the start of the command; mid-command or any other value is still blocked.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@notque
notque merged commit 5218674 into main Oct 3, 2026
11 checks passed
@notque
notque deleted the fix/dangerous-guard-bypass-prefix branch October 3, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant