docs: record the guardrail gaps that are accepted on purpose #111
Reference in New Issue
Block a user
Delete Branch "feat/agent-guardrails"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Docs only: one commit (
a0362d3) that landed onfeat/agent-guardrailsafter #110 was merged.docs/agent-guardrails.md.bash_protected_portrow: what it matches and why 8080 is protected.No code changes. The plugin, scripts and tests are untouched.
Why
A live check on 2026-10-04 showed the agent's blocked
curl localhost:8080/healthsucceeding when retried throughwebfetch. The decision was to accept that gap rather than add a rule, and to write it down. Each gap below was probed at the hook boundary before it was documented.task,call_omo_agent,edit,writeandbash, sowebfetchoflocalhost:8080passes.bash_protected_portmatches literallocalhost/127.0.0.1/0.0.0.0plus:8080. It misses[::1]:8080, the machine's own address and URLs held in variables, and it blocks a commit message that nameslocalhost:8080. It does see insidebash -candpython3 -c.bash -c '...'/sh -c '...'wrappers evadebash_bannedandbash_main_checkout:bash -c 'pkill -f foo'andbash -c 'git stash'both pass.bash_main_checkoutcan mis-anchor a relativecdchain that follows an absolute one.Verification
Docs only; no test reads the file. The probes are the evidence: each claim in the new section was run through the real hook (
tool.execute.beforewith{tool, sessionID, callID}and{args}) and the allow/block result recorded.🤖 Generated with Claude Code
https://claude.ai/code/session_01KkCGRantZsSwmcFpet6FTa