Creates a PreToolUse hook that denies run_bash commands matching any of a
set of regular expressions (case-insensitive). The default patterns cover:
file system destruction:
rm -rf,mkfs,dd if=, writes to/dev/;privilege escalation:
sudo,su -,chmod 777,chown root,setuid;code execution:
eval,exec,source $VAR, backticks,$(...),python -cand similar one-liners;process manipulation:
kill -9,killall,pkill -9, fork bombs;system files and services:
crontab,systemctl,/etc/passwd,/etc/shadow,/etc/sudoers;credentials and history:
printenv, reading.ssh,.awsor.envfiles, clearing shell history;network exfiltration:
curl -X POST,wget --post,nc -e,netcat, reverse shells;obfuscation: variable expansion, piping
base64output to a shell, hex and octal escapes, quote splitting, backslash escapes.
The patterns are broad, so they also block some harmless commands. A
denylist can't catch every obfuscated command either. To keep shell
commands contained, turn off bash in Permissions or run the agent in a
container or other OS sandbox.
The hook returns a denial for a matching command and NULL otherwise, so
hooks added after it still see the commands it lets through.
Value
A HookMatcher.
Examples
if (FALSE) { # \dontrun{
# Use default patterns
agent$add_hook(hook_block_dangerous_bash())
# Add custom patterns
agent$add_hook(hook_block_dangerous_bash(
additional_patterns = c("my_custom_pattern", "another_pattern")
))
} # }